auth

Block personal emails in Auth0

Use an Auth0 Action on the Pre User Registration trigger to deny personal, disposable and relay emails with isBusinessEmail, and tag work emails.

isBusinessEmail for Auth0

Auth0 Actions run your code during authentication flows. The Pre User Registration trigger runs before a user is created in a database or passwordless connection, which is exactly where a work-email check belongs.

1. Store the key as a secret

In the Action editor, add a secret named IBE_API_KEY with your ibe_live_… key. Never hard-code it.

2. The Action

Create an Action on the Pre User Registration trigger:

exports.onExecutePreUserRegistration = async (event, api) => {
  const email = event.user.email;
  if (!email) return;

  let verdict;
  try {
    const res = await fetch('https://api.isbusinessemail.com/v1/check', {
      method: 'POST',
      headers: {
        Authorization: `Bearer ${event.secrets.IBE_API_KEY}`,
        'Content-Type': 'application/json',
      },
      body: JSON.stringify({ email, policy: 'b2b' }),
      signal: AbortSignal.timeout(2500),
    });
    if (!res.ok) return;          // fail open: never block signups on our errors
    verdict = await res.json();
  } catch {
    return;                       // timeout or network error: fail open
  }

  if (verdict.recommendation === 'block') {
    const hint = verdict.did_you_mean ? ` Did you mean ${verdict.did_you_mean}?` : '';
    api.access.deny('work_email_required', `Please sign up with your work email.${hint}`);
    return;
  }

  api.user.setUserMetadata('email_category', verdict.category);
  api.user.setUserMetadata('google_workspace', verdict.workspace?.google_workspace?.detected ?? false);
  api.user.setUserMetadata('microsoft_365', verdict.workspace?.microsoft_365?.detected ?? false);
};

Deploy it and add it to the Pre User Registration flow.

  • The second argument to api.access.deny is the message the user sees; keep it friendly.
  • Metadata lets your app read the verdict later (for example to pre-select a Microsoft or Google connector).

3. Social connections

Pre User Registration doesn’t run for social connections such as “Sign in with Google”. For those, classify on the first login with a Post Login Action (for example when it’s the user’s first login) and either deny access or flag the account. Remember that a Google social login can be a personal @gmail.com account.

Tips

  • Use policy: 'strict' if your product needs a company tenant from day one; unknown and role accounts are then blocked too.
  • Actions have execution time limits. Keep the timeout around 2–3 s and fail open.
  • Test with personal@test.isbusinessemail.com (denied) and business@test.isbusinessemail.com (allowed).

Official docs: Auth0 documentation (see Actions and the Pre User Registration trigger). See also: Categories and policies.