Dev.to Security 🔐 Cybersecurity 👁 0 📖 3 min read

Stop Mailinator signups with one GET request

If your free trial lets anyone in with an email address, someone will sign up as [email protected] forty times. A list lookup at signup is the cheapest first filter. This API does that lookup without you maintaining the l

If your free trial lets anyone in with an email address, someone will sign up as [email protected] forty times. A list lookup at signup is the cheapest first filter. This API does that lookup without you maintaining the lists.

The shortest working call

Subscribe to the free plan on the listing (link at the bottom), copy your key, and run:

curl --request GET \
  --url 'https://disposable-email-checker16.p.rapidapi.com/[email protected]' \
  --header 'x-rapidapi-host: disposable-email-checker16.p.rapidapi.com' \
  --header 'x-rapidapi-key: YOUR_RAPIDAPI_KEY'

JavaScript (Node 18+):

const res = await fetch(
  'https://disposable-email-checker16.p.rapidapi.com/checkDisposable?email=' +
    encodeURIComponent('[email protected]'),  {
    headers: {
      'x-rapidapi-host': 'disposable-email-checker16.p.rapidapi.com',
      'x-rapidapi-key': process.env.RAPIDAPI_KEY,
    },
  }
);
if (!res.ok) throw new Error(`HTTP ${res.status}`);
const data = await res.json();
if (data.disposable) console.log('blocked:', data.matchedDomain);

Python:

import os, requests

r = requests.get(
    "https://disposable-email-checker16.p.rapidapi.com/checkDisposable",
    params={"email": "[email protected]"},    headers={
        "x-rapidapi-host": "disposable-email-checker16.p.rapidapi.com",
        "x-rapidapi-key": os.environ["RAPIDAPI_KEY"],
    },
    timeout=10,
)
r.raise_for_status()
data = r.json()
print(data["disposable"], data["matchedDomain"])

The response, field by field

Captured from the live API on 7 Oct 2026 (HTTP 200, 322 bytes):

{
  "input": "[email protected]",  "type": "email",
  "domain": "mailinator.com",
  "disposable": true,
  "freeProvider": false,
  "matchedLists": [
    "disposable-email-domains",
    "disposable",
    "mailchecker",
    "burner-email-providers"
  ],
  "matchedDomain": "mailinator.com",
  "listsUpdatedAt": "2026-10-05T10:09:51.295Z",
  "meta": {
    "user": "..."
  }
}

(meta.user holds the account name of the caller, shown as "..." here.)

  • input and type: what you sent, and whether it was read as an email or a bare domain. A URL also works; only the domain is used.
  • domain: the domain that was extracted and checked.
  • disposable: true if the domain is on at least one list. Subdomains are matched against their parent domain, so you do not need to strip them first.
  • freeProvider: true for providers such as Gmail. It is always false when disposable is true.
  • matchedLists: which of the five merged public lists flagged the domain. Four of five agree here. A domain flagged by one list is a weaker signal than one flagged by all.
  • matchedDomain: the entry that matched, or null.
  • listsUpdatedAt: when the lists were last refreshed. They refresh when older than 7 days.

A free provider looks like this (gmail.com, also captured 7 Oct 2026, 213 bytes): type is domain, disposable is false, freeProvider is true, matchedLists is [] and matchedDomain is null. That split lets you reject throwaway domains outright while only flagging free providers on a B2B form.

What it does not do

  • A domain missing from the lists is not proof the address is real or safe. New throwaway domains appear daily.
  • The lists are community-maintained, so false positives happen. Use matchedLists to see how many agree.
  • It never contacts the mailbox. It does not check that the address exists, that the domain has mail servers, or that the user can receive mail. For that you need a confirmation email.
  • It is a list lookup. It does not score a domain on age or reputation.

Errors

Status When Body
200 Input read and checked The result above
400 email missing {"error":"Pass ?email=<email address or domain>.","code":400}
400 email not readable {"error":"Not a valid email address.","code":400}
405 Any method other than GET {"error":"Use GET /checkDisposable?email=<address or domain>.","code":405}
502 Unexpected failure inside the API {"error":"Check failed: ...","code":502}

The 400, 405 and 502 bodies are from the API's own documentation and were not re-run on 7 Oct. Requests that fail at the RapidAPI gateway (a missing or wrong key, or a quota that is used up) return RapidAPI's own error, not this shape.

Plan

The free Basic plan on the listing currently shows 1,000 requests per month. Paid plans start at $29 per month.

Listing and playground: https://rapidapi.com/samaanmohammed/api/disposable-email-checker16

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.