Email Validation

7 Signs an Email Is Fake: Caught at Signup

LTLeadCop Team
August 20, 20265 min read
7 Signs an Email Is Fake: caught at signup, on a LeadCop blog cover

Every signup form is a small act of trust. Someone hands you an email address, and you assume there's a real person behind it. But a meaningful slice of the addresses hitting your forms are fake: throwaway inboxes, malformed domains, or bots stuffing garbage into your database. Left unchecked, they inflate your metrics, wreck email deliverability, and bury your sales team in leads that go nowhere.

The good news: fake emails leave fingerprints. Here are seven signs an email is fake, and how to catch each one the moment a user hits submit, before the bad address ever reaches your database.

1. It uses a disposable or temporary domain

The most common fake email isn't misspelled or malformed. It's a perfectly valid address on a disposable email provider like mailinator.com, temp-mail.org, or one of the tens of thousands of throwaway services that spin up new domains weekly. Users reach for them to grab a lead magnet or free trial without handing over their real inbox.

You can't catch these by checking syntax, because the syntax is fine. You catch them by cross-referencing the domain against a maintained blocklist. LeadCop checks every submission against a database of 200,000+ known disposable and temporary providers, returning isDisposable: true so you can block or flag the address instantly.

2. The domain has no valid MX records

A domain can only receive email if it publishes MX (mail exchange) records in its DNS. If those records are missing, no message you ever send will arrive. The address is undeliverable by definition, whether it was a typo, a made-up domain, or a bot's random string.

A real-time MX lookup is one of the highest-signal checks you can run. When LeadCop returns mxValid: false, you're looking at an address that literally cannot receive mail. Blocking it at signup saves you a guaranteed hard bounce later.

3. The top-level domain is fake or invalid

Bots and careless typists produce addresses ending in TLDs that don't exist, like user@company.cim, john@brand.con, or entirely invented extensions. The local part looks normal, so a naive validator waves it through.

Validating the TLD against the official list of recognized extensions filters these out immediately. LeadCop flags them with isInvalidTld: true, catching both fat-fingered mistakes and machine-generated junk in the same pass.

4. It's a role-based address, not a person

Addresses like info@, admin@, sales@, support@, and no-reply@ aren't tied to an individual. They're shared mailboxes or automated endpoints. They aren't always "fake," but for most signup flows they're a red flag: they convert poorly, complain more, and often indicate someone avoiding a personal address.

LeadCop identifies these with isRoleAccount: true. Depending on your funnel, you can block them outright or simply route them for extra review, a light touch for B2B forms where a role account might be legitimate.

5. The domain is an obvious typo

Not every bad email is malicious. A huge share are honest mistakes: gmial.com, yaho.com, hotmial.com, outlok.com. The user meant to reach you; they just slipped on the keyboard. Silently rejecting them loses a real lead; silently accepting them guarantees a bounce.

The fix is to detect the likely intended domain and offer a correction. LeadCop's didYouMean field returns the probable fix (for example, suggesting gmail.com for gmial.com) so your form can prompt "Did you mean gmail.com?" and recover a lead that would otherwise vanish.

6. The local part looks machine-generated

Human email addresses tend to follow patterns: names, initials, real words, familiar number combinations. Bot-generated addresses often don't: long strings of random characters like x7f9q2z8kd@…, keyboard mashing, or repetitive filler. On its own, a strange local part isn't proof of a fake, but combined with other weak signals it tips the scale.

This is why single yes/no checks miss so much. LeadCop rolls every signal (disposable status, MX validity, TLD, role account, typos, and provider reputation) into a single reputation score from 0 to 100 and a riskLevel band (Excellent to Critical). A gibberish address on an otherwise valid domain still lands in a low-score band, giving you one number to threshold on instead of a dozen edge cases to hand-code.

7. A free provider where a work email is expected

This one is context-dependent. A Gmail or Yahoo address isn't fake, but if you sell a B2B product and someone signs up for an enterprise plan with a personal free account, that's worth a second look. It often signals a low-intent lead, a competitor poking around, or someone dodging their corporate identity.

LeadCop surfaces this with isFreeEmail: true. The right response usually isn't a hard block. It's a gentle warning nudging the user toward their work email, so you filter intent without turning away genuine consumer signups.

Catch the signs automatically, at the moment of signup

Any one of these signs is useful. Together, they're decisive. The catch is that checking them by hand (maintaining a disposable-domain list, running live MX lookups, validating TLDs, scoring typos) is a real engineering project, and the blocklists go stale within days.

That's exactly what LeadCop does in a single API call that runs in under 100ms, right as the user submits. Every check above comes back in one response, with a reputation score you can act on and a fail-open design that never blocks a real signup if the service is briefly unreachable. You drop in the script or plugin, set your threshold, and fake emails stop entering your database.

Stop cleaning up bad data after the fact. Catch fake emails at the gate: start blocking disposable emails for free with LeadCop.

Scale your lead quality with LeadCop.

Join 2,400+ teams blocking disposable emails and protecting their growth funnels.

Start for free today
7 Signs an Email Is Fake (and How to Catch Them at Signup) | Leadcop