# Email domain blacklist with wildcards (revisited)

**URL:** <https://meta.discourse.org/t/email-domain-blacklist-with-wildcards-revisited/70088>\
**Category:** Feature\
**Created:** [September 15, 2017, 2:37am UTC](https://meta.discourse.org/t/email-domain-blacklist-with-wildcards-revisited/70088 "2017-09-15T02:37:40Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![schungx](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/schungx/32/70989_2.png) [@schungx](https://meta.discourse.org/u/schungx)\
**Post date:** [September 20, 2017, 6:24am UTC](https://meta.discourse.org/t/email-domain-blacklist-with-wildcards-revisited/70088/5 "2017-09-20T06:24:43Z")

</div>

Tracing through the code, there is something very suspicious.

`EmailValidator` seems to be only used when a user updates his/her email address (in `EmailUpdater`).

When a user is created, it only validates against proper email format but not whether the email domain is blacklisted.

Emphatically, it is _not_ used to verify when a _staged_ user is created via `email in`, because `email/receiver.rb`, in `process_internal`, it only checks against things:

```plaintext
Regexp.new(SiteSetting.ignore_by_title) =~ @mail.subject // Blacklisted TOPIC TITLE
raise BouncedEmailError if is_bounce? // Bounce mail
raise NoSenderDetectedError if @from_email.blank? // No From field
raise ScreenedEmailError if ScreenedEmail.should_block?(@from_email) // Screend Email address

```

After this, a new _staged_ user is created via `find_or_create_user`.

Shouldn’t `EmailValidator.validate_each` be called on `@from_email` to make sure that the incoming `email in` is not from a blacklisted domain?

Or, better, check first if the user with that email address already exists. If so, let it pass. Otherwise, call `EmailValidator.validate_each` to check if it is blacklisted. **DO NOT** create a _staged_ user if the email is blacklisted.

---

_[View the full topic](https://meta.discourse.org/t/email-domain-blacklist-with-wildcards-revisited/70088)._
