Disposable Email Detection API

Disposable Email API: isDisposable in One Call

One GET to the validation endpoint returns the isDisposable flag alongside the full 9-check verdict & 99.99% accuracy. Block burner signups on one boolean, no signup to try it.

Read the docs for the full API and bulk jobs, or wire it into your signup.

Trusted by 500,000+ leading GTM teams of all sizes

From key to blocked burner

How the disposable API works

Three steps, no SDK, no webhooks. Get a key, send one GET to the endpoint, then block on the isDisposable boolean.

001KEY

Get your free API key

Sign up and generate a vfx_ key from the dashboard in under a minute. A thousand verification credits land instantly, twenty-five hundred with a work email, and they never expire on you.

002REQUEST

Call the endpoint

Send one GET to the validation endpoint with your key in the header, no SDK and no OAuth, from cURL, Node, or Python - any HTTP client works. Latency runs about 380 ms.

003VERDICT

Block on the isDisposable flag

Read the isDisposable boolean and reject burner signups in one line. The full nine-check verdict rides along in the same response, so you can block hard or just flag it for review.

Disposable email, explained

What a disposable email list API does

Not a stale blocklist dump. A continuously refreshed isDisposable flag, read alongside every other check.

A disposable email list API answers one question on every signup: is this address a real, reachable inbox, or a throwaway spun up to clear your form and disappear? Burner providers hand out inboxes that self-destruct in minutes, and those addresses fuel most fake accounts, trial abuse, and junk signups. Verifox reads the answer back as an isDisposable flag inside the same nine-check verdict, one GET request against the validation endpoint, with the full category covered in the disposable email glossary.

The 9-point engine

Nine checks behind every verdict

The disposable match is one of nine. The same engine our paid API runs weighs it against SMTP, catch-all, domain age, and reputation.

  1. 01

    Syntax

    Every address runs a full RFC 5321 and RFC 5322 compliance pass before a single network call goes out. The engine catches what visual scanning misses, the double dot in [email protected], the trailing period, the IDN homograph that looks valid but resolves to a different domain.

    Bundled typo suggestions let your form offer “did you mean [email protected]?” instead of rejecting silently.

    /dashboard/verify
    The Verifox dashboard verifying matthamnett@avencera.ai: the Syntax tile is ringed in the nine-check result board, beside a card showing the parse of matthamnett @ avencera.ai against RFC 5321 and RFC 5322, verdict “Valid format”.
  2. 02

    Domain & MX

    Once syntax passes, the engine resolves the domain. We confirm the DNS records exist, fetch the MX record priority list in order, and verify at least one mail-exchange server is actively accepting connections right now.

    Misspelled domains like gmial.com, expired domains, and parked-for-sale domains all fail this gate before the engine wastes a single SMTP roundtrip.

    /dashboard/verify
    The Verifox dashboard verifying matthamnett@avencera.ai: the MX Record tile is ringed in the result board, beside a card showing the real MX 0 record avencera-ai.mail.protection.outlook.com on Microsoft 365, verdict “MX record found”.
  3. 03

    SMTP handshake

    The engine opens a TCP connection on port 25, performs the EHLO handshake, then negotiates MAIL FROM and RCPT TO. Every server response code (220, 250, 550, 552) is parsed deterministically against the IANA enhanced-status registry.

    This is the moment a mailbox proves it actually exists. No third-party guesses, no statistical heuristics, just the receiving server's own answer.

    /dashboard/verify
    The Verifox dashboard verifying matthamnett@avencera.ai: the SMTP Connect tile is ringed in the result board, beside a card showing the EHLO → MAIL FROM → RCPT TO exchange and the server’s 250 2.1.5 Recipient OK reply, verdict “Mailbox proven”.
  4. 04

    Catch-all detection

    Some domains accept every email regardless of whether the mailbox exists, a setup known as a catch-all configuration. The engine sends a deterministic probe to a deliberately fake address ([email protected]); if the server returns the same 250 OK it returned for the real address, the domain is catch-all.

    The verdict isn't dropped, it's flagged RISKY so you know the deliverability signal is degraded.

    /dashboard/verify
    The Verifox dashboard verifying matthamnett@avencera.ai: the Catch-All tile is ringed in the result board, beside a card comparing the real address (250 OK) with a deliberately fake probe (550 rejected), verdict “Validates recipients”.
  5. 05

    Disposable

    The engine maintains a curated registry of 10,247 disposable email providers, including Mailinator, Guerrilla Mail, 10MinuteMail, Tempmail, and the long tail of regional clones.

    Any address matching the blocklist is flagged INVALID. Deliverability to a mailbox that exists for 10 minutes and is never checked is functionally zero, regardless of whether the SMTP handshake passes.

    /dashboard/verify
    The Verifox dashboard verifying matthamnett@avencera.ai: the Disposable tile is ringed in the result board, beside a card showing the 10,247-provider throwaway blocklist and no match for avencera.ai, verdict “Legitimate domain”.
  6. 06

    Role address

    info@, support@, no-reply@, admin@, billing@. These are shared inboxes, not individuals.

    The engine extracts the local-part of every address, matches it against the known role-prefix registry, and tags the result with a reduced engagement score.

    You don't drop them automatically. The verdict flags them as roles so you can decide.

    /dashboard/verify
    The Verifox dashboard verifying matthamnett@avencera.ai: the Role Address tile is ringed in the result board, beside a card matching the local-part matthamnett against the info@ / support@ / no-reply@ / admin@ role registry with no match, verdict “Personal address”.
  7. 07

    Domain age

    Fresh-spam domains registered hours ago are the single biggest source of inbound abuse. The engine queries WHOIS and RDAP for every unique domain, extracts the registration date, and flags anything under 30 days old with a “fresh” warning.

    Domains aged 5+ years pick up a corresponding trust signal. The same heuristic spam filters have been using since the early 2000s, ported into the verdict.

    /dashboard/verify
    The Verifox dashboard verifying matthamnett@avencera.ai: the Domain Age tile is ringed in the result board, beside a card showing the WHOIS creation date 2025-07-10 against the 30-day fresh-spam threshold, verdict “1y old”.
  8. 08

    Email authentication

    SPF, DKIM, and DMARC together prove the sender is authorised to send from that domain.

    The engine reads each policy via DNS, validates SPF includes recursively, scans six common DKIM selectors, and confirms DMARC alignment with the From: header.

    A failing DMARC policy means the sender can be spoofed, so the verdict warns you before you reply.

    /dashboard/verify
    The Verifox dashboard verifying matthamnett@avencera.ai: the DMARC tile is ringed in the result board, beside a card showing the real SPF include, DKIM selector1/selector2 and DMARC p=reject records, verdict “Aligned & enforcing”.
  9. 09

    Mailbox state

    Beyond “exists vs doesn't exist”, the engine extracts the precise mailbox state from the SMTP server's response. Full inbox (552 / 522 quota), disabled mailbox (550 5.1.1), out-of-office autoresponder, frozen account.

    Each state maps to a specific retry policy. Full inbox retries in 6 hours. Disabled drops permanently. The verdict tells you which bucket the bounce belongs in so your retry logic doesn't waste cycles.

    /dashboard/verify
    The Verifox dashboard verifying matthamnett@avencera.ai: the Inbox Exists tile is ringed in the result board, beside a card showing the live 250 2.1.5 active reply against the full-inbox and disabled states that drive retry policy, verdict “Inbox confirmed”.
Why this one

Disposable email detection, without the tradeoffs

Most disposable checkers rely on stale lists, missing new burner domains. Ours runs nine paid-grade checks against a continuously refreshed list.

Verification engine
9

checks on every
address

The same nine-check pipeline as the paid API runs on every address, free or not.

No signup to start

Verify your first emails right here, no account, no card.

10k emails a minute

Bulk CSV in, verified list out. Same speed on every plan.

Instantly verified

Every address comes back already checked, with a confidence score.

99.99% accurate

Validated on a 10,000-address mixed benchmark including catch-all domains.

Credits never expire

1,000 free on signup. 2,500 with a work email. Pay as you go after.

Start verifying, free

Emails are never stored

Processed in memory, dropped on response. SOC 2 · GDPR · CCPA.

How we stack up

Verifox vs the other disposable filters

NeverBounce and ZeroBounce both flag disposable domains. Verifox weighs the disposable match against domain age and reputation in one verdict, with a continuously-refreshed list.

★ The accurate checkerVerifox
NeverBounce99.0%
ZeroBounce99.6%
NeverBounce
ZeroBounce
NeverBounce1,000 / monthly
ZeroBounce100 / monthly
NeverBounceYes
ZeroBounceNever
NeverBounceFlagged only
ZeroBounceAI scoring
NeverBounce
ZeroBounce
NeverBounce
ZeroBounce
NeverBounce
ZeroBounce
NeverBounce
ZeroBounce
Pricing

Pay once, or not at all

Most tools reset your balance every month. Verifox sells credits that sit in your account until you spend them.

FreeProve it on your own list before you spend anything.$0

forever

1,000credits on signup

No card required

2,500 with a work email

Free includes

  • All 9 checks included
  • Full API and bulk CSV
  • Catch-all confidence scoring
  • No card required
Most popular
Credit packsBuy once, spend whenever. Slide to price your list.$59

one time

10,000credits

$0.0059 eachSAVE 34%

Everything in Free, plus

  • Credits never expire
  • Verify or find from one pool
  • Up to 79% off at volume
  • No contract, no minimum
Verifox ONECredits land monthly and stack on your balance.$79

per month

15,000credits a month

$0.0053 each

Unused credits roll over

Everything in packs, plus

  • Unused credits roll over
  • Our lowest per-email rate
  • 50 requests per second API
  • Cancel anytime

One credit verifies one address; a find costs 10. All prices in USD, checkout via Stripe.

What teams are saying

Built for the teams that ship outbound

Growth leads, marketers, and engineers running real campaigns on real lists, with a verified email on every byline.

Thomas George, GTM Lead at Stripe

90% lower bill, 0.4% bounces

We were paying ZeroBounce a four-figure monthly bill and still landing 3% bounces on cold campaigns. Switched the pipeline to Verifox, dropped to 0.4% bounces, and cut the bill by more than 90%.
Thomas G.GTM Lead, Stripe
Brittany King, GTM Lead at HubSpot

Catch-all finally has a verdict

Other tools flag 30% of our B2B list as 'risky catch-all' and leave the call to us. Verifox returns a real verdict on those addresses, with a confidence score. We send more, we send safer.
Brittany K.GTM Lead, HubSpot
Dale Micallef, GTM Lead at Slack

Reputation rebuilt in 6 weeks

We had a Gmail spam-folder problem after a bad list import. Verifox cleaned the list and the warmup ran on the same engine. Back in primary inbox in six weeks. One vendor, half the cost.
Dale M.GTM Lead, Slack
Erica Kovalkoski, GTM Lead at Discord

0.7% bounce on 50k

Ran a 50,000-address outbound list through Verifox before our quarterly campaign. Bounces landed at 0.7%, sender reputation didn't move, replies were up 22% over last quarter.
Erica K.GTM Lead, Discord
Greg Lindsay, GTM Lead at OpenAI

MCP in 10 minutes

Their MCP server let me wire email verification directly into our internal Claude agent in about ten minutes. Zero glue code. No other vendor in this space has thought about that workflow.
Greg L.GTM Lead, OpenAI
Rini Vasana, Product Manager at Vercel

10k/min held under 400ms

Tested Verifox at 10,000 verifications per minute on a Tuesday morning. Latency held under 400ms median, no soft failures, no rate-limit walls. The vendor we benched throttled at 2,000/min.
Rini V.Product Manager, Vercel
Jonathan Aharon, GTM Lead at MongoDB

Hygiene that doesn't break pipeline

Our SDRs were enriching from three tools and 14% of the emails were invalid before they hit the sequencer. Verifox sits in the pipeline now and the team stopped seeing 'undeliverable' replies the next week.
Jonathan A.GTM Lead, MongoDB
Emma Fox, GTM Lead at Linear

Bulk that actually ships

Bulk upload, sorted CSV back in twenty minutes, plug into our growth stack. The half-day list-hygiene project per cohort turned into something the marketing intern runs on autopilot.
Emma F.GTM Lead, Linear
David Hare, GTM Lead at Snowflake

Scores you can act on

Verifox returns a 0-100 confidence score per address, not just a label. We thresholded at 75 for the cold sequencer, 60 for nurture, and our deliverability team finally has a knob they can tune.
David H.GTM Lead, Snowflake
Trust & compliance

Enterprise-grade security and scale

Every layer of the stack carries a third-party attestation, so you can ship into regulated industries without rebuilding your compliance posture.

  • Claymation Japanese hanko seal in jade-green clay with a twisted shimenawa rope rim, the words SOC 2 TYPE II embossed in cream clay on its face.

    SOC 2 Type II

    Independently audited to the SOC 2 Type II standard.

  • Claymation Japanese hanko seal in cobalt-blue clay with a twisted shimenawa rope rim, the word GDPR embossed in cream clay on its face.

    GDPR

    Built for the EU with full GDPR data-subject rights.

  • Claymation Japanese hanko seal in rose-pink clay with a twisted shimenawa rope rim, the word CCPA embossed in cream clay on its face.

    CCPA

    California opt-out, do-not-sell, plus DSAR handling.

  • Claymation Japanese hanko seal in terracotta clay with a twisted shimenawa rope rim, the text ISO 27001 embossed in cream clay on its face.

    ISO 27001

    Information security held to the ISO 27001 standard.

  • Claymation Japanese hanko seal in lilac-purple clay with a twisted shimenawa rope rim, the text ISO 42001 embossed in cream clay on its face.

    ISO 42001

    AI governance aligned to the new ISO 42001 standard.

Free field manual

The Dead List

An investigation into the money leaking out of your list - and the nine checks that decide whether your email is read, or never arrives at all.

The Dead List field manual, held up by the Verifox fox
Get the free manual

57 pages, free PDF, no signup

Common questions

Answers for Disposable email

The questions we get from developers and growth teams wiring disposable email blocking into a signup flow, with the real endpoints and real opinions behind our verification stack.

How does the disposable email list API actually work?

You call GET /v1/email-validation/:email and the JSON response includes an isDisposable flag alongside the full nine-check breakdown, so blocking a burner signup is one condition in your handler. Median latency sits around 380 ms, and sub-50 ms for cached domains.

Prefer not to write code at all? The FoxGuard widget ships with blockDisposable on by default, so your form rejects throwaway addresses before submit. Request and response shapes live in the API docs.

What counts as a disposable email address?

A disposable email is any address on a domain built to be thrown away: temporary inboxes, burner providers, and ten-minute-mail services people use to clear a signup gate without handing over a real address. Mailinator, Guerrilla Mail, Temp Mail, and thousands of lesser-known domains all fall in this bucket, and new ones appear daily.

They are the addresses most likely to fuel fake accounts, trial abuse, and junk signups, and they never convert. Disposable detection is one of the nine checks our verification engine runs on every address it sees.

Will Apple Hide My Email or DuckDuckGo addresses get flagged as disposable?

No. Privacy relays forward to a real, monitored inbox, which is the opposite of a burner. The SMTP handshake in our nine-check pipeline confirms a live mailbox sits behind the relay, so those addresses come back deliverable, not disposable. The isDisposable flag is reserved for domains whose inboxes are built to self-destruct.

Unsure about one specific address? Run it through the disposable email lookup and read the per-check verdict yourself.

How fast do new burner domains enter the disposable list?

Continuously. The disposable-domain list our engine matches against is refreshed all day rather than shipped quarterly, so a throwaway provider that went live this morning is caught this afternoon. Freshness is the whole game here, because burner services rotate domains precisely to outrun stale blocklists.

There is a second net underneath. The engine also scores domain age as one of its nine checks, so a day-old domain raises the risk score even before it is catalogued anywhere. Details on every check sit under email verification.

Should I block disposable signups outright or just flag them?

Block when a signup hands out value immediately: free trials, credits, coupons, or anything a fraud ring can farm with fresh inboxes. Flag and review when the cost of a false rejection is higher than the cost of a junk row, like a newsletter or a waitlist.

The API gives you both levers: the isDisposable boolean for a hard gate, plus the overall score for softer policies. On forms, FoxGuardshows a custom message like "Disposable emails are not allowed" so legitimate users self-correct on the spot.

Why not just use a free open-source disposable domain list from GitHub?

Static lists rot. Burner providers spin up new domains daily, and a repo updated whenever a maintainer finds time will always lag the domains doing the actual damage this week. A list match alone also says nothing about a brand-new domain nobody has catalogued yet.

Verifox pairs the continuously refreshed list with live signals: domain age, MX records, and a real SMTP handshake from the nine-check verification engine, measured at 99.99% accuracy on a 1,000-address benchmark. A text file on GitHub cannot do any of that.

Can I allow a domain the API marks as disposable?

Yes, because the policy is yours. The API returns the verdict; your code decides what to do with it, so allowlisting a domain is one extra condition before you check isDisposable. Nothing to configure on our side, no support ticket.

The FoxGuard widget goes one step further with per-field overrides: set data-verifox-block-disposable="false" on a specific input and that field accepts throwaway addresses even when blocking is on globally.

Is the disposable email checker on this page actually free?

Yes. The tool above runs 4 checks per day with no account, no card. It executes the same nine-check engine the paid API runs, disposable-domain match included.

Create a free account and you get 1,000 credits on the spot, or 2,500 if your signup email is a work address. Past that, credits are pay-as-you-go and never expire, with volume pricing shown for your region.

Can I scan an existing list for disposable addresses in bulk?

Yes. POST /v1/email-validation/bulk accepts up to 100,000 emails per job, or a CSV upload, and processes roughly 10,000 emails per minute on the standard tier. Every row comes back with its own isDisposable verdict.

Smaller list and no code handy? Paste it into the free email validator instead; your free signup credits cover most small lists outright.

Do you store the emails I send to the API?

No. Every address, whether it arrives from the free checker above or from an API call, is verified in memory and discarded the moment the response returns. We never store, log, or sell them.

Verifox is SOC 2 Type II compliant, with the full Trust Center report available on request. The privacy policy spells out exactly what we touch and what we never keep.