PHPackages                             climactic/laravel-spam - PHPackages - PHPackages  [Skip to content](#main-content)[PHPackages](/)[Directory](/)[Categories](/categories)[Trending](/trending)[Leaderboard](/leaderboard)[Changelog](/changelog)[Analyze](/analyze)[Collections](/collections)[Log in](/login)[Sign up](/register)

1. [Directory](/)
2. /
3. [Security](/categories/security)
4. /
5. climactic/laravel-spam

ActiveLibrary[Security](/categories/security)

climactic/laravel-spam
======================

Anti-spam protection for Laravel: disposable-email and blocklist rules, StopForumSpam lookups, middleware, and a check API.

0.1.0(3mo ago)41MITPHPPHP ^8.2

Since Apr 17Pushed 3mo agoCompare

[ Source](https://github.com/Climactic/laravel-spam)[ Packagist](https://packagist.org/packages/climactic/laravel-spam)[ Docs](https://github.com/climactic/laravel-spam)[ GitHub Sponsors](https://github.com/sponsors/climactic)[ Fund](https://ko-fi.com/climacticco)[ RSS](/packages/climactic-laravel-spam/feed)WikiDiscussions main Synced 1w ago

READMEChangelog (1)Dependencies (12)Versions (2)Used By (0)

[![Laravel Spam](https://camo.githubusercontent.com/d08bcd8613a01a0b2689ae965dd7d8a7805f2b8db8cc3bee1ff02b8a9d75f346/68747470733a2f2f62616e6e6572732e6265796f6e64636f2e64652f4c61726176656c2532305370616d2e706e673f7468656d653d6c69676874267061636b6167654d616e616765723d636f6d706f7365722b72657175697265267061636b6167654e616d653d636c696d61637469632532466c61726176656c2d7370616d267061747465726e3d7a69675a6167267374796c653d7374796c655f31266465736372697074696f6e3d426c6f636b2b646973706f7361626c652b656d61696c732b616e642b7370616d2b7369676e7570732b696e2b796f75722b4c61726176656c2b617070266d643d312673686f7757617465726d61726b3d3026666f6e7453697a653d313030707826696d616765733d68616e64)](https://camo.githubusercontent.com/d08bcd8613a01a0b2689ae965dd7d8a7805f2b8db8cc3bee1ff02b8a9d75f346/68747470733a2f2f62616e6e6572732e6265796f6e64636f2e64652f4c61726176656c2532305370616d2e706e673f7468656d653d6c69676874267061636b6167654d616e616765723d636f6d706f7365722b72657175697265267061636b6167654e616d653d636c696d61637469632532466c61726176656c2d7370616d267061747465726e3d7a69675a6167267374796c653d7374796c655f31266465736372697074696f6e3d426c6f636b2b646973706f7361626c652b656d61696c732b616e642b7370616d2b7369676e7570732b696e2b796f75722b4c61726176656c2b617070266d643d312673686f7757617465726d61726b3d3026666f6e7453697a653d313030707826696d616765733d68616e64)Laravel Spam
============

[](#laravel-spam)

A pragmatic anti-spam toolkit for Laravel applications. Block disposable and throwaway email signups, reject known bad actors via StopForumSpam, and configure your own allow/blocklists — with validation rules, middleware, and a check API.

[![Discord](https://camo.githubusercontent.com/a2d0c0993adc0d0f466338c3991d1d318ab74795b52e1d5e4a2e41efc27acfb1/68747470733a2f2f696d672e736869656c64732e696f2f646973636f72642f3330333139353332323531343031343231303f7374796c653d666f722d7468652d6261646765)](https://discord.gg/kedWdzwwR5)[![Latest Version on Packagist](https://camo.githubusercontent.com/4d61fdd56915abad4dc065f8b4e5f53ea6380d34f2842ceda9214bc449a947dd/68747470733a2f2f696d672e736869656c64732e696f2f7061636b61676973742f762f636c696d61637469632f6c61726176656c2d7370616d2e7376673f7374796c653d666f722d7468652d6261646765)](https://packagist.org/packages/climactic/laravel-spam)[![GitHub Tests Action Status](https://camo.githubusercontent.com/7f781433269b7917ae1b1e8f6e95f3c0c0789320d98b49e87890cbd2fc2a9dd6/68747470733a2f2f696d672e736869656c64732e696f2f6769746875622f616374696f6e732f776f726b666c6f772f7374617475732f636c696d61637469632f6c61726176656c2d7370616d2f72756e2d74657374732e796d6c3f6272616e63683d6d61696e266c6162656c3d7465737473267374796c653d666f722d7468652d6261646765)](https://github.com/climactic/laravel-spam/actions?query=workflow%3Arun-tests+branch%3Amain)[![GitHub Code Style Action Status](https://camo.githubusercontent.com/669c7fb9cf690ec7eabe7f8850bfe005f171312336ec097fb59b7cae36183f2c/68747470733a2f2f696d672e736869656c64732e696f2f6769746875622f616374696f6e732f776f726b666c6f772f7374617475732f636c696d61637469632f6c61726176656c2d7370616d2f6669782d7068702d636f64652d7374796c652d6973737565732e796d6c3f6272616e63683d6d61696e266c6162656c3d636f64652532307374796c65267374796c653d666f722d7468652d6261646765)](https://github.com/climactic/laravel-spam/actions?query=workflow%3A%22Fix+PHP+code+style+issues%22+branch%3Amain)[![Total Downloads](https://camo.githubusercontent.com/d776e4d18e3e3c1bcfee2324d3ec75c38275abccc2610143e0e1afe605b57e1a/68747470733a2f2f696d672e736869656c64732e696f2f7061636b61676973742f64742f636c696d61637469632f6c61726176656c2d7370616d2e7376673f7374796c653d666f722d7468652d6261646765)](https://packagist.org/packages/climactic/laravel-spam)[![Sponsor on GitHub](https://camo.githubusercontent.com/b3163f75bf5ed93d5cdab93ef38cdf453559a26611bab9abe917d7dee974979a/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f53706f6e736f722d4769744875622d6561346161613f7374796c653d666f722d7468652d6261646765266c6f676f3d676974687562)](https://github.com/sponsors/climactic)[![Support on Ko-fi](https://camo.githubusercontent.com/b5dfdef80a44c8875071357e6b7e2ef1f3c595e89a0b947682d5b12a58722d9e/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f537570706f72742d4b6f2d2d66692d4646354535423f7374796c653d666f722d7468652d6261646765266c6f676f3d6b6f2d6669266c6f676f436f6c6f723d7768697465)](https://ko-fi.com/ClimacticCo)

📖 Table of Contents
-------------------

[](#-table-of-contents)

- [Laravel Spam](#laravel-spam)
    - [📖 Table of Contents](#-table-of-contents)
    - [Features](#features)
    - [🌟 Sponsors](#-sponsors)
    - [📦 Installation](#-installation)
    - [⚙️ Configuration](#%EF%B8%8F-configuration)
    - [🚀 Usage](#-usage)
        - [The `Spam::check()` API](#the-spamcheck-api)
        - [Validation rules](#validation-rules)
        - [Route middleware](#route-middleware)
        - [Individual rules](#individual-rules)
    - [🔄 Keeping the disposable list fresh](#-keeping-the-disposable-list-fresh)
    - [📚 API Reference](#-api-reference)
        - [Facade methods](#facade-methods)
        - [Validation rules](#validation-rules-1)
        - [Middleware](#middleware)
        - [Console](#console)
    - [🧪 Testing](#-testing)
    - [📋 Changelog](#-changelog)
    - [🤝 Contributing](#-contributing)
    - [🔒 Security Vulnerabilities](#-security-vulnerabilities)
    - [💖 Support This Project](#-support-this-project)
    - [⭐ Star History](#-star-history)
    - [📦 Other Packages](#-other-packages)
    - [📄 License](#-license)
    - [⚖️ Disclaimer](#%EF%B8%8F-disclaimer)

Features
--------

[](#features)

- 🚫 Block disposable / throwaway email providers (bundled list of 70k+ domains)
- 🌐 StopForumSpam lookups with caching and a fail-open default
- 📋 Configurable blocklists for domains and TLDs
- ✅ Drop-in validation rules for any `FormRequest` or `Validator::make()` call
- 🛡️ Route middleware for protecting any endpoint that accepts an email
- 🔍 A single `Spam::check()` API that returns a typed reason
- 🔄 Artisan command to refresh the disposable-email list from upstream
- 🧪 Zero database tables, zero external auth, zero required API keys

🌟 Sponsors
----------

[](#-sponsors)

*Your logo here* — Become a sponsor and get your logo featured in this README and on our website.

**Interested in title sponsorship?** Contact us at  for premium placement and recognition.

📦 Installation
--------------

[](#-installation)

You can install the package via composer:

```
composer require climactic/laravel-spam
```

Optionally publish the config file:

```
php artisan vendor:publish --tag="laravel-spam-config"
```

Optionally publish the bundled disposable-email list to local storage (only needed if you plan to refresh it yourself — see [below](#-keeping-the-disposable-list-fresh)):

```
php artisan vendor:publish --tag="laravel-spam-data"
```

⚙️ Configuration
----------------

[](#️-configuration)

The config file lives at `config/spam.php`. Every option is documented inline:

```
return [
    'default_field' => env('SPAM_DEFAULT_FIELD', 'email'),
    'message' => env('SPAM_MESSAGE', 'This email address is not allowed. Please use a different one.'),

    // `blocked_tlds` / `blocked_domains` accept a comma-separated
    // env override — see the .env snippet below.
    'blocked_tlds' => ['tk', 'ml', 'cf', 'ga', 'gq'],
    'blocked_domains' => [
        // 'example.com',
    ],

    'disposable' => [
        'enabled' => env('SPAM_DISPOSABLE_ENABLED', true),
        'storage_path' => env('SPAM_DISPOSABLE_STORAGE_PATH', storage_path('app/laravel-spam/disposable-domains.json')),
        'source_url' => env('SPAM_DISPOSABLE_SOURCE_URL', 'https://cdn.jsdelivr.net/gh/disposable/disposable-email-domains@master/domains.json'),
        'cache_ttl' => env('SPAM_DISPOSABLE_CACHE_TTL'), // null = forever
    ],

    'stopforumspam' => [
        'enabled' => env('STOPFORUMSPAM_ENABLED', true),
        'frequency' => (int) env('STOPFORUMSPAM_FREQUENCY', 3),
        'cache_ttl' => (int) env('STOPFORUMSPAM_CACHE_TTL', 3600),
        'timeout' => (int) env('STOPFORUMSPAM_TIMEOUT', 5),
    ],
];
```

Everything is env-driven, so you can tune the package from `.env` without publishing the config:

```
SPAM_DEFAULT_FIELD=email
SPAM_MESSAGE="This email address is not allowed. Please use a different one."
SPAM_BLOCKED_TLDS="tk,ml,cf,ga,gq"
SPAM_BLOCKED_DOMAINS="example.com,another.test"

SPAM_DISPOSABLE_ENABLED=true
SPAM_DISPOSABLE_STORAGE_PATH=           # Override the JSON path
SPAM_DISPOSABLE_SOURCE_URL=             # Override the upstream list URL
SPAM_DISPOSABLE_CACHE_TTL=              # null = forever

STOPFORUMSPAM_ENABLED=true
STOPFORUMSPAM_FREQUENCY=3               # Min appearances to count as spam
STOPFORUMSPAM_CACHE_TTL=3600
STOPFORUMSPAM_TIMEOUT=5
```

No API key required — StopForumSpam lookups are anonymous and this package does not submit reports.

🚀 Usage
-------

[](#-usage)

### The `Spam::check()` API

[](#the-spamcheck-api)

Get a structured verdict for any email:

```
use Climactic\Spam\Facades\Spam;
use Climactic\Spam\Enums\SpamReason;

$result = Spam::check($email);

if ($result->isSpam) {
    Log::warning('Blocked signup', [
        'email' => $email,
        'reason' => $result->reason->value, // 'disposable', 'blocked_tld', …
    ]);
}
```

`SpamReason` cases: `Clean`, `InvalidEmail`, `BlockedDomain`, `BlockedTld`, `Disposable`, `StopForumSpam`.

Convenience predicates:

```
Spam::isSpamEmail($email);        // bool — any spam signal
Spam::isDisposable($email);       // bool
Spam::isBlockedDomain($email);    // bool — exact domain *or* TLD match
Spam::isStopForumSpam($email);    // bool
```

### Validation rules

[](#validation-rules)

Use `Spam::emailRules()` in any `FormRequest` or inline validator. It returns Laravel's standard email rules plus the three spam rules — append your own extras (like `unique:`) as needed:

```
use Climactic\Spam\Facades\Spam;

public function rules(): array
{
    return [
        'email' => Spam::emailRules([
            'unique:'.User::class,
        ]),
    ];
}
```

Or drop it into an inline validator:

```
Validator::make($data, [
    'email' => Spam::emailRules(),
])->validate();
```

### Route middleware

[](#route-middleware)

Protect any endpoint that accepts an email field with the `spam.email` middleware alias. A flagged email yields a standard `422` validation response.

```
Route::post('/register', RegisterController::class)
    ->middleware('spam.email');

Route::post('/contact', ContactController::class)
    ->middleware('spam.email:contact_email'); // custom field name
```

If no parameter is passed, the middleware reads `config('spam.default_field')` (default: `email`).

### Individual rules

[](#individual-rules)

If you want to reach for a specific rule directly:

```
use Climactic\Spam\Rules\BlockedEmailDomain;
use Climactic\Spam\Rules\DisposableEmail;
use Climactic\Spam\Rules\StopForumSpamEmail;

$data->validate([
    'email' => [
        'required', 'email',
        app(BlockedEmailDomain::class),
        app(DisposableEmail::class),
        app(StopForumSpamEmail::class),
    ],
]);
```

🔄 Keeping the disposable list fresh
-----------------------------------

[](#-keeping-the-disposable-list-fresh)

The package ships with a snapshot of [disposable/disposable-email-domains](https://github.com/disposable/disposable-email-domains). To refresh from upstream on your own schedule, run:

```
php artisan spam:update
```

The command writes to `config('spam.disposable.storage_path')` (default: `storage/app/laravel-spam/disposable-domains.json`) and clears the cache. Recommended: schedule it monthly:

```
use Illuminate\Support\Facades\Schedule;

Schedule::command('spam:update')->monthly();
```

📚 API Reference
---------------

[](#-api-reference)

### Facade methods

[](#facade-methods)

MethodDescription`Spam::check(string $email): SpamResult`Full check; returns `{isSpam, reason}``Spam::isSpamEmail(string $email): bool`True if any signal fires`Spam::isDisposable(string $email): bool`True if the domain is in the disposable list`Spam::isBlockedDomain(string $email): bool`True if the domain or TLD is blocklisted`Spam::isStopForumSpam(string $email): bool`True if StopForumSpam flags the email`Spam::emailRules(array $extra = []): array`Email validation rules; append extras### Validation rules

[](#validation-rules-1)

RuleClassBlocked domain / TLD`Climactic\Spam\Rules\BlockedEmailDomain`Disposable email`Climactic\Spam\Rules\DisposableEmail`StopForumSpam lookup`Climactic\Spam\Rules\StopForumSpamEmail`### Middleware

[](#middleware)

AliasClassParameter`spam.email``Climactic\Spam\Http\Middleware\BlockSpamEmails`Request field (defaults to config)### Console

[](#console)

CommandDescription`spam:update`Refresh the disposable-email list🧪 Testing
---------

[](#-testing)

```
composer test
```

📋 Changelog
-----------

[](#-changelog)

Please see [CHANGELOG](CHANGELOG.md) for more information on what has changed recently.

🤝 Contributing
--------------

[](#-contributing)

Please see [CONTRIBUTING](CONTRIBUTING.md) for details. You can also join our Discord server to discuss ideas and get help: [Discord Invite](https://discord.gg/kedWdzwwR5).

🔒 Security Vulnerabilities
--------------------------

[](#-security-vulnerabilities)

Please report security vulnerabilities to .

💖 Support This Project
----------------------

[](#-support-this-project)

Laravel Spam is free and open source, built and maintained with care. If this package has saved you development time or helped power your application, please consider supporting its continued development.

[ ![Sponsor on GitHub](https://camo.githubusercontent.com/b54bfcc9644ed7bcc05286df7b65016fc35a3ef50ead57e5942733d1b7663048/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f53706f6e736f722532306f6e2d4769744875622d6561346161613f7374796c653d666f722d7468652d6261646765266c6f676f3d676974687562)](https://github.com/sponsors/climactic) [ ![Support on Ko-fi](https://camo.githubusercontent.com/f29eb9e7ac04ba39e8f164bd49b7170f8d5263e726c135bfbebf865998f3b146/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f537570706f72742532306f6e2d4b6f2d2d66692d4646354535423f7374796c653d666f722d7468652d6261646765266c6f676f3d6b6f2d6669266c6f676f436f6c6f723d7768697465)](https://ko-fi.com/ClimacticCo)⭐ Star History
--------------

[](#-star-history)

[![Star History Chart](https://camo.githubusercontent.com/101818d62538edddca419f5f8d6c91e749d5b24810d693229bce07f98b2c5213/68747470733a2f2f6170692e737461722d686973746f72792e636f6d2f7376673f7265706f733d636c696d61637469632f6c61726176656c2d7370616d26747970653d64617465266c6567656e643d746f702d6c656674)](https://www.star-history.com/#climactic/laravel-spam&type=date&legend=top-left)

📦 Other Packages
----------------

[](#-other-packages)

Other open-source Laravel packages from [Climactic](https://github.com/climactic):

PackageDescription[climactic/laravel-credits](https://github.com/climactic/laravel-credits)Ledger-based credit system for virtual currencies, reward points, and credit-based features.[climactic/laravel-polar](https://github.com/climactic/laravel-polar)Seamless [Polar.sh](https://polar.sh) integration for subscriptions, payments, and webhooks.[climactic/laravel-altcha](https://github.com/climactic/laravel-altcha)Drop-in [ALTCHA](https://altcha.org) proof-of-work spam protection — privacy-first, self-hosted, no third-party services.📄 License
---------

[](#-license)

The MIT License (MIT). Please see [License File](LICENSE) for more information.

⚖️ Disclaimer
-------------

[](#️-disclaimer)

This package is not affiliated with Laravel. It's for Laravel but is not by Laravel. Laravel is a trademark of Taylor Otwell. Disposable-domain data is sourced from the [disposable/disposable-email-domains](https://github.com/disposable/disposable-email-domains) community project.

###  Health Score

33

—

LowBetter than 72% of packages

Maintenance81

Actively maintained with recent releases

Popularity5

Limited adoption so far

Community6

Small or concentrated contributor base

Maturity36

Early-stage or recently created project

 Bus Factor1

Top contributor holds 100% of commits — single point of failure

How is this calculated?**Maintenance (25%)** — Last commit recency, latest release date, and issue-to-star ratio. Uses a 2-year decay window.

**Popularity (30%)** — Total and monthly downloads, GitHub stars, and forks. Logarithmic scaling prevents top-heavy scores.

**Community (15%)** — Contributors, dependents, forks, watchers, and maintainers. Measures real ecosystem engagement.

**Maturity (30%)** — Project age, version count, PHP version support, and release stability.

###  Release Activity

Cadence

Unknown

Total

1

Last Release

98d ago

### Community

Maintainers

![](https://www.gravatar.com/avatar/04e8fd6548e1113d35fb74e60ba71ce472fcf61503f8bd0c5b2f0928910860d4?d=identicon)[climactic](/maintainers/climactic)

---

Top Contributors

[![adiologydev](https://avatars.githubusercontent.com/u/9266227?v=4)](https://github.com/adiologydev "adiologydev (4 commits)")

---

Tags

laravelspamanti-spamstopforumspamdisposable-emailclimacticlaravel-spam

###  Code Quality

TestsPest

Static AnalysisPHPStan

Code StyleLaravel Pint

### Embed Badge

![Health badge](/badges/climactic-laravel-spam/health.svg)

```
[![Health](https://phpackages.com/badges/climactic-laravel-spam/health.svg)](https://phpackages.com/packages/climactic-laravel-spam)
```

###  Alternatives

[spatie/laravel-pdf

Create PDFs in Laravel apps

1.0k4.8M48](/packages/spatie-laravel-pdf)[rawilk/profile-filament-plugin

Profile &amp; MFA starter kit for filament.

3914.8k](/packages/rawilk-profile-filament-plugin)[harris21/laravel-fuse

Circuit breaker for Laravel queue jobs. Protect your workers from cascading failures.

45955.7k](/packages/harris21-laravel-fuse)[vormkracht10/laravel-mails

Laravel Mails can collect everything you might want to track about the mails that has been sent by your Laravel app.

24957.5k](/packages/vormkracht10-laravel-mails)[lettermint/lettermint-laravel

Official Lettermint driver for Laravel

1190.2k1](/packages/lettermint-lettermint-laravel)

PHPackages © 2026

[Directory](/)[Categories](/categories)[Trending](/trending)[Changelog](/changelog)[Analyze](/analyze)
