Download the PHP package g4t/email-rule without Composer
On this page you can find all versions of the php package g4t/email-rule. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download g4t/email-rule
More information about g4t/email-rule
Files in g4t/email-rule
Package email-rule
Short Description A self-contained Laravel validation rule that verifies email addresses are real and deliverable — syntax, DNS, MX, disposable providers, role mailboxes and an optional SMTP probe.
License MIT
Informations about the package email-rule
Laravel Email Rule
A self-contained Laravel validation rule that checks an email address is real and deliverable — not just that it looks like an email.
[email protected] passes Laravel's built-in email rule. It does not pass this one.
No API key, no external service, no database table. Install it and it works.
What it checks
| Check | Default | Notes |
|---|---|---|
| RFC syntax | ✅ rejects | Length limits, dot placement, character set |
| Domain resolves | ✅ rejects | A/AAAA/MX lookup |
| Domain accepts mail | ✅ rejects | MX records, including RFC 7505 null MX |
| Disposable provider | ⚙️ opt-in | Bundled blocklist, subdomains included |
| Role mailbox | ⚙️ opt-in | support@, info@, … |
| Mailbox exists | ⚙️ opt-in | Live SMTP handshake |
| Catch-all domain | ⚙️ opt-in | Probes a decoy address |
The defaults are the fast, safe ones. Everything that requires a network round trip beyond DNS, or that encodes a product decision rather than a correctness one, is opt-in.
Installation
The service provider is auto-discovered. Publish the config only if you want to change the defaults:
Requires PHP 8.2+, Laravel 11/12/13, and the intl extension (for
internationalised domains).
Usage
The rule object
The string rule
For rules built from configuration, or when you prefer strings:
Parameters: disposable, role, smtp, catch_all, fail_closed, strict.
Outside a validator
Error messages
Each finding has its own message, so the user is told what is actually wrong:
| Finding | Message |
|---|---|
invalid_syntax |
The email must be a valid email address. |
unresolvable_domain |
The domain of the email does not exist. |
no_mail_exchanger |
The domain of the email cannot receive email. |
disposable |
The email cannot be a temporary or disposable address. |
role |
The email must be a personal address, not a shared mailbox. |
catch_all |
The email could not be confirmed as a real mailbox. |
mailbox_rejected |
The mail server rejected the email. Please check it for typos. |
Publish the language files to change them, or add your own locale under
lang/vendor/email-rule/{locale}/validation.php.
Two decisions worth understanding
It fails open
If DNS is unreachable or the mail server never answers, the address is accepted.
That is deliberate. Rejecting a real customer because your resolver had a bad minute costs you a signup; accepting one questionable address costs you a bounced email. If you would rather have the opposite trade-off:
or set email-rule.fail_open to false.
SMTP is off by default
An SMTP handshake takes seconds, and this rule usually runs inside a form
submission. Without it, the strongest claim the rule can make is "this domain
accepts mail" — which is why [email protected] passes the defaults.
Proving a specific mailbox exists means asking the mail server.
Turn it on per rule:
…or change the default for every rule:
EMAIL_RULE_SMTP is the default, not a master switch: a rule that asks for
->withSmtp() probes either way, and ->withoutSmtp() opts out either way. To
hard-disable SMTP across an entire application, bind the null probe:
EMAIL_RULE_SMTP_HELOandEMAIL_RULE_SMTP_FROMmust belong to a domain you control, with matching forward and reverse DNS. Otherwise mail servers greylist the probe and every answer degrades to "unverifiable" — which, since the rule fails open, means the check silently does nothing.Most cloud providers also block outbound port 25 by default.
For a signup form that wants SMTP-grade certainty, the better pattern is to accept the address immediately and verify it on a queue:
Configuration
These are the defaults for every rule instance; a fluent call on a rule always wins over the config.
Disposable domains
The bundled list covers the providers seen most often and is deliberately conservative — a false positive rejects a real customer.
Subdomains are matched automatically: blocking trashmail.com also blocks
inbox.trashmail.com.
To sync a full upstream blocklist:
Caching
DNS answers are cached for 24 hours through your application's cache, so a form with several email fields — or a bulk import — does not repeat lookups.
Swapping the internals
Both network seams are interfaces. Bind your own to use DNS-over-HTTPS, a third-party verification API, or a fake in tests:
That is exactly how this package's own test suite runs without touching the network.
Testing
Licence
MIT.
laravel-email-rule
All versions of email-rule with dependencies
ext-intl Version *
illuminate/contracts Version ^11.0|^12.0|^13.0
illuminate/support Version ^11.0|^12.0|^13.0
illuminate/validation Version ^11.0|^12.0|^13.0