Integrations
Laravel Package
Overview
The UserCheck Laravel package adds a usercheck validation rule backed by the UserCheck API, so you can reject disposable, relay, or spam addresses with the validator you already use.
It requires PHP 8.2 or later and Laravel 11, 12, or 13.
Features
- Block disposable email addresses
- Block public email domains (Gmail, Yahoo, and so on) to require business addresses
- Block email forwarding and relay services
- Block domains flagged as spam
- Block domains from your own blocklist (Pro plans only)
- Check for missing MX records
- Validate by domain only, so the local part of the address never leaves your application
- Use it as a string rule, an object rule, or through the
UserCheckfacade - Localization support for every error message
Installation
Install via Composer:
composer require usercheck/usercheck-laravel
Configuration
Add your API key to .env:
USERCHECK_API_KEY=your_api_key_here
You can get a free API key at app.usercheck.com.
Basic usage
In your form request or controller:
$request->validate([
'email' => 'required|email|usercheck'
]);
On its own, the rule only checks that the API accepts the address as valid. Blocking is opt-in: add the parameters below for each signal you want to reject on.
Rule options
Pass parameters to choose what fails validation:
| Parameter | Effect |
|---|---|
block_disposable |
Fails when the address is from a disposable email provider |
block_no_mx |
Fails when the domain has no MX records |
block_public_domain |
Fails on public email domains such as Gmail and Yahoo |
block_relay_domain |
Fails on email forwarding and relay services |
block_spam |
Fails on domains flagged as spam |
block_blocklisted |
Fails on domains in your own blocklist. Pro plans only |
domain_only |
Validates the domain only, so the local part is never sent to the API |
Combine them with commas:
$request->validate([
'email' => 'required|email|usercheck:domain_only,block_disposable,block_no_mx,block_spam',
]);
Facade usage
use UserCheck\Laravel\Facades\UserCheck;
$result = UserCheck::validateEmail('[email protected]');
$result = UserCheck::validateDomain('example.com');
Both return:
[
'is_valid' => true,
'error_code' => null,
]
The facade takes the same checks as boolean arguments, in the order $blockDisposable, $blockNoMx, $blockPublicDomain, $blockBlocklisted, $blockRelayDomain, $blockSpam. All default to false, so validateEmail('[email protected]', true) blocks disposable addresses and nothing else.
Localization
To customize error messages:
php artisan vendor:publish --provider="UserCheck\Laravel\UserCheckProvider" --tag="lang"
Edit translations in resources/lang/vendor/usercheck.
Need help?
Email [email protected] or open an issue on GitHub.