Skip to content
CHADA Store

Rule: Email heuristics

Rule key: email_heuristics · Default weight: 0.85 · Tier: Lite

Combines three sub-signals on the billing email address. Scores stack up to the per-rule cap of 100.

1. Disposable domain (70 points)

The plugin bundles 153 known disposable-email domains (Mailinator, Guerrilla Mail, 10MinuteMail, YOPmail, etc.). Match is exact-domain — sub-domains aren\’t automatically blocked. Add your own under Settings → Disposable Email.

2. Prior chargeback on the email (60 points)

Looks up the canonicalised email against the wfg_chargebacks table. Requires the chargeback webhook integration to be active and populating that table.

3. Suspicious pattern (25 points)

One or more of:

  • Digits-only domain label (e.g. buyer@1234.com)
  • Suspicious TLD (.xyz, .top, .click, .work, .country, …)
  • Gibberish local-part — Shannon-entropy-based check that flags strings like qzwxecvbnmk