Signup Protection Pricing Documentation Sign up Log in

Integrations

Laravel Package

Overview

The UserCheck Laravel package adds a usercheck validation rule backed by the UserCheck API, so you can reject disposable, relay, or spam addresses with the validator you already use.

It requires PHP 8.2 or later and Laravel 11, 12, or 13.

Features

  • Block disposable email addresses
  • Block public email domains (Gmail, Yahoo, and so on) to require business addresses
  • Block email forwarding and relay services
  • Block domains flagged as spam
  • Block domains from your own blocklist (Pro plans only)
  • Check for missing MX records
  • Validate by domain only, so the local part of the address never leaves your application
  • Use it as a string rule, an object rule, or through the UserCheck facade
  • Localization support for every error message

Installation

Install via Composer:

composer require usercheck/usercheck-laravel

Configuration

Add your API key to .env:

USERCHECK_API_KEY=your_api_key_here

You can get a free API key at app.usercheck.com.

Basic usage

In your form request or controller:

$request->validate([
    'email' => 'required|email|usercheck'
]);

On its own, the rule only checks that the API accepts the address as valid. Blocking is opt-in: add the parameters below for each signal you want to reject on.

Rule options

Pass parameters to choose what fails validation:

Parameter Effect
block_disposable Fails when the address is from a disposable email provider
block_no_mx Fails when the domain has no MX records
block_public_domain Fails on public email domains such as Gmail and Yahoo
block_relay_domain Fails on email forwarding and relay services
block_spam Fails on domains flagged as spam
block_blocklisted Fails on domains in your own blocklist. Pro plans only
domain_only Validates the domain only, so the local part is never sent to the API

Combine them with commas:

$request->validate([
    'email' => 'required|email|usercheck:domain_only,block_disposable,block_no_mx,block_spam',
]);

Facade usage

use UserCheck\Laravel\Facades\UserCheck;

$result = UserCheck::validateEmail('[email protected]');
$result = UserCheck::validateDomain('example.com');

Both return:

[
    'is_valid' => true,
    'error_code' => null,
]

The facade takes the same checks as boolean arguments, in the order $blockDisposable, $blockNoMx, $blockPublicDomain, $blockBlocklisted, $blockRelayDomain, $blockSpam. All default to false, so validateEmail('[email protected]', true) blocks disposable addresses and nothing else.

Localization

To customize error messages:

php artisan vendor:publish --provider="UserCheck\Laravel\UserCheckProvider" --tag="lang"

Edit translations in resources/lang/vendor/usercheck.

Need help?

Email [email protected] or open an issue on GitHub.

Previous
WordPress Plugin