Skip to main content

How throwaway providers rotate domains to outrun static lists

Published Updated 18 minute readGuidesRichelo Killian

Throwaway email providers treat domains the way their users treat inboxes: as consumables. A provider registers cheap domains in bulk, points them at mail infrastructure it already runs, serves signups through them until they are blocked or no longer useful, then abandons them and registers more. In August 2026 we measured the footprint of that behavior directly: 10,864 genuinely new disposable email domains appeared in a single 34 day window, and not one day in that window produced zero. Rotation is the reason a static blocklist starts decaying the moment you download it, and this article explains the mechanics, the economics, the wreckage it leaves behind, and what actually keeps up with it.

I have spent more than fifteen years in email deliverability, and the single most common mental model error I see is treating disposable domains as a fixed population you can enumerate once. They are not a population; they are a flow. Everything below is about that flow, and every number in it comes from our monthly public data reports, the August 2026 and September 2026 editions, so you can check the methodology yourself.

Why do disposable providers rotate domains at all?

Because the domain is the only part of their stack that defenders can effectively block, and it is also the cheapest part to replace. That asymmetry drives everything.

Think about what a throwaway email service actually consists of. There is real infrastructure underneath: mail servers, storage, a web frontend, sometimes an API. That layer is expensive to build and slow to move, and providers do not want to touch it. Then there is the domain layer on top: the part users type after the @ sign, and the part that lands on blocklists. When sometempdomain.example gets blocked by enough signup forms, the provider does not rebuild anything. It registers a new name, points the new name's Mail Exchanger (MX) records at the same backend it was already running, and carries on. The service is unchanged; only the label moved.

From the provider's side this is rational to the point of being boring. A blocklist entry kills one domain, not the service, so the counter to being blocked is simply supply: hold a pool of interchangeable front-end domains, cycle through them, and keep registrations flowing so the pool never empties. From the defender's side it means the thing you blocked yesterday tells you nothing about what you will see tomorrow, unless your detection looks below the domain name, which is a point we will come back to.

How fast do new disposable email domains appear?

Continuously, and faster than most people guess. In our 34 day observation window from July 6 to August 8, 2026, after excluding the one time bulk import that seeded the dataset, we recorded 10,864 new disposable email domains, an average of 319.5 per day. Two of those days were one time intake events on our side rather than organic discovery, a single upstream list refresh that added 722 domains and a newly added source that contributed 4,200, so the cleaner rotation signal is the other 32 days, which still averaged 185.7 genuinely new domains every single day. And that rate is not a one month artifact: the September 2026 edition measured the following window, August 1 to September 5, and found 10,223 more new domains in 36 days, with the steady rate at 185.1 per day once its own single intake event is excluded. Two windows, ten weeks, and the flow held to within one domain per day.

Measurement, July 6 to August 8, 2026 Value
New disposable domains detected in the 34 day window 10,864
Average per day, whole window 319.5
Average per day excluding two one time intake events 185.7 across the remaining 32 days
Days in the window with zero new domains 0
New domains still able to receive mail on report day 9,141 of 10,864

Two rows in that table deserve a second look. The zero row is the rotation thesis in one number: there was no pause, no quiet week, no moment when the supply of new disposable email domains stopped. And the last row matters just as much: 9,141 of the 10,864 new domains still passed live MX validation on report day. These are not junk registrations that never worked. They are working, mail-receiving domains, which is exactly what makes them dangerous to a signup form and exactly what a list downloaded before they existed cannot contain.

What does domain rotation actually look like in practice?

It looks like many new names converging on a small amount of shared mail infrastructure. When we grouped the window's new domains by the registrable root of the first mail host they resolve to, a short head of clusters emerged, and that clustering is the observable signature of the front-end pool pattern: lots of interchangeable domains, few backends.

Mail infrastructure (MX root) New domains routed through it in 34 days
cleantempmail.com 719
cloudflare.net 597
catchmail.io 455
215.im 391
emailsrvr.com 241
unstablemail.com 238
titan.email 236
above.com 195
registrar-servers.com 187
blackhole.mx 164

Read that table with the caveat we attached to it in the report, because it is easy to over-interpret. A cluster names shared mail infrastructure, not necessarily a disposable operator. Some of these roots look like exactly what they are, dedicated temp-mail backends collecting hundreds of fresh front-end names in a month. Others, cloudflare.net and emailsrvr.com among them, are commodity mail and routing services that disposable operators simply run their mail through; the domains are disposable, the infrastructure provider is not. And 2,408 of the window's new domains had no mail host at all by report day, so they sit outside any cluster, some already dead within weeks of appearing, which is the churn doing its work in fast forward.

The practical lesson sits in the biggest clusters. When one backend receives 719 new front-end domains in 34 days, blocking any individual domain in that pool accomplishes almost nothing, because the pool is the unit that matters. That is what rotation is: the pool persists, the names are traffic.

Why is rotation so cheap for providers?

Because the raw material costs almost nothing, and the top level domain (TLD) distribution of the dataset shows exactly where the cheapness lives. Across all 211,812 domains we tracked in August 2026, the top five TLDs held 55.15 percent of everything, and the roster is a price list as much as a popularity chart. .com leads at 37.01 percent because it is abundant, unremarkable, and cheap in bulk. Behind it come the budget new TLDs .xyz and .site, perennially discounted to a dollar or two, and the historically free country codes .ml, .tk, and .ga, which at their peak cost literally nothing to register. When a domain costs a dollar and the service earns from ads or subscriptions on the other side, burning a blocked domain is not a loss event. It is routine consumption, like a restaurant going through napkins.

The mix among brand new domains is the more interesting signal, because it shows rotation chasing whatever is cheap and available right now rather than staying loyal to history.

TLD Share of new detections, 34 day window Share of full dataset
.com 34.88% 37.01%
.org 5.96% 3.03%
.uk 4.42% 0.65%
.id 1.93% 0.73%
.ru 1.89% 5.43%

.uk was running at nearly seven times its historical weight among new detections, and .id at almost three times, while .ru, a heavyweight of the accumulated corpus, had faded to a third of its overall share. I am wary of telling a tidy story about why any single TLD is hot in any single month, because registrar promotions, policy changes, and operator preferences all move this around. The durable point is that it moves. Where new disposable email domains concentrate today is not where the historical mass sits, and any defense tuned to yesterday's distribution, including a mental model like "throwaways are all .tk and .xyz," will quietly lag reality.

What happens to the domains left behind?

They pile up into a graveyard, and the graveyard is most of the dataset. Of the 211,812 disposable domains we tracked in August 2026, only 73,110, which is 34.52 percent, could still receive mail. 135,083, or 63.77 percent, were dead: no mail route at all for most of them, and an explicit null MX record for 3,271, the DNS declaration that a domain accepts no mail. That is what years of rotate-and-abandon accumulates into. Nearly two of every three disposable domains ever cataloged are already corpses.

The graveyard is not just a curiosity; it has two practical consequences. First, it means raw list size is a vanity metric. A huge disposable email domains list is mostly a museum of domains that can no longer receive anything, and blocking a dead domain protects you from nothing, because mail to it was never going to be delivered anyway. Second, and worse, dead entries are latent false positives. Expired domains return to the open market, and when a legitimate business re-registers a name that spent a year as a throwaway, every stale list still carrying it will block that business's real customers. The mechanics of how a dead domain announces itself, and why "no MX record" is not the same thing as dead, are their own topic, covered in our null MX pillar.

Here is the honest limit of what we can say about lifespan today: no longer nothing, but still early. Per domain aliveness history did not exist for the August report; a recheck job has been collecting it since August 9, and the September edition published the first readings. Of 77,893 domains first observed alive and rechecked since, 1.84 percent were dead again at their latest recheck, over a median observation span of just 17 days, an early floor rather than a lifespan estimate. And the churn runs both ways: in the September window, 1,686 tracked domains went from alive to dead while 1,215 came back from dead to alive, which is the graveyard's false positive risk caught in the act. Full mortality curves arrive as the history grows.

Why do static lists lose this race?

Structurally, not through any failing of the people who maintain them. A static list is a snapshot of a flow, and the flow does not stop while the snapshot sits in your repository. In August 2026 we measured three widely used free blocklists against the same live MX sweep, and the freshness result is the cleanest demonstration of rotation beating enumeration that I have ever had numbers for.

Free blocklist Entries New domains from our 34 day window it contained
disposable-email-domains 8,201 222 of 10,864
disposable/disposable 74,688 419 of 10,864
mailchecker 56,356 4 of 10,864

The best of the three had captured 419 of the 10,864 new domains, under four percent. The most widely bundled library list had captured 4. Not four percent, four domains. A month later, the September edition re-ran the same measurement on the next window: 763 of 10,223 for the best list, and 1, a single domain, for the most widely bundled one. And this is not a size problem: the largest of the three carries 74,688 entries and was still missing 61.16 percent of all the disposable domains that were live on measurement day. Size buys you a bigger museum. It does not buy you tomorrow morning's registrations, because nothing static can contain domains that did not exist when it was built.

This is also why re-downloading more often helps less than people expect. Pulling a fresh copy weekly resets your snapshot, but the list itself only knows what volunteers have found and merged, and at roughly 186 organic new domains a day, the gap between what exists and what any human-curated file contains regrows continuously. The full comparison, including dead weight and false positive risk, is in Free disposable email lists vs a live detection API; the one sentence version is that a list is a great tool for scrubbing the past and a poor tool for guarding the present.

How can new disposable domains be caught on day one?

By looking at what rotation cannot cheaply change: the infrastructure underneath the name. Remember the asymmetry from the top of this article. Providers rotate domains because domains are cheap and backends are not, which means the backend is the stable, observable thing. A brand new domain is anonymous for about as long as nobody looks up its DNS. The moment you resolve its MX records and find them pointing at mail infrastructure already known to serve disposable traffic, the new name has told you what it is, on day one, before any human has submitted it to any list.

That is the core of how live detection outruns rotation, and it is why MX validation shows up in every serious approach. In practice, catching the flow takes three things working together: DNS-level checks at lookup time, so a new domain's infrastructure affiliations are visible immediately; aggregation across multiple upstream sources, so discovery does not depend on any single community's attention; and daily refresh of the whole dataset, so dead domains fall out as fast as new ones arrive, which keeps the false positive graveyard from building up on your side. None of this requires probing mailboxes or sending anything; it is all readable from public DNS. A fuller treatment of the detection stack, including the signals beyond MX, lives in The Complete Guide to Disposable Email Detection.

I want to be precise about the claim here, because zero hype is a house rule. Infrastructure fingerprinting does not catch literally every new domain on its first day; a provider standing up an entirely new backend gets a window of anonymity, and the 2,408 clusterless new domains in our window show the edges of the technique. What it does is collapse the economics. Rotation works because each new domain is nearly free and buys a useful period of invisibility. When pointing a new name at an existing backend gets it flagged within a day, the invisible period shrinks toward zero, and the provider's cheapest move stops paying.

Does domain rotation hurt your sender reputation at Gmail?

No, and it is worth being exact about where the damage from rotation actually lands, because this is the most misdiagnosed risk in the entire topic. Rotation hurts you on a delay, through your list quality, at your Email Service Provider (ESP), not at the mailbox providers.

Walk the timeline. A rotated-in domain is brand new, so your static defenses miss it and the signup lands in your database looking clean. Weeks later the provider has rotated onward, the domain is abandoned, and it joins the 63.77 percent. Your next campaign mails it and takes a hard bounce, and a batch of such signups produces a bounce spike. Gmail, Outlook, and Yahoo never see any of this in a way that touches your standing with them; mailbox providers judge you on how their own users receive and engage with your mail, and a dead throwaway domain has no users at any of them. The entity that does see it is your ESP. Mailchimp, SendGrid, and their peers police bounce rates aggressively because shared sending infrastructure makes your list quality their problem, and a spike reads to their automated compliance systems like a purchased or badly maintained list. The consequences run from a warning to a throttle to a forced cleaning to a suspended account, and a suspension during a launch is the expensive version of this story.

So the reason to care about new disposable email domains is not a Gmail reputation score, which was never in danger. It is that every rotated domain you fail to catch at signup is a future hard bounce with your ESP's name on it.

Are relay services part of the rotation problem?

No, and the contrast is instructive, because relays are what non-rotation looks like. Apple Hide My Email, Firefox Relay, SimpleLogin, addy.io, DuckDuckGo Email Protection, and Proton aliases give a real person a permanent masked address that forwards to the inbox they actually read. In August 2026 we tracked exactly 12 relay domains across those 6 provider families. Twelve stable domains, against 10,864 new disposable domains in a single month. Relay providers do not rotate because they have nothing to outrun: their domains are meant to be recognized, their addresses are meant to last, and the person behind one is a privacy-conscious, frequently paying customer whose mail gets delivered.

This is why conflating relays with disposables is such an expensive mistake, and why we detect and flag them as a separate category with the explicit advice not to block them. A filter that treats "masked" as "throwaway" takes the twelve most stable, most legitimate domains in this entire landscape and puts them in the same bucket as the churn. Block the flow, welcome the relays, and if anyone on your team proposes otherwise, the relay section of the complete guide is the link to send them.

What should you do about rotation if you run signup forms?

Accept that you are defending against a flow, and pick tools that move at the flow's speed. Concretely, that means four things. Check addresses at the moment of signup with a live lookup rather than a bundled file, because signup time is the only moment you can decline an address cheaply. Act on the verdict, blocking confirmed throwaways with a clear human message and letting everything else through. Keep the check fail-open with a tight timeout, so a slow or unavailable lookup never costs you a real signup; the check protects the list, it must never break the form. And let relay addresses pass, deliberately, as covered above. If you want the wiring, we maintain copy-pasteable implementations for Next.js and Node.js with Express, and the same pattern ports to any stack in an afternoon.

If you would rather not build the moving parts yourself, this is the problem isitdisposable.com exists for: a live dataset of more than 217,000 domains drawn from six upstream sources, validated against live MX records and refreshed daily, so the domains registered this morning are handled by the same mechanism as the ones from five years ago. It returns relay as its own signal, fails open by design, and takes one API call or a JavaScript snippet to integrate. The free plan includes 250 lookups per month, and the 14-day full-access trial needs no credit card, which is enough to watch a few weeks of your own signup traffic and see the rotation arrive in real time.

Frequently asked questions about new disposable email domains

How many new disposable email domains appear each day? In our measured 34 day window in mid 2026, an average of 319.5 per day overall, and 185.7 per day of organic discovery once two one time intake events are excluded. No day in the window produced zero.

How long does the average disposable domain stay alive? Honestly: measurement has only just begun. Our recheck history started collecting in August 2026, and the first early readings in the September report show 1.84 percent of a 77,893 domain alive cohort dead again at their latest recheck, over a median observation span of 17 days, an early floor, not a lifespan estimate. The strict 30 day mortality figure becomes computable in the next edition, and lifespan curves follow as the history grows.

Why do providers use thousands of domains instead of one? Because one domain is one blocklist entry away from dead, while a pool of interchangeable domains on a shared backend survives any individual block. The domain is the cheapest, most replaceable layer of the service, so it absorbs all the attrition.

Where do new disposable domains concentrate? On cheap TLDs and shared mail infrastructure. In our window, .com led new detections at 34.88 percent, .uk ran at nearly seven times its historical share, and the top backend cluster alone received 719 new front-end domains in 34 days.

Can a blocklist ever keep up with rotation? Not structurally. The best free list we measured contained 419 of the window's 10,864 new domains, and the most widely bundled one contained 4. A snapshot cannot contain domains that did not exist when it was taken; only a live lookup evaluated at signup time moves at the same speed as the flow.

About the author

Richelo Killian

Founder

Founder of isitdisposable.com and the SenderWorx email tool suite. Builds email infrastructure and anti-abuse tooling.