StopReg is a powerful email validation API that helps you
detect and block disposable, temporary, and fake email
addresses in real-time. This documentation will guide you
through integrating StopReg into your application to protect
your platform from spam, fraud, and abuse.
What is StopReg?
StopReg provides businesses and individuals with tools and
resources for detecting and blocking disposable email
providers. Our API validates email addresses instantly
(typically within milliseconds), allowing you to block
disposable emails during signup, checkout, or form submission.
Key Features
Real-time Validation: Instant email
checking with millisecond response times
Comprehensive Database: Over 124,000
disposable email domains in our database
Privacy-Focused: We don't store full email
addresses - only check the domain part
Easy Integration: Simple REST API that
works with any programming language
Whitelisting Support: Whitelist trusted
domains to ensure legitimate users are never blocked
Make your first API call to validate an email address
The API endpoint is simple and secure. You'll use a
POST request with your API token in the header and the email address in the body. Continue reading the
next sections to learn about
authentication, endpoints, and code examples.
API Authentication
StopReg uses API token-based authentication. Your API token is
unique to your account and should be kept secure. Never share
your API token publicly or commit it to version control
systems.
Navigate to the API section or locate the API token on
your Dashboard home
Copy your API token (you can regenerate it at any time if
needed)
Using Your API Token
We recommend using the x-api-token header for all requests. This keeps your token out of
URL logs and follows industry standards.
Headers:x-api-token: YOUR_API_TOKEN
Security Best Practices
Keep it Secret: Treat your API token like a
password - never expose it in client-side code
Use Environment Variables: Store your API
token in environment variables, not in your source code
Regenerate if Compromised: If you suspect
your token has been exposed, regenerate it immediately from
your dashboard
Server-Side Only: Always make API calls
from your server-side code, never from the browser
Rate Limits
Rate limits depend on your subscription plan. Free trial
accounts have limited requests per day, while paid plans offer
higher limits or unlimited requests. Check your dashboard for
your current rate limit status.
API Endpoints
StopReg provides a simple REST API endpoint for email
validation. All endpoints use HTTPS and return JSON responses.
Email Verification
Endpoint:
POST https://api.stopreg.com/api/v1/verify/email
Domain Verification
Endpoint:
POST https://api.stopreg.com/api/v1/verify/domain
Body Parameters (JSON)
email (string, required for /email): The
email address to validate
domain (string, required for /domain): The
domain name to validate (e.g., example.com)
Request Example
POST https://api.stopreg.com/api/v1/verify/email
Headers:x-api-token: YOUR_API_TOKENContent-Type: application/jsonBody:
{ "email": "test@example.com" }
Response Format
The API returns a JSON response with the following structure:
When integrating StopReg into your registration or signup
forms, validate the email address before allowing the user to
complete registration. If classification.is_disposable is
true, show an error message asking the user to
use a valid email address.
Best Practices & Troubleshooting
Follow these best practices to ensure optimal performance and
reliability when using the StopReg API.
Best Practices
Validate on Server-Side: Always perform
email validation on your server, never in client-side
JavaScript. This protects your API token and ensures
security.
Handle Errors Gracefully: Implement proper
error handling for network failures, rate limits, and API
errors. Provide user-friendly error messages.
Cache Results When Appropriate: For
frequently checked domains, consider caching results to
reduce API calls and improve performance.
Use Whitelisting: Whitelist trusted
corporate domains to prevent false positives and ensure
legitimate users are never blocked.
Monitor Rate Limits: Keep track of your API
usage to avoid hitting rate limits. Upgrade your plan if
needed.
Validate Email Format First: Check basic
email format before calling the API to save unnecessary
requests.
Common Use Cases
Registration Forms: Validate emails during
user signup to prevent fake accounts
Checkout Processes: Block disposable emails
during e-commerce checkout
Free Trial Signups: Prevent abuse of free
trial offers
Support Ticket Systems: Verify contact
emails for support requests
Troubleshooting
API Returns Error
Verify your API token is correct and active
Check that the email parameter is properly URL-encoded
Ensure you're using the correct endpoint URL
Check your rate limit status in the dashboard
Slow Response Times
Check your network connection
Verify you're using HTTPS (not HTTP)
Consider implementing request timeouts and retries
False Positives
Use the whitelist feature for trusted domains
Report false positives through your dashboard
Check if the domain is actually disposable before blocking
Support
If you need additional help or have questions, contact our
support team at
support@stopreg.com
or visit your dashboard for more resources.
Frequently Asked Questions
Your questions around disposable email, answered.
A disposable email blocker is a tool that automatically detects
and blocks temporary, fake, or throwaway email addresses from
signing up on your website. This helps you maintain a clean user
database, reduce spam, and protect your platform from abuse.
Disposable emails are commonly used for fraud, spam, duplicate
account creation, free-trial abuse, and bot signups. Blocking
them helps you:
Improve lead quality
Reduce fraud and abuse
Protect your free trials
Increase conversion accuracy
Improve email deliverability
Yes. The API validates emails instantly (typically within
milliseconds), allowing you to block disposable emails during
signup, checkout, or form submission.
Yes. You can whitelist domains you trust to ensure legitimate
users are never blocked by mistake.
No. We do not store full email addresses. For privacy and
compliance, we only check the domain part and discard all data
immediately.
No. Only temporary and fake domains. Corporate, ISP, and custom
domain emails are always allowed unless they appear in known
disposable lists.
Yes. We offer flexible plans, including:
Monthly subscription
Unlimited requests for enterprise users
Yes. Feel free to test the free trial and see how many fake
signups you prevent within minutes.