Watch-IP

Disposable Email Detection vs Email Verification

Disposable-email detection and domain checks tell you whether an address's domain is a known temporary-email provider and whether it can receive mail at all; mailbox verification tries to confirm that the specific mailbox exists. Watch-IP's email check does the first, not the second — conflating them leads to false confidence that an address which passed a domain check actually works.

Four different checks, often bundled under one name

“Email verification” can mean any of: syntax validation (does the string look like an email?), domain classification (is the domain a known disposable/temporary provider, and does it have a mail server at all?), SMTP mailbox probing (does the mail server accept a message to that specific address without actually sending one?), and ownership confirmation (does the person who submitted it control the mailbox — typically via a confirmation link?). These are separate technical checks with different costs and failure modes. Watch-IP implements the first two, plus typo and role-address detection; it does not perform SMTP probing or ownership confirmation.

What an accept verdict actually means

verdict: accept means none of the checks found a problem: the syntax is valid, the domain exists and publishes a mail server, it doesn't match a known disposable provider, and there's no likely typo or role address. It does not mean the mailbox exists, that it belongs to the person signing up, or that it will stay valid. A very new disposable provider that no list or mail-server observation covers yet will pass. Treat accept as “no known problem,” not “verified real.”

Appropriate signup feedback

Show a specific message per reason — invalid syntax, a disposable domain and a domain with no mail server call for different corrective action from the visitor — and offer didYouMean as a one-click fix for a typo. Collapsing them into one generic “invalid email” message makes the error harder to act on. Because the single check is browser-callable with a publishable key, enforce whatever decision actually matters on your backend too; a client-side check alone can be skipped by disabling JavaScript or calling your signup endpoint directly.

When you need real mailbox verification

If your application needs confidence that a mailbox is real and reachable — for transactional email delivery, for example — use a confirmation-link flow (send a message, require the user to click a link). For cleaning an existing list before a campaign, a domain-level pass such as Watch-IP's list jobs removes invalid, disposable, mistyped and no-mail-server addresses cheaply; a mailbox-level verifier can then be used on what remains if you need it. That's a category difference, not a Watch-IP-specific gap.

What this article does not claim

This page describes disposable-email detection as a category and Watch-IP's own email check specifically. It is not a claim that any disposable-domain list is complete, or that an accept verdict predicts deliverability, engagement, or that the address belongs to the person who submitted it.

Sources

Written by Watch-IP editorial, 2026-09-06; updated 2026-09-28 for the v2 email check. Reviewed against apps/api/src/lib/email-check.ts, email-verdict.ts, email-dns.ts and email-store.ts.

Related pages