Auth0 · JavaScript
Block disposable email in Auth0
Use an Auth0 Pre User Registration Action. Runs synchronously before Auth0 creates the user — return api.access.deny() to reject at the auth layer.
The code
/**
* Auth0 Action — Login / Post Login > Pre User Registration
* Add PIISEND_API_KEY to Action Secrets
*/
exports.onExecutePreUserRegistration = async (event, api) => {
const email = event.user.email;
if (!email) return;
try {
const res = await fetch("https://api.piisend.com/api/v1/intelligence/email", {
method: "POST",
headers: {
Authorization: `Bearer ${event.secrets.PIISEND_API_KEY}`,
"Content-Type": "application/json",
},
body: JSON.stringify({ email }),
});
if (res.ok) {
const data = await res.json();
if (data.signals?.disposable) {
api.access.deny("Please use a permanent email address.");
}
}
} catch (e) {
// fail open — omit deny on error
}
};API key
Add `PIISEND_API_KEY` under Action Secrets in the Auth0 dashboard.
Fail-open vs fail-closed
Omit `api.access.deny` when fetch fails unless your policy requires fail-closed.
Pair with verification
Deploy the Action to Pre User Registration and test with a known disposable domain.
Send verification email with Piisend
After blocking disposable addresses, send OTP and verification mail through the same Piisend account. One API key for intelligence checks and transactional sends.