Skip to content
imper.ai

Email and Domain Checks

Description

Email and domain checks evaluate the email address a user presents during verification and the domain it belongs to. Rather than looking only at whether an address is syntactically valid, these checks assess whether the address and its domain are consistent with a legitimate, established identity - or whether they show signs of being disposable, newly created, or otherwise high-risk.

Key indicators include:

  • Disposable or temporary email providers

Addresses hosted on throwaway or temporary-mail services that are commonly used to avoid attribution.

  • Newly registered or low-reputation domains

Domains created recently or with little to no legitimate sending history, which are frequently stood up for a single campaign.


Relevance to Social Engineering Attacks

In social engineering campaigns, attackers routinely rely on email addresses that cannot be traced back to a real, verifiable identity. Disposable addresses and freshly registered domains let an attacker present a plausible-looking identity while avoiding any lasting connection to their activity.

Common attacker objectives include:

  • Impersonation - using a look-alike or newly registered domain to appear as a legitimate employee, vendor, or candidate.

  • Attribution avoidance - relying on disposable addresses so that the identity cannot be linked to prior fraudulent activity.

  • Scale - generating large numbers of addresses on the same low-reputation infrastructure to support repeated attempts.

By flagging disposable providers, low-reputation domains, and domain inconsistencies, this check surfaces identities that are unlikely to belong to a genuine, established user.