Search...
Menu

Registration Security

Registration security is used to configure security protection policies for the application registration process, including disposable email blocking and human verification (CAPTCHA), effectively preventing fake account registrations and automated attacks.

Path: Log in to the RootAuth console → Navigate to the target application → Click Configuration in the top navigation bar → Select Security Settings – General Security → Registration Security

 

1. Disposable Email Policy

Configuration Item Description Default Status
Block registrations using disposable email addresses When enabled, the system will identify and block the use of temporary email addresses (such as 10-minute email, disposable email) for registration, effectively preventing fake accounts. Checked by default

How It Works:

  • When a user submits registration using a domain that is recognized by the industry as a "disposable email" domain, the system will directly block the registration attempt and display a prompt.

  • This blocking occurs after the user has correctly filled in the registration information and clicks the "Register" button.

  • If this option is disabled, any email address can be used for registration.

Scope of Impact: Only affects the registration process of the current application; does not interfere with other applications.

2. Human Verification (CAPTCHA) Policy

Configuration Item Description Default Status
Users must always pass human verification before sending a verification code When enabled, users must first pass a graphical CAPTCHA (e.g., slider, click-based) when clicking "Get Verification Code" during registration, login (via verification code), or password reset. This prevents automated attacks. Checked by default

Covered Scenarios:

  • Registration process: obtaining an email activation code

  • Verification code login: obtaining a login verification code

  • Password reset: obtaining a password reset verification code

Interaction Description:

  • When enabled, clicking the corresponding button ("Get Activation Code""Get Verification Code""Send Verification Code") will immediately trigger the CAPTCHA popup. The email is sent only after the CAPTCHA is successfully completed.

  • When disabled, clicking the button will directly send the verification code without a CAPTCHA challenge.

Note: The password login scenario does not involve sending a verification code and is therefore not affected by this configuration.

 

3. Configuration Effect and Experience Verification

  • Effectiveness Time: After modifying any configuration items, click "Save". The changes will take effect within 2 minutes without needing to restart the application.

  • Experience Verification: You can quickly preview the effect of the security policies by clicking the "Try Registration/Login" button in the upper-right corner of the current application page:

    • Attempt to register using a temporary email address to verify the blocking prompt.

    • Attempt to obtain a verification code to confirm whether the CAPTCHA popup appears.

Previous
General Security
Next
Risk Policies
Last modified: 2026-03-11Powered by