Skip to content
Writing
NewAPISecurityDeliverabilityTypeScriptNode

Building a Role-Based and Disposable Email Detection API: Deliverability Protection with SadaSend

Disposable and role-based emails cause 3x higher spam complaints that trigger Gmail/Yahoo domain penalties. Here is how to detect them at signup and block bad sends with SadaSend.

Tayyab MughalFounder & AI Chief3 min read

Why role-based and burner emails destroy deliverability

When users sign up with disposable burner emails (Mailinator, GuerrillaMail, 10MinuteMail) or functional role-based addresses (admin@, support@, billing@), your deliverability metrics suffer immediately.

Role-based addresses are shared by multiple team members or automated ticket systems. When a new recipient receives an onboarding email they didn't personally request, they click 'Report Spam'. Role-based emails have 3x higher spam complaint rates than personal addresses, quickly pushing your domain past Google's strict 0.3% spam threshold.

Disposable emails are abandoned after 10 minutes, generating hard bounces on all subsequent transactional messages and tanking your domain reputation.

The 3 layers of modern email verification

  • Layer 1: Real-Time Disposable Domain Filtering. Comparing incoming domains against a continuously updated database of 180,000+ temporary email providers and analyzing MX infrastructure fingerprints.
  • Layer 2: Role-Based Prefix Heuristics. Matching the local part against known functional prefixes (info@, sales@, billing@, compliance@, security@).
  • Layer 3: SMTP Handshake Probing without Sending. Connecting to the recipient's mail exchanger on port 25 and issuing HELO → MAIL FROM → RCPT TO to verify mailbox existence, combined with a randomized probe to detect catch-all domains.

Implementing pre-send hygiene with SadaSend

Instead of writing complex SMTP socket scrapers or paying high per-lookup fees to legacy fraud APIs, you can enforce recipient verification directly before sending via SadaSend:

TYPESCRIPT
// Validate and filter recipient before dispatching
import { isDisposableEmail, isRoleBasedEmail } from '@/lib/email-hygiene';

export async function sendUserReceipt(toEmail: string, orderData: Order) {
  // Pre-flight hygiene check
  if (isDisposableEmail(toEmail)) {
    throw new Error('Disposable burner emails are not permitted for order receipts.');
  }

  // Dispatch via SadaSend with built-in deliverability protection
  const res = await fetch('https://api.sadasend.com/v1/emails', {
    method: 'POST',
    headers: {
      'Authorization': `Bearer ${process.env.SADASEND_API_KEY}`,
      'Content-Type': 'application/json',
      'Idempotency-Key': `receipt:${orderData.id}`,
    },
    body: JSON.stringify({
      to: toEmail,
      from: 'receipts@yourdomain.com',
      subject: `Your receipt for Order #${orderData.id}`,
      html: `<p>Thank you for your purchase of ${orderData.amount}.</p>`,
    }),
  });

  return res.json();
}

How SadaSend protects your domain automatically

SadaSend maintains an automated account-wide suppression list that records hard bounces, spam complaints, and unsubscribe requests across all your sending keys. When your code or an autonomous AI agent attempts to send to a suppressed address, SadaSend intercepts the call and rejects it instantly at the API gateway.

This guarantees that dirty recipient data never reaches external mail servers, keeping your bounce rate under 0.1% and safeguarding your Gmail and Yahoo sender reputation.

Early Access

Building AI agents that send email?

Join the SadaSend early access waitlist to get scoped API keys, recipient allowlists, and Model Context Protocol (MCP) servers upon launch.

Use Case:
One email when it opens
Social Hashtags & Share
#EmailAPI#DeveloperTools#API#AppSec#CyberSecurity#AICompliance
Tayyab MughalFounder & AI Chief

Building SadaSend — transactional email with an MCP server that has a ceiling. Writes about deliverability, email infrastructure, and what happens when you hand an autonomous agent a sending credential.