Block Disposable Emails on Shopify
To block disposable emails on Shopify, add one script tag to your theme so it gates the forms where fake addresses actually enter: customer account registration and your newsletter and lead capture forms. Be clear about the platform limit up front, because plenty of guides are not: Shopify does not let you intercept checkout itself, so nothing in this guide touches a buyer mid-purchase. For everything the theme cannot gate, Shopify Flow can flag suspect customers for review the moment they are created. All three paths below fail open, so a slow or unreachable check never costs you a signup, and never a sale.
Why do Shopify stores attract fake signups?
Because stores pay for email addresses in discounts, and disposable addresses are how people collect the payment without becoming customers. The welcome popup offering 10 percent off is the Shopify-specific honeypot: one person with a throwaway provider can farm your welcome code today, tomorrow, and every day after, each time as a brand new address, and refer-a-friend credits and free-shipping thresholds farm the same way. The leftovers are Shopify fake customer accounts and Shopify newsletter spam signups that pollute your Klaviyo or Shopify Email lists, where you pay by contact and by send for subscribers who were never people. The supply is effectively unlimited: as of the September 2026 State of Disposable Email report, the dataset behind this guide tracked 217,847 disposable domains, with 10,223 new ones appearing in a single 36-day window, and 9,971 of those new domains were live, working mail destinations on report day. A code-farming address is deliverable on the day it claims your discount, which is exactly why simple format checks wave it through.
What can you actually gate on Shopify?
Two surfaces, honestly stated. First, the forms your theme renders: the classic customer registration form at /account/register and every newsletter or lead capture form in your sections, including the footer signup. A script in your theme can gate all of these. Second, nothing at checkout: Shopify does not allow merchant scripts to intercept the checkout flow, and any tool claiming to block throwaway emails inside checkout on a standard plan is overpromising. One more modern wrinkle: if your store uses Shopify's new passwordless customer accounts, that login lives on Shopify-hosted pages outside your theme, so the snippet cannot reach it. That is precisely the gap the Flow path covers, because Flow sees every customer record the moment it is created, no matter which door it came through.
How do you add the snippet in the theme editor?
Generate your tag in the dashboard, where the publishable key, mode, and visitor message are baked in, and it comes out shaped like this:
<script src="https://cdn.isitdisposable.com/v1/snippet.js"
data-key="pk_live_your_publishable_key"
data-mode="warn"
async></script>
Then, in your Shopify admin: Online Store, Themes, click the three dot menu on your current theme, Edit code, open Layout, then theme.liquid, paste the tag just above the closing head tag, and Save. That covers every page the theme renders. If you would rather not touch code files at all, the theme editor's Custom Liquid block does the same job for a single template: Customize, add a Custom Liquid block to the page with the form, and paste the tag there.
Out of the box, the snippet finds the email inputs in your theme's forms, checks each address as the visitor types using your publishable key, which is safe in a storefront because it only works from origins you approve, and applies your configured mode. Allow is invisible. Warn shows your message, a nudge toward a permanent address, and lets the signup proceed. Block shows the message and stops the submit, reserved for confirmed throwaways. To see it work, register with [email protected], the canonical disposable provider, whose public record you can browse at isitdisposable.com/d/mailinator.com.
How do you flag fake customers with Shopify Flow?
Flow acts after the fact, which makes it the path that works everywhere, including the passwordless account pages and any app-created customers no form ever gated. Flow shipped as a Plus exclusive for years, but Shopify now includes it on all paid plans, so most stores have it waiting in the admin. Build one workflow:
- Trigger: Customer created.
- Action: Send HTTP request. Method POST, URL https://api.isitdisposable.com/v1/check, headers Content-Type: application/json and Authorization: Bearer sk_live_your_secret_key, body {"email":"{{ customer.email }}"}.
- Condition on the response: the simplest reliable check is whether the response body contains "action":"block".
- If it does: Add customer tags, something like disposable-review, and optionally send an internal email so a human looks before this customer receives codes, credits, or store privileges.
Note what this path can and cannot do. It cannot block, because the customer record already exists when Flow fires; it flags, which for Shopify fake customer accounts is usually enough, since the tag can exclude them from discount eligibility, loyalty programs, and your email segments in one stroke. Use your secret key here, the sk_ one, because Flow runs server-side in Shopify's infrastructure, never in a shopper's browser.
Can apps and custom storefronts call the API directly?
Yes, and if you have developers, this is the strongest gate of all: a custom app, a Hydrogen or headless storefront, or your own signup service can call the same POST /v1/check with a secret key and refuse the registration server-side before the account exists, the same pattern our stack guides walk through for other platforms. One paragraph is all this path needs here because, if it applies to you, your developers can pull it from the API docs in an afternoon.
Which path should you choose?
| Path | Plan requirement | Where it acts | Block or flag |
|---|---|---|---|
| Snippet in the theme | Any plan with an online store | At the form, before signup | Blocks or warns, per your configured mode |
| Shopify Flow workflow | Paid Shopify plans (Flow installed) | After customer creation, in your admin | Flags and tags for review; cannot block |
| App or custom storefront via API | Any plan, developer required | Server side, before the account exists | Blocks outright |
Most stores should run the first two together: the snippet stops throwaways at the forms shoppers actually use, and Flow catches everything that arrives through doors no form guards. They are one tag and one workflow, and they do not overlap so much as interlock.
Should you block relay addresses like Apple Hide My Email?
Never, and in ecommerce this rule has teeth. Relay and alias services, Apple Hide My Email, Firefox Relay, SimpleLogin, addy.io, DuckDuckGo Email Protection, Proton aliases, forward to a real person's permanent inbox, and the shopper behind an Apple relay address is an iCloud+ subscriber holding a payment method. Blocking relays to stop code farmers throws away exactly the privacy-conscious buyers you want, which is why the check reports relays as their own signal and the default policy warns rather than blocks. Leave that default alone, and if anyone on your team or your agency proposes a blanket block, the relay section of The Complete Guide to Disposable Email Detection is the link to settle it.
What happens if the check is unavailable?
Your store keeps selling, full stop. The service is designed to degrade into permission: an exhausted quota or an overloaded moment comes back as a normal answer with the action set to allow, so the snippet lets the form submit, and the Flow condition simply does not match. If the check cannot complete at all, the snippet steps aside, and the form behaves exactly as your theme built it, and the Flow path never had the power to interrupt anything in the first place. A validator that could cost you a sale would be worse than the problem it solves, and this one is built so it cannot.
The cost of skipping all this does not show up where merchants usually look. Farmed discount codes are margin walking out the door, and the dead throwaways left on your list hard bounce in a batch on your next campaign, which is a list quality signal platforms like Klaviyo and Mailchimp act on with warnings, forced cleanings, or paused sending. Your Gmail reputation was never the issue; your standing with your own email platform is. The check behind every path in this guide is isitdisposable.com, a live dataset of 217,847 disposable domains per the September report, drawn from multiple upstream sources, MX-validated and refreshed daily, and the free plan of 250 lookups a month plus a 14-day full-access trial, no credit card, is enough to watch a store's real signup traffic and count the code farmers you have been paying.
About the author
Richelo Killian
Founder
Founder of isitdisposable.com and the SenderWorx email tool suite. Builds email infrastructure and anti-abuse tooling.