Should a Website Block Disposable Email?
In short. It depends on what a lost real customer costs you, and in practice most blocking is set far tighter than the actual risk justifies. We run a service that gets blocked, so the arguments for blocking are laid out here in full rather than waved away.
Start with the honest disclosure
This site hands out disposable addresses. If sites stop refusing them we benefit. You should read everything below with that in mind, which is exactly why the case for blocking is stated first and completely, and why nothing here argues that abuse is imaginary. It is not.
Four real reasons to block
Trial abuse. A free trial per account becomes an unlimited free product if accounts are free and infinite. For anything with real per-user cost, this is the strongest argument there is.
Votes, reviews and rankings. Anywhere one account equals one unit of influence, cheap accounts are the attack. Review scores, polls, contests, referral bonuses.
Deliverability metrics. Mail to an expired mailbox eventually bounces or lands in a spam trap, and both damage your sending reputation. A list full of dead addresses makes your real mail arrive less often.
Compliance. Some regulated activities require a contactable customer of record, and an address designed to expire fails that requirement regardless of anyone's opinion.
If one of these describes you, block, and read the rest for how to do it without overshooting.
What blocking does not solve
It stops casual abuse and inconveniences determined abuse for about four minutes.
Anyone running fraud at scale does not use public throwaway domains. They buy addresses on ordinary domains for fractions of a cent, or they register a domain and run a catch-all, which is indistinguishable from a small business. The sophisticated attacker you are worried about walks straight past a blocklist; the person it stops is a shopper who did not want another newsletter.
That is the asymmetry worth sitting with. A blocklist is a filter tuned to catch the least motivated attacker and the most privacy-conscious customer, which is close to the opposite of what you want.
The cost nobody measures
A refused signup is invisible. It does not appear as a failed conversion, because from your analytics nothing happened: a form was abandoned. There is no support ticket, because from the user's side the site simply refused them and they went elsewhere.
So the cost of blocking is systematically underestimated in every meeting where it gets discussed. The benefit is visible, countable and reported as fraud prevented. The cost is a slightly lower conversion rate that everyone attributes to something else. If you have never measured how many signups your validator refuses, you do not have the numbers to justify the setting you are running.
Worse, some of those refusals hit people whose addresses are not disposable at all. False positives are common enough that they usually outnumber the genuine catches on ordinary consumer sites.
Alternatives, from gentle to firm
Verify the address. Confirm by clicking a link. This catches nothing about disposability but catches everything about deliverability, which is what most sites actually care about.
Delay the reward. Let anyone sign up, but release the trial credit, the discount or the referral bonus after some period. Throwaway addresses expire before the reward arrives, and legitimate users simply come back. A waitlist does this by accident: the invitation goes out weeks later, and only an address that still exists can accept it.
Bind to something scarcer than email. Device, phone number, payment method. Any of these costs an attacker more than an address does, and none of them punishes a customer for their choice of mailbox.
Review anomalies by hand. Forty signups from one address range in an hour is a pattern worth looking at; one signup from a domain on a list is not.
Block, but only the top offenders. If you do block, use a short list of the largest services rather than an exhaustive one. The long tail of any blocklist is where the false positives live.
Where blocking is not arguable
Anything involving money moving, physical goods shipping, or a regulated service being delivered. Also anything where you are legally required to be able to reach the customer later.
In these cases the address is part of the transaction record, not a contact preference, and an expiring address genuinely cannot do the job. Nobody sensible argues otherwise, including us.
Choosing a threshold with numbers instead of feelings
Two quantities, both estimable in an afternoon.
The cost of one abusive account: what a free trial actually costs you to serve, or what one fake review costs in trust.
The value of one refused customer: your average customer value multiplied by the share of refused signups who were legitimate. That share is higher than most teams assume.
Compare them. If an abusive account costs you two cents of compute and a customer is worth forty dollars, you can tolerate an enormous amount of abuse before blocking pays for itself. If each fraudulent account costs you a physical device, the answer flips immediately.
The point is not that blocking is wrong. It is that most sites have never done this arithmetic and inherited their setting from a library default written by someone who never saw their numbers.
Read next
When Validation Blocks Real People
Catch-all company domains, new domains and subaddressing get flagged as disposable every day. How to spot the losses you never see.
Marketplaces and Classified Ads
Selling one item should not cost you a permanent contact. How to handle buyer mail without handing over your real address.
Gated Downloads and Webinars
The PDF costs one work email and eleven follow-ups. What happens to the address you type into a lead form.