CashoutGuard: fraud prevention for rewards, GPT, faucet, PTC and offerwall sites.

Disposable emails and Gmail aliases: stopping multi-account signups on rewards sites

The signup form is the first place a multi-account farm touches your site, and the email field is where most of them cut corners. This guide shows the three email tricks farms use, how to spot each one, and why the email check works best as one signal among several.

Short answer

Normalize every address (lower case, drop the +tag, remove dots in Gmail), compare the normalized address with your existing accounts, flag throwaway domains and domains with no mail server, and treat all of it as evidence for review rather than an automatic ban.

Dots and +tags
john.doe+7@gmail.com and johndoe@gmail.com reach the same inbox.
Throwaway inboxes
Thousands of disposable domains, new ones every week.
No mail server
A domain without MX records cannot receive the confirmation email.
Best use
One signal next to device, network and payout links.

Why the email field matters on a rewards site

On a rewards, GPT or offerwall site every new account is worth something on day one: a signup bonus, a referral reward, a fresh cap on the best-paying offers. A farm that can open ten accounts for the price of one multiplies all of that. The cheapest part of an account to fake is the email address, so that is where the corners get cut.

Most sites ask for an email and send a confirmation link. That stops people who type a random address, but it does not stop someone who controls the inbox, and a farm always controls the inbox. What the confirmation step does not tell you is whether that inbox is the same one behind twenty other accounts, or one that will be thrown away tomorrow.

The good news is that the email is also one of the easiest signals to check, and it is available before the user has earned anything. Checked at signup, it lets you hold the account, ask for more verification or simply watch it closely, long before the first cashout request arrives.

The three email tricks farms use

TrickExampleWhat catches it
Dot and plus aliasesj.ohn.doe+12@gmail.com, johndoe+13@gmail.comNormalizing the address before comparing it with existing accounts
Disposable inboxesx7k2@mailinator.com, random@10minutemail-style domainsA list of throwaway domains, refreshed often
Made-up domainsuser@my-rewards-site-2025.xyz with no mail serverA DNS lookup for MX (or A) records

Aliases are the most common trick on GPT sites because they cost nothing and look perfectly normal. Gmail ignores dots in the local part and everything after a plus sign, so a single inbox can sign up hundreds of times with addresses that are all different strings. Outlook and many other providers support plus addressing too, although only Gmail ignores the dots.

Disposable inboxes are the second trick. Farms rotate between many throwaway providers, and new domains appear every week, so a list that was complete last year is not complete today. Made-up domains are rarer, but they show up when a site does not confirm emails at all.

Normalize before you compare

Comparing raw email strings catches nothing, because every alias is a different string. The fix is to compare a normalized form: lower-case the address, drop everything after the first plus sign in the local part, and for Gmail and Googlemail also remove the dots and map both domains to gmail.com. Two accounts whose normalized addresses match belong to the same inbox, whatever they typed.

function normalized_email(string $email): string
{
    [$local, $domain] = explode('@', strtolower(trim($email)), 2);
    $local = explode('+', $local, 2)[0];
    if (in_array($domain, ['gmail.com', 'googlemail.com'], true)) {
        $local = str_replace('.', '', $local);
        $domain = 'gmail.com';
    }
    return $local . '@' . $domain;
}

Store the normalized form (or a hash of it) next to each account and look it up at signup. If it already exists, the new account is the same person as the old one. That is a strong link, as strong as a shared payout address, and it usually means the owner is trying to claim the signup bonus again.

Disposable domains and missing mail servers

A throwaway domain is not proof of fraud on its own. Some privacy-minded users sign up with one, and a few of them are honest. On a rewards site, though, a disposable address on a brand-new account that immediately goes for the highest-paying offers is a pattern worth holding for review.

A domain with no mail server is a stronger signal: nobody can receive the confirmation email there, so the account was never meant to be contacted. If your signup flow does not confirm emails, this check alone removes a surprising share of junk accounts.

  • Check the domain against a list of disposable providers that is refreshed at least weekly.
  • Look up MX records, falling back to an A record, and cache the answer per domain for a day.
  • Flag role addresses such as admin@ or info@: unusual for a rewards user, harmless for a business.
  • Never block free providers such as Gmail or Outlook by themselves: that is where your real users are.

You can try all of these checks on a single address with the free email checker, which shows the normalized inbox, the disposable flag and whether the domain has a mail server.

Why the email check is not enough on its own

A determined farm buys or creates real mailboxes, and each one passes every email check. That is why the email should never be the only line of defense. The accounts behind real, distinct inboxes still share devices, networks, time zones and, above all, payout addresses.

The strongest setup combines the email with those links: a new account whose normalized email is new, but whose browser was already used by three other accounts and whose cashout goes to the same wallet, is the same person as before. The email check catches the lazy farms; device and payout links catch the careful ones.

How CashoutGuard does it

Send the email with the signup event to /v1/evaluate. CashoutGuard normalizes it, stores only a hash, flags disposable domains (email_disposable) and links accounts that share the same inbox (email_shared). The same account is also checked for shared devices, VPN and hosting networks, and shared payout addresses when it cashes out, so one score covers all of it.

In the dashboard, searching Accounts for an email shows every account behind that inbox, aliases included, together with what the address is: disposable, alias, or a normal mailbox. The bulk check page takes a list of up to 500 emails or IP addresses from an export and tells you which of your accounts use each one. New sites start in shadow mode, so you can see what would be flagged before anything is blocked.

Frequently asked questions

Should I block every Gmail address with a plus sign?

No. Plus addressing is a normal feature some people use to filter mail. It only matters when the normalized address already belongs to another account on your site.

Is the email stored?

CashoutGuard stores a hash of the normalized address, scoped to your site, so it can match accounts without keeping the address itself.

How often do disposable domains change?

New throwaway domains appear every week. CashoutGuard refreshes its list every day, and a domain without a mail server is flagged whether or not it is on the list.

What about users who sign up with a work address?

Company domains with a working mail server are treated as normal mailboxes. Role addresses such as info@ are flagged only as a weak signal.

Keep reading