Auth0 · JavaScript

Block disposable email in Auth0

Use an Auth0 Pre User Registration Action. Runs synchronously before Auth0 creates the user — return api.access.deny() to reject at the auth layer.

The code

/**
 * Auth0 Action — Login / Post Login > Pre User Registration
 * Add PIISEND_API_KEY to Action Secrets
 */
exports.onExecutePreUserRegistration = async (event, api) => {
  const email = event.user.email;
  if (!email) return;

  try {
    const res = await fetch("https://api.piisend.com/api/v1/intelligence/email", {
      method: "POST",
      headers: {
        Authorization: `Bearer ${event.secrets.PIISEND_API_KEY}`,
        "Content-Type": "application/json",
      },
      body: JSON.stringify({ email }),
    });
    if (res.ok) {
      const data = await res.json();
      if (data.signals?.disposable) {
        api.access.deny("Please use a permanent email address.");
      }
    }
  } catch (e) {
    // fail open — omit deny on error
  }
};

API key

Add `PIISEND_API_KEY` under Action Secrets in the Auth0 dashboard.

Fail-open vs fail-closed

Omit `api.access.deny` when fetch fails unless your policy requires fail-closed.

Pair with verification

Deploy the Action to Pre User Registration and test with a known disposable domain.

Send verification email with Piisend

After blocking disposable addresses, send OTP and verification mail through the same Piisend account. One API key for intelligence checks and transactional sends.