BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
WPCoreTools Disposable Email Guard icon
Actively maintained Tested with WP 7.1

WPCoreTools Disposable Email Guard

Block disposable, burner, and temp-mail addresses on WordPress and WooCommerce sign-ups, comments, checkout, and any custom form. Works fully offline.

Active installs10+10+ tier
Downloads · 30d94▼ -39.4% vs prev. 30d
Rating—0 reviews
Health score62/100Good
All-time downloads455Since May 2026
Support resolved—No recent threads
RequiresWP 6.2PHP 7.4+
Downloads · 7d15▼ -11.8% week over week
Our verdict

Solid choice

WPCoreTools Disposable Email Gu… is a solid plugin choice in 2026, with a few things worth checking first. It runs on 10+ sites and was last updated 1 month ago, and scores 62/100 on our health check.

  • Tested with the latest WordPress (7.1)
  • Small user base (10+ active installs)
  • Very few reviews so far

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

61320Jul 7Aug 20Oct 4
Yesterday3
Daily average (1y)3
Peak day27Aug 9, 2026
Last 12 months464

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where WPCoreTools Disposable Emai… stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
anti-spam >100 730 Best anti-spam plugins →
burner email #2 7 Best burner email plugins →
disposable email #32 192 Best disposable email plugins →
email validation >100 4,349 Best email validation plugins →
temporary email #86 1,090 Best temporary email plugins →

Version adoption

Share of active sites per release.

  • 1.0100.0%

About WPCoreTools Disposable Email Guard

From the official readme · v1.0.7

Description

This plugin refuses sign-ups, comments, checkouts, and form submissions when the email address belongs to a disposable, burner, or temp-mail service. All checks run on your own server against domain lists that ship inside the plugin file — no email address is ever sent to a third-party service, and the plugin does not contact any external server in its default configuration.

Five well-known community-maintained disposable-email lists are bundled as snapshots. Two are active out of the box (around 9,800 unique domains combined); three larger lists are available as opt-in for stricter coverage. An optional auto-update from the upstream GitHub URLs is also available, off by default.

What it detects

  • Disposable and burner addresses (default ON) — Mailinator, YOPmail, Guerrilla Mail, 10minutemail, Temp-Mail, and similar services.
  • Anonymous / privacy mail (default OFF) — Proton Mail, Tutanota, Mailbox.org, Posteo, StartMail, SimpleLogin, addy.io, DuckDuckGo Email Protection, Firefox Relay, Apple Hide My Email. Off by default because plenty of legitimate paying customers prefer these services.
  • Plus-addressing aliases (default OFF) — user+tag@example.com style sub-addresses.
  • Dead and no-MX domains (default OFF) — typos like gnail.com, parked or expired domains. One DNS lookup per new domain, then cached.
  • Custom block and allow rules with wildcard patterns: *@spammer.com, *@*.ru, spam*@*.

Where it checks

WordPress core:

  • Registration form
  • Profile email change
  • Comment author email (off by default)
  • Programmatic user creation (wp_insert_user, REST API, WP-CLI, other plugins)
  • Lost-password form
  • Multisite signup form

WooCommerce:

  • Customer registration
  • Checkout (billing email)
  • My Account → Edit Account email change
  • Product reviews
  • Coupon application — refuse coupons when the billing email is on a blocklist (anti-abuse safety net)

Form plugins:

  • Contact Form 7 — built-in, no configuration needed
  • Gravity Forms — built-in, no configuration needed
  • Any other form plugin via the wpcdeg_check filter (one line of PHP from your form’s email-validation hook)

Three modes

  • Block — reject the submission with a clear error message.
  • Flag — let the submission through, but tag the user / comment / order with wpcdeg_flagged meta so you can review them in a list. Pairs with WooCommerce auto-hold and coupon refusal.
  • Log only — record matches in the detection log without rejecting or tagging anything. Useful for a dry-run before turning enforcement on.

Domain lists

Five bundled snapshots are available, each toggled independently:

  • disposable-email-domains (MIT) — ON by default, ~5,400 domains.
  • 7c/fakefilter — ON by default, ~4,500 domains.
  • groundcat/disposable-email-domain-list (MIT) — opt-in, ~27,000 domains.
  • wesbos/burner-email-providers (MIT) — opt-in, ~27,000 domains.
  • disposable/disposable-email-domains (MIT) — opt-in, ~72,000 domains.

Each ships as a snapshot inside the plugin (data/sources/{id}.txt) and is loaded from disk; no network call is required for any of them to function.

If you want the snapshots refreshed on a schedule from their GitHub raw URLs, an optional auto-update feature is available. It is off by default. See “External services” below for what is contacted and what is sent.

Tools

  • Stats dashboard with a 14-day activity chart, per-reason breakdown, and top detected domains.
  • WP Dashboard widget with the same at-a-glance summary.
  • Detection log with date / reason / context filters and CSV export.
  • Optional periodic email digest, daily or weekly.
  • CSV / TXT bulk import for the blocklist and the allowlist.
  • Settings JSON export and import for moving configuration between sites.
  • WP-CLI: wp wpcdeg refresh / test / stats / log / sources / clear-log.
  • HPOS and Cart/Checkout Blocks compatibility declarations.

Privacy

  • No email address is ever sent to a third-party service.
  • The plugin does not contact any external server in its default configuration.
  • If you enable the optional auto-update feature (or click the manual “Update now” button), the plugin issues HTTPS GET requests to raw.githubusercontent.com for the source URLs you have selected. The request body is empty, the User-Agent is WPCoreToolsDisposableEmailGuard/<version>, and no email addresses, user data, or your site URL are transmitted. Full disclosure under “External services” below.
  • The detection log stores the email address, domain, reason, and IP address locally for admin review. Retention is configurable from 7 to 365 days (default 90); a daily WP-Cron job purges older rows.
  • On uninstall, all data is deleted only if you turned on the “Delete data on uninstall” setting.

External services

This plugin can optionally contact one external service. No request is ever made automatically in the default configuration: the recurring auto-update is off by default and must be explicitly enabled via the setup wizard or the Lists tab (Settings → WPCoreTools Disposable Email Guard → Lists → “Auto-update from upstream sources”), and the manual “Update now” button only ever fetches at the moment you click it.

GitHub (raw.githubusercontent.com)

  • What it is: GitHub serves the raw source files of five public, community-maintained lists of disposable-email domains. The plugin downloads only the list files; nothing else.
  • What it is used for: Refreshing the bundled snapshots of the disposable-email lists you have selected, so your active blocklist stays current between plugin releases.
  • When data is sent: In exactly two cases. (1) Scheduled: when the “Auto-update from upstream sources” setting is enabled, WP-Cron fetches the enabled source URLs on the schedule you configure (hourly / twice-daily / daily / weekly). While that setting is off, the recurring cron contacts nothing at all. (2) Manual: when you click the “Update now” / “Refresh now” button (or run wp wpcdeg refresh), a one-time fetch of the enabled sources runs immediately — the click itself is the consent, so this works regardless of the auto-update setting.
  • What is sent: One HTTPS GET request per enabled source URL. The request body is empty. The User-Agent is WPCoreToolsDisposableEmailGuard/<plugin-version>. No email addresses, user data, IP information beyond what GitHub’s CDN normally logs, or your site URL are transmitted.
  • Where the requests go:
    • https://raw.githubusercontent.com/disposable-email-domains/disposable-email-domains/main/disposable_email_blocklist.conf
    • https://raw.githubusercontent.com/7c/fakefilter/main/txt/data.txt
    • https://raw.githubusercontent.com/groundcat/disposable-email-domain-list/master/domains.txt
    • https://raw.githubusercontent.com/wesbos/burner-email-providers/master/emails.txt
    • https://raw.githubusercontent.com/disposable/disposable-email-domains/master/domains.txt
  • Service operator: GitHub, Inc.
  • Terms of service: https://docs.github.com/en/site-policy/github-terms/github-terms-of-service
  • Privacy statement: https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement

If you would rather not contact GitHub at all, leave “Auto-update from upstream sources” off (its default state). The bundled snapshots provide full functionality offline.

You may also add your own custom URLs on the Lists tab (e.g. an internal threat-feed URL or a private gist). Those URLs follow exactly the same rules as the built-in sources: fetched by the recurring schedule only while auto-update is enabled, and by the “Update now” button when you click it. They are entirely under your control.

Installation

  1. Upload the plugin folder to /wp-content/plugins/, or install it via Plugins → Add New.
  2. Activate the plugin.
  3. Visit Settings → WPCoreTools Disposable Email Guard. The first-time setup wizard runs automatically.

The bundled domain lists are active immediately on activation; the plugin works fully offline. Anonymous-provider blocking, plus-addressing checks, dead-domain MX checks, and the optional auto-update of source snapshots are all off by default and must be enabled explicitly.

Frequently asked questions

Does this send my visitors’ email addresses to an external service?

No. Every check runs locally against domain lists that ship inside the plugin file. By default the plugin makes no outbound connections at all.

Does the plugin contact GitHub or any other server in its default configuration?

No. The bundled snapshots are loaded from disk, and nothing is fetched automatically. The optional auto-update feature, which lets WP-Cron contact GitHub to refresh those snapshots on a schedule, is off by default and must be enabled in the setup wizard or the Lists tab. The manual “Update now” button fetches only at the moment you click it. See “External services” for the full disclosure.

Will this block legitimate Proton Mail or Tutanota users?

Only if you turn on the “Anonymous / privacy providers” toggle. It is off by default for exactly that reason.

How are the disposable lists kept up to date?

Two ways. Either install a fresh version of the plugin (each release bundles updated snapshots), or opt into the auto-update feature, which lets WP-Cron fetch the source URLs from GitHub on a schedule (hourly, twice-daily, daily, or weekly).

Can I dry-run before I switch on blocking?

Yes. Set Mode to “Log only” — emails are recorded but no submissions are rejected. Or use “Flag” mode to allow signups but tag the user / order / comment for admin review.

What is “Flag” mode?

A non-destructive alternative to outright blocking. Submissions go through, but matching users get a wpcdeg_flagged user meta and a “Flagged” column on the Users list, comments get a meta tag, and WooCommerce orders get an order note plus a “Flagged” column on the Orders list. Useful when you do not want to lock out potential Proton or Tutanota customers but still want to triage them.

Can existing users get locked out by this plugin?

No. Logging in is never checked — the plugin validates new submissions only: registrations, checkout, comments, profile email changes, and the forms you enable. Existing accounts keep working even if their email provider later appears on a blocklist. Password reset by username is deliberately always allowed (only reset requests typed as an email address are checked), so nobody loses access to an account they already have. If long-standing members use a provider you are now blocking, add that domain to the allowlist.

Does this plugin ever delete users, orders, or comments?

No, never. It only blocks new submissions or flags existing ones for your review — flag and block, never delete. Removing a user, order, or comment is always a manual admin action through the normal WordPress / WooCommerce screens.

Does it work with WooCommerce HPOS?

Yes, both the legacy posts-table orders list and HPOS are supported.

Does it work with Contact Form 7 and Gravity Forms?

Yes, built-in integration on both. For other form plugins (WPForms, Elementor Forms, Forminator, Fluent Forms, etc.), call the wpcdeg_check filter from your form’s email-validation hook.

What happens if a remote list URL is unreachable when auto-update runs?

The previous successful copy is kept (no data loss); the failure is recorded in the per-source meta. If no fetch has ever succeeded, the bundled snapshot continues to be used.

Will it slow down my site?

No. Each email check is an O(1) lookup against an in-memory map, loaded once per request and cached for an hour.

Does the MX record check slow down sign-ups?

Only the first lookup per domain — results are cached for 24 hours on success and 1 hour on failure. Most sign-ups hit the cache immediately. The check is opt-in and off by default.

Changelog

1.0.7

  • Compatibility: Tested with WordPress 7.1 and WooCommerce 11.0.

1.0.6

  • New: the WooCommerce block-based checkout (Store API) is now validated server-side with the same rules, messages, and logging as the classic checkout — previously only the classic checkout hook ran.
  • Fix: subdomains of listed domains (e.g. anything.mailinator.com) now match the blocklist; the allowlist walks parent domains the same way and keeps precedence.
  • Fix: blocked programmatic email changes no longer blank an existing user’s address. Invalid inserts are rejected with a proper error; invalid updates keep the original email, and unchanged emails always pass through.
  • Fix: editing a user whose unchanged email is on a blocklist no longer fails — profile validation now runs only when the email is actually being changed.
  • Fix: wildcard entries the UI documents (@yourcompany.com, *@.ru, spam@) are no longer silently stripped when saving the allowlist or importing lists/settings.
  • Fix: the dead-domain MX check now fails open on DNS resolver outages — a resolver failure is no longer cached as “dead” for an hour.
  • Fix: coupon refusal now also runs on the WooCommerce block-based checkout (Store API), with the same rules and message as the classic checkout.
  • Fix: internationalized (punycode / IDN) domains — e.g. under the .xn--p1ai (.рф) TLD — are no longer dropped when the source lists are parsed, and unicode domains are converted to punycode before comparison when PHP’s intl extension is available.
  • Fix: a list entry equal to a common multi-part public suffix (such as co.uk) can no longer match every address under that suffix.
  • Fix: scan counters now use atomic database increments, so the dashboard and digest scan totals and detection rate stay accurate under concurrent traffic.
  • Fix: daily and weekly schedules (list refresh, log purge, email digest) recompute each occurrence in the site timezone, so they no longer drift an hour off the configured time after DST transitions.
  • Fix: a user whose stored email was blanked by the earlier blanking bug can no longer change it to a blocked address — the update is rejected with a visible error.
  • Fix: the setup wizard’s final page no longer claims lists are “fetching in background” when auto-update is off — it now shows the active bundled-snapshot counts instead.
  • Fix: the detection-log CSV export now honors the active period / reason / context filters and exports every matching row (the previous export ignored filters and stopped at the newest 500 rows).
  • Fix: uninstalling with “Delete data on uninstall” enabled now removes everything it should — the uploads directory including its .htaccess, all plugin transients and counter/cache options, and the flag meta on users, comments, and orders (both legacy and HPOS).
  • Fix: Contact Form 7 integration no longer fatals (PHP 8 TypeError) when the email field is posted as an array.
  • Fix: “Update now” now fetches the enabled sources even while auto-update is off (the click is explicit one-shot consent); the recurring cron no longer fetches anything — including custom URLs — while auto-update is off.
  • Fix: the setup wizard’s list-selection step now rebuilds the active blocklist immediately, so the Done page count and enforcement match your selection.
  • Fix: the CSV import notice now reports the number of entries actually saved after sanitization and warns when nothing was imported.
  • Security: the detection-log CSV export now neutralises spreadsheet formula injection in exported cells.
  • Tweak: the bulk-import “Replace” mode and the settings-JSON import now ask for confirmation and state exactly what will be overwritten (Replace touches only your custom list — never the built-in source lists).
  • Tweak: the clear-log confirmation clarifies that flagged users, orders, and comments keep their flags; the Clear log button no longer disappears when the current filter matches nothing.
  • Tweak: “Whitelist” heading renamed to “Allowlist”; corrected the empty-blocklist notice, wizard step copy, and test-digest notice; External services and FAQ documentation updated to match actual behaviour.
  • Compatibility: Tested with WooCommerce 11.0 and PHP 8.5.

1.0.5

  • Compatibility: Tested with WordPress 7.0 and WooCommerce 10.8. No behaviour changes.

1.0.4

  • Fix: WordPress 6.7+ “Translation loading for the wpcoretools-disposable-email-guard domain was triggered too early” notice. Default block-message strings are now stored as raw English in WPCDEG_Settings::defaults() (which fires on plugins_loaded, before WP’s init action), and translated at display time via the new WPCDEG_Settings::display_message() helper. Translators are unaffected — the literals still appear in WPCDEG_Settings::default_translated_messages() for .pot extraction.
  • Fix: PHP 8.4 deprecation warnings about implicitly-nullable typed parameters (WPCDEG_Stats $stats = null → ?WPCDEG_Stats $stats = null) in WPCDEG_Admin and WPCDEG_Integrations constructors.
  • No behaviour changes — same defaults, same gates, same UI. End users on non-English sites with the default messages still see localized strings (translation now resolves at render time instead of activation time).

1.0.3

  • New: “More tools by WPCoreTools” tab listing the rest of our free, GPL toolkit (Email Verify, Tidy Media, Speedix). Each entry shows whether it’s already active on the site, with one-click activate links and Thickbox modal install for missing plugins.
  • New: companion-aware notice — when WPCoreTools Email Verify is active, the More Tools tab calls out that you have layered protection.
  • Fix: readme Tested up to corrected.
  • No changes to validation, blocklists, or existing settings.

1.0.2

Initial public release.

  • Five bundled disposable-email source snapshots, two enabled by default; works fully offline.
  • Three modes: block, flag, log only.
  • Optional anonymous-provider blocking, plus-addressing checks, dead-MX checks (all off by default).
  • WordPress integrations: registration, profile, comments, lost-password, multisite signup, programmatic user creation.
  • WooCommerce integrations: registration, checkout, My Account email change, product reviews, coupon-abuse blocker, auto-hold for flagged orders. HPOS and Cart/Checkout Blocks compatible.
  • Built-in Contact Form 7 and Gravity Forms integration; generic wpcdeg_check filter for other form plugins.
  • Custom block / allow lists with wildcard support.
  • Detection log with filters and CSV export, stats dashboard with 14-day chart, optional periodic email digest.
  • WP-CLI: refresh, test, stats, log, sources, clear-log.
  • CSV / TXT bulk import; settings JSON export and import.
  • Per-reason customizable user-facing messages; quiet-hour cron scheduling in site timezone.

Full changelog on WordPress.org →

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best WPCoreTools Disposable Email… alternatives

All anti-spam plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Akismet Anti-spam: Spam Protection Akismet Anti-spam: Spam Protection The best anti-spam protection to block spam comments and spam in a contact form. The most… by Automattic 5M+ ★★★★★★★★★★ 4.7 (1.2K) 2 months ago 94
2 Antispam Bee Antispam Bee Sophisticated antispam plugin for effective daily comment and trackback spam-fighting… by pluginkollektiv 700K+ ★★★★★★★★★★ 4.8 (226) 1 month ago 78
3 WP Armour – Honeypot Anti Spam WP Armour – Honeypot Anti Spam Fastest growing Anti Spam plugin. No API calls, subscriptions, captcha or puzzle. Full GDPR… by Dnesscarkey 400K+ ★★★★★★★★★★ 5 (1.5K) 1 month ago 80
4 CF7 Apps – Honeypot, Database, Redirection, Webhook, and Addons for Contact Form 7 CF7 Apps Add hCaptcha, Honeypot, and Redirection to Contact Form 7 with CF7 Apps, and generate forms… by Saad Iqbal 300K+ ★★★★★★★★★★ 3.8 (135) 6 days ago 89
5 Anti-Spam by CleanTalk – Spam Protection Without CAPTCHA Anti-Spam by CleanTalk – Spam Protection Without CAPTCHA Stop spam in contact forms, comments, registrations, and WooCommerce automatically. CAPTCHA… by CleanTalk Inc 200K+ ★★★★★★★★★★ 4.8 (3.2K) 5 days ago 93
6 CloudSecure WP Security CloudSecure WP Security CloudSecure WP Securityは、管理画面とログインURLをサイバー攻撃から守る、国産・日本語対応のセキュリティ対策プラグインです。… by XServer 100K+ ★★★★★★★★★★ 5 (2) 6 days ago 86
7 Gravity Forms Zero Spam Gravity Forms Zero Spam Block form spam in Gravity Forms with an invisible token check, email rejection rules, and… by GravityKit 100K+ ★★★★★★★★★★ 4.3 (24) 1 month ago 84
8 Email Encoder – Protect Email Addresses and Phone Numbers Email Encoder – Protect Email Addresses and Phone Numbers Protect email addresses and phone numbers on your site and hide them from spambots. Easy to… by Online Optimisation 90K+ ★★★★★★★★★★ 4.9 (93) 2 weeks ago 91
9 Spam Protection | Maspik Spam Protection | Maspik Blocks spam the moment you activate it. No CAPTCHA, no setup, no API key. Multi-Layer. Just… by yonifre 30K+ ★★★★★★★★★★ 4.7 (87) 6 days ago 94
10 Blackhole for Bad Bots Blackhole for Bad Bots Blackhole is a WordPress security plugin that detects and traps bad bots in a virtual black… by Jeff Starr 30K+ ★★★★★★★★★★ 4.7 (148) 1 month ago 90

FAQ

WPCoreTools Disposable Email Guard: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 5, 2026

Is WPCoreTools Disposable Email Gu… free?

Yes. WPCoreTools Disposable Email Gu… is free to download and use from the official WordPress.org plugin directory.

Is WPCoreTools Disposable Email Gu… safe to use in 2026?

WPCoreTools Disposable Email Gu… is a solid plugin choice in 2026, with a few things worth checking first. It runs on 10+ sites and was last updated 1 month ago, and scores 62/100 on our health check.

How many websites use WPCoreTools Disposable Email Gu…?

WPCoreTools Disposable Email Gu… is active on 10+ WordPress websites and has been downloaded 455 times since it launched in May 2026. It was downloaded 94 times in the last 30 days.

Does WPCoreTools Disposable Email Gu… work with WordPress 7.1?

Yes. The developer has tested WPCoreTools Disposable Email Gu… up to WordPress 7.1.2, the latest release. It requires WordPress 6.2 or newer.

What PHP version does WPCoreTools Disposable Email Gu… need?

WPCoreTools Disposable Email Gu… requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was WPCoreTools Disposable Email Gu… last updated?

The latest version, 1.0.7, was released on August 23, 2026 (1 month ago).

Who makes WPCoreTools Disposable Email Gu…?

WPCoreTools Disposable Email Gu… is developed and maintained by Wp Core Tools.

What are the best alternatives to WPCoreTools Disposable Email Gu…?

The most popular alternatives to WPCoreTools Disposable Email Gu… are Akismet Anti-spam: Spam Pro… (5M+ installs), Antispam Bee (700K+ installs) and WP Armour (400K+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.