Firebase Auth · TypeScript
Block disposable email in Firebase Auth
Use a Firebase Cloud Function with the beforeUserCreated blocking trigger. Throw HttpsError to reject before Firebase persists the user.
The code
// functions/src/index.ts
import { beforeUserCreated, HttpsError } from "firebase-functions/v2/identity";
import { defineSecret } from "firebase-functions/params";
const piisendKey = defineSecret("PIISEND_API_KEY");
const PIISEND_URL = "https://api.piisend.com/api/v1/intelligence/email";
export const blockDisposable = beforeUserCreated(
{ secrets: [piisendKey] },
async (event) => {
const email = event.data.email;
if (!email) return;
try {
const r = await fetch(PIISEND_URL, {
method: "POST",
headers: {
Authorization: `Bearer ${piisendKey.value()}`,
"Content-Type": "application/json",
},
body: JSON.stringify({ email }),
});
if (r.ok && (await r.json()).signals?.disposable) {
throw new HttpsError("invalid-argument", "Please use a permanent email address.");
}
} catch (e) {
if (e instanceof HttpsError) throw e;
// fail open on network errors
}
},
);API key
Store `PIISEND_API_KEY` in Firebase Secret Manager via `defineSecret`.
Fail-open vs fail-closed
Only re-throw HttpsError for confirmed disposable hits.
Pair with verification
Enable blocking functions in Firebase console and deploy to your auth region.
Send verification email with Piisend
After blocking disposable addresses, send OTP and verification mail through the same Piisend account. One API key for intelligence checks and transactional sends.