Disposable Email CheckFree
GET /v1/emails/disposable
- Looks only at the domain. No mail server is contacted.
- Answers one question: is this a temporary email domain?
- 0 credits, so you can run it on every signup.
Free0 credits per check, whatever the result
Find out if an email address belongs to a temporary inbox before you create the account, send the welcome email, or hand out free credits. Send one address and get the domain and a true or false answer back. Every check is free.
Opens in the API playground. No credits used.
Try
Background
A disposable email address, also called a temporary, throwaway, or burner email, comes from a service that hands out an inbox to anyone for a few minutes or hours with no signup. People use one to get past an email gate without sharing a real address. Once the inbox expires, there is no way to reach that person again.
That shows up as trial abuse, duplicate free accounts, welcome emails that bounce, and CRM records nobody can follow up on. The Disposable Email Check API tells you, at the moment of signup, whether the domain belongs to one of these services. It costs no credits, so you can run it on every form without thinking about the bill.
Request and response
Only the domain after the @ is checked against the current disposable-domain list. No message is sent and no mail server is contacted.
curl -G "https://api.envoapi.com/v1/emails/disposable" \ --data-urlencode "[email protected]" \ -H "Authorization: Bearer $ENVO_API_KEY"emailAuthorizationX-RateLimit-*X-Request-Id{ "data": { "domain": "mailinator.com", "isDisposable": true }, "meta": { "creditCost": 0 }}domainisDisposablecreditCostIntegration
The check is one GET request from your server. Here is the same call in Node.js, Python and cURL.
Sign up, copy the key from your dashboard, and keep it on the server. The check runs from your backend, never from the browser.
Send the address your user typed as the email query parameter. Only the domain after the @ is used.
isDisposableWhen it is true, ask for another address, hold free credits, or flag the lead. When it is false, carry on as usual.
const url = new URL("https://api.envoapi.com/v1/emails/disposable");url.searchParams.set("email", form.email);const response = await fetch(url, { headers: { Authorization: `Bearer ${process.env.ENVO_API_KEY}` },});const { data } = await response.json();if (data.isDisposable) { // Ask for a work or personal address instead.}import osimport requestsresponse = requests.get( "https://api.envoapi.com/v1/emails/disposable", headers={"Authorization": f"Bearer {os.environ['ENVO_API_KEY']}"}, params={"email": form["email"]},)data = response.json()["data"]if data["isDisposable"]: # Ask for a work or personal address instead. ...curl -G "https://api.envoapi.com/v1/emails/disposable" \ --data-urlencode "[email protected]" \ -H "Authorization: Bearer $ENVO_API_KEY"Use cases
Run the check when the form is submitted. If the domain is disposable, ask for a work or personal address instead of creating the account.
Stop one person from opening ten trials with ten temporary inboxes. Send disposable signups through extra verification before you grant credits or trial days.
Flag disposable addresses as leads arrive from forms, imports, and partners. Sales stops chasing inboxes that will be gone next week, and reports count only real contacts.
People use temporary inboxes to grab a PDF and vanish. Check the address before you send the asset, so your follow-up list holds real prospects.
Keep contest entries and referral rewards for real people. One check per entry costs nothing, so there is no reason to skip it.
Temporary inboxes expire and then bounce. Drop them before a campaign goes out instead of after the bounces come back.
Disposable check vs. email verification
Use the disposable check on every form, because it is free. Use Verify Email when you need to know the mailbox is real, such as before a campaign or a sales handoff.
GET /v1/emails/disposable
GET /v1/emails/verify
isCatchAll and isDisposable. Uses credits.Response codes
Every error carries a code, a message, a retryable flag, and meta.requestId so support can find the request.
| Status | Meaning |
|---|---|
200 | The check ran. Read data.domain and data.isDisposable. |
400 | The email parameter is missing or invalid. |
401 | Your API key is invalid or inactive. |
403 | Your API key or account cannot access this endpoint. |
405 | Use GET for this endpoint. |
406 | The format in your Accept header is not supported. |
415 | The Content-Type in your request is not supported. |
429 | Too many requests. Wait for the Retry-After header. |
500 | A server error stopped the request. Retry later. |
503 | The domain list or a required dependency is unavailable. Retry after the Retry-After header when one is sent. |
FAQ
A disposable, temporary, or burner email address comes from a service that gives anyone an inbox for a few minutes or hours with no signup. People use them to get past email gates without sharing a real address. Accounts created with them are hard to recover, rarely convert, and often bounce later.
No. It checks only whether the domain after the @ is a known disposable email domain. It does not check that the mailbox exists or that mail will be delivered. Use the Email Verification API for that.
Nothing. Every successful response reports a creditCost of 0, whether the domain is disposable or not. Your plan's rate limits still apply.
The endpoint takes an email address, but only the domain is used. Send any address on that domain, such as [email protected], and read data.domain in the response.
Yes. The domain is lowercased and normalized before the check, and everything before the @ is ignored. [email protected] and [email protected] give the same result.
An exact match on the normalized domain. The domain after the @ is either on the current disposable-domain list or it is not. The response returns that domain so you can log what was checked.
Yes. It costs no credits, but each request counts toward your rate limit. If you go over it you get a 429 with a Retry-After header.
No. Every response is sent with Cache-Control: private, no-store, so each request reflects the current domain list.
The API returns 503 when the domain list or a required dependency is unavailable, with a Retry-After header when a retry time is known. Until it recovers, treat the address as unknown, not as safe.
That is your call. Many teams ask for a different address and let the user continue, which keeps conversion high and cuts abuse. Others allow the signup but hold free credits or trial features until a real address is confirmed.
Create an API key, add one GET request to your form handler, and stop temporary inboxes from turning into fake accounts. Every check is free.