{"id":195529,"date":"2024-07-11T16:46:02","date_gmt":"2024-07-11T16:46:02","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/advanced-email-domain-restriction\/"},"modified":"2026-08-15T11:01:39","modified_gmt":"2026-08-15T11:01:39","slug":"advanced-email-domain-restriction","status":"publish","type":"plugin","link":"https:\/\/ar.wordpress.org\/plugins\/advanced-email-domain-restriction\/","author":17633541,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.5.0","stable_tag":"1.5.0","tested":"7.0.4","requires":"6.3","requires_php":"7.4","requires_plugins":null,"header_name":"Advanced Email Domain Restriction","header_author":"Md Siddiqur Rahman","header_description":"Allow email domains for user registrations with custom messages.","assets_banners_color":"4694e5","last_updated":"2026-08-15 11:01:39","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/buymeacoffee.com\/imsiddiqur","header_plugin_uri":"https:\/\/wordpress.org\/plugins\/advanced-email-domain-restriction","header_author_uri":"https:\/\/siddiqur.com","rating":5,"author_block_rating":0,"active_installs":100,"downloads":2370,"num_ratings":1,"support_threads":1,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"rockscoder","date":"2024-07-24 05:18:09"},"1.1.0":{"tag":"1.1.0","author":"rockscoder","date":"2025-04-15 17:33:44"},"1.2.0":{"tag":"1.2.0","author":"rockscoder","date":"2026-02-22 15:29:42"},"1.3.0":{"tag":"1.3.0","author":"rockscoder","date":"2026-02-22 16:12:01"},"1.4.0":{"tag":"1.4.0","author":"rockscoder","date":"2026-05-24 13:37:06"},"1.4.1":{"tag":"1.4.1","author":"rockscoder","date":"2026-05-24 13:47:47"},"1.5.0":{"tag":"1.5.0","author":"rockscoder","date":"2026-08-15 11:01:39"}},"upgrade_notice":{"1.5.0":"<p>Fixes LearnDash registration bypass and adds BuddyPress, MemberPress, Paid Memberships Pro, Gravity Forms, Fluent Forms, Tutor LMS, and ACF support.<\/p>","1.4.0":"<p>UX polish: rule type labels, live preview, test-email checker, duplicate detection, and CSV import summary.<\/p>","1.3.0":"<p>New matching options: Support for TLD-based and full email address restriction.<\/p>","1.2.0":"<p>Major update: CSV Bulk Upload\/Export, Clean Architecture refactoring, and Security Hardening.<\/p>","1.1.0":"<p>Now support WooCommerce customer registration email domain check.<\/p>"},"ratings":{"1":0,"2":0,"3":0,"4":0,"5":1},"assets_icons":{"icon-256x256.png":{"filename":"icon-256x256.png","revision":3546262,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3648478,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3648478,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.1.0","1.2.0","1.3.0","1.4.0","1.4.1","1.5.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3546302,"resolution":"1","location":"assets","locale":"","width":1903,"height":903},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3546262,"resolution":"2","location":"assets","locale":"","width":3350,"height":1722},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3546262,"resolution":"3","location":"assets","locale":"","width":3346,"height":1558},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3648478,"resolution":"4","location":"assets","locale":"","width":3200,"height":2222},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3648478,"resolution":"5","location":"assets","locale":"","width":3200,"height":2222}},"screenshots":{"1":"Settings Page","2":"Registration Form","3":"Custom Error Message","4":"Test Email Checker \u2014 Allowed","5":"Test Email Checker \u2014 Blocked"}},"plugin_section":[],"plugin_tags":[555,267,603,599,286],"plugin_category":[58],"plugin_contributors":[229515],"plugin_business_model":[],"class_list":["post-195529","plugin","type-plugin","status-publish","hentry","plugin_tags-domain","plugin_tags-email","plugin_tags-registration","plugin_tags-spam","plugin_tags-woocommerce","plugin_category-user-management","plugin_contributors-rockscoder","plugin_committers-rockscoder"],"banners":{"banner":"https:\/\/ps.w.org\/advanced-email-domain-restriction\/assets\/banner-772x250.png?rev=3648478","banner_2x":"https:\/\/ps.w.org\/advanced-email-domain-restriction\/assets\/banner-1544x500.png?rev=3648478","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/advanced-email-domain-restriction\/assets\/icon-256x256.png?rev=3546262","icon_2x":"https:\/\/ps.w.org\/advanced-email-domain-restriction\/assets\/icon-256x256.png?rev=3546262","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/advanced-email-domain-restriction\/assets\/screenshot-1.png?rev=3546302","caption":"Settings Page"},{"src":"https:\/\/ps.w.org\/advanced-email-domain-restriction\/assets\/screenshot-2.png?rev=3546262","caption":"Registration Form"},{"src":"https:\/\/ps.w.org\/advanced-email-domain-restriction\/assets\/screenshot-3.png?rev=3546262","caption":"Custom Error Message"},{"src":"https:\/\/ps.w.org\/advanced-email-domain-restriction\/assets\/screenshot-4.png?rev=3648478","caption":"Test Email Checker \u2014 Allowed"},{"src":"https:\/\/ps.w.org\/advanced-email-domain-restriction\/assets\/screenshot-5.png?rev=3648478","caption":"Test Email Checker \u2014 Blocked"}],"raw_content":"<!--section=description-->\n<p><strong>Advanced Email Domain Restriction (AEDR)<\/strong> gives you full control over who is allowed to create an account on your WordPress site. Instead of letting anyone register with any email address, restrict registration to a trusted allow-list of company domains, specific email addresses, top-level domains (TLDs), or wildcard subdomains \u2014 and stop spam registrations, fake accounts, and unauthorized signups before they happen.<\/p>\n\n<p>Whether you run a company intranet that should only accept <code>@yourcompany.com<\/code> addresses, a course platform that should only enroll students with a <code>.edu<\/code> email, or a membership site that wants to block free webmail providers, AEDR gives you a simple allow-list-based way to enforce it \u2014 with no regex or code required.<\/p>\n\n<h3>Common Use Cases<\/h3>\n\n<ul>\n<li><strong>Restrict registration to your company domain<\/strong> \u2014 only allow <code>@yourcompany.com<\/code> emails to sign up for an internal site, intranet, or extranet.<\/li>\n<li><strong>Block spam and fake account registrations<\/strong> \u2014 stop bots and throwaway\/disposable email signups by only accepting domains you trust.<\/li>\n<li><strong>Gate course or membership access by email domain<\/strong> \u2014 for example, only allow <code>.edu<\/code> addresses to register for a student-only LearnDash course, or restrict a corporate LMS to employee emails.<\/li>\n<li><strong>Control WooCommerce customer registration<\/strong> \u2014 prevent unauthorized signups on your WooCommerce store at checkout or account creation.<\/li>\n<li><strong>Enforce domain rules across every registration form on your site<\/strong> \u2014 WooCommerce, LearnDash, BuddyPress, MemberPress, Paid Memberships Pro, Contact Form 7, WPForms, Elementor Pro, Gravity Forms, and Fluent Forms all respect the same allow-list.<\/li>\n<\/ul>\n\n<h3>Key Features<\/h3>\n\n<ul>\n<li><strong>Allow-list Only<\/strong>: Restrict registrations to a specific list of trusted domains, exact email addresses, TLDs, or wildcard subdomains.<\/li>\n<li><strong>Bulk Upload<\/strong>: Import large lists of domains via CSV.<\/li>\n<li><strong>Domain Export<\/strong>: Download your allowed domains list for backup or analysis.<\/li>\n<li><strong>WooCommerce Support<\/strong>: Fully compatible with WooCommerce customer registration.<\/li>\n<li><strong>Form &amp; Field Plugin Support<\/strong>: Automatically validate email fields in <strong>Contact Form 7<\/strong>, <strong>WPForms<\/strong>, <strong>Elementor Pro<\/strong>, <strong>Gravity Forms<\/strong>, <strong>Fluent Forms<\/strong>, and <strong>Advanced Custom Fields (ACF)<\/strong>.<\/li>\n<li><strong>LMS &amp; Membership Support<\/strong>: Works with <strong>LearnDash<\/strong>, <strong>Tutor LMS<\/strong>, <strong>BuddyPress \/ BuddyBoss<\/strong>, <strong>MemberPress<\/strong>, and <strong>Paid Memberships Pro<\/strong> registration flows.<\/li>\n<li><strong>TLD &amp; Full Email Support<\/strong>: Restrict registrations to specific TLDs (e.g., .com) or specific email addresses (e.g., user@example.com).<\/li>\n<li><strong>Wildcard Subdomain Support<\/strong>: A rule like <code>*.example.com<\/code> matches both <code>example.com<\/code> and any subdomain, such as <code>sales.example.com<\/code>.<\/li>\n<li><strong>Case-Insensitive<\/strong>: Matches <code>gmail.com<\/code> regardless of how the user types it.<\/li>\n<li><strong>Custom Messages<\/strong>: Define your own error messages for restricted domains.<\/li>\n<li><strong>Live Test Checker<\/strong>: Instantly test any email address in the admin panel to confirm whether it would be allowed or blocked.<\/li>\n<li><strong>No Regex, No Code<\/strong>: Every rule type is entered as plain text \u2014 no technical knowledge required.<\/li>\n<\/ul>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin files to the <code>\/wp-content\/plugins\/advanced-email-domain-restriction<\/code> directory, or install the plugin through the WordPress plugins screen directly.<\/li>\n<li>Activate the plugin through the 'Plugins' screen in WordPress.<\/li>\n<li>Use the Settings-&gt; Domain Restriction screen to configure the plugin.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"how%20do%20i%20restrict%20wordpress%20registration%20to%20a%20specific%20domain%3F\"><h3>How do I restrict WordPress registration to a specific domain?<\/h3><\/dt>\n<dd><p>Go to Settings \u2192 Domain Restriction and add the domain (e.g. <code>yourcompany.com<\/code>) to the Allowed Domains list. Once saved, only email addresses ending in <code>@yourcompany.com<\/code> will be able to register \u2014 every other domain is blocked automatically.<\/p><\/dd>\n<dt id=\"can%20i%20block%20specific%20email%20providers%20like%20gmail%2C%20yahoo%2C%20or%20outlook%3F\"><h3>Can I block specific email providers like Gmail, Yahoo, or Outlook?<\/h3><\/dt>\n<dd><p>Yes. Since AEDR works as an allow-list, simply don't include <code>gmail.com<\/code>, <code>yahoo.com<\/code>, <code>outlook.com<\/code>, or any other webmail domain in your allowed list, and registrations from those domains will be blocked. This is a common way to reduce spam and fake account signups.<\/p><\/dd>\n<dt id=\"can%20i%20allow%20an%20entire%20top-level%20domain%20%28tld%29%2C%20like%20all%20.edu%20or%20.gov%20addresses%3F\"><h3>Can I allow an entire top-level domain (TLD), like all .edu or .gov addresses?<\/h3><\/dt>\n<dd><p>Yes. Add a rule starting with a dot, such as <code>.edu<\/code> or <code>.gov<\/code>, and any email address ending in that TLD will be allowed, regardless of the domain in front of it.<\/p><\/dd>\n<dt id=\"can%20i%20allow%20only%20one%20specific%20email%20address%20instead%20of%20a%20whole%20domain%3F\"><h3>Can I allow only one specific email address instead of a whole domain?<\/h3><\/dt>\n<dd><p>Yes. Add the full address (e.g. <code>john@example.com<\/code>) as a rule, and only that exact email will be allowed to register \u2014 useful for granting a single exception.<\/p><\/dd>\n<dt id=\"does%20wildcard%20subdomain%20matching%20work%3F\"><h3>Does wildcard subdomain matching work?<\/h3><\/dt>\n<dd><p>Yes. A rule like <code>*.example.com<\/code> allows both <code>example.com<\/code> itself and any subdomain such as <code>team.example.com<\/code> or <code>sales.example.com<\/code>.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20support%20woocommerce%20customer%20registration%3F\"><h3>Does this plugin support WooCommerce customer registration?<\/h3><\/dt>\n<dd><p>Yes. AEDR hooks directly into WooCommerce's registration process, so the same domain rules apply whether a customer registers through the standard WordPress form or through WooCommerce's My Account \/ checkout registration.<\/p><\/dd>\n<dt id=\"does%20this%20work%20with%20learndash%3F\"><h3>Does this work with LearnDash?<\/h3><\/dt>\n<dd><p>Yes. AEDR validates the email domain on LearnDash's Login &amp; Registration modal as well as the default WordPress registration form, so students can only register with an approved email domain \u2014 useful for restricting course access to <code>.edu<\/code> or company email addresses.<\/p><\/dd>\n<dt id=\"is%20buddypress%20or%20buddyboss%20registration%20supported%3F\"><h3>Is BuddyPress or BuddyBoss registration supported?<\/h3><\/dt>\n<dd><p>Yes. AEDR validates the email domain during BuddyPress and BuddyBoss community signup, in addition to standard WordPress registration.<\/p><\/dd>\n<dt id=\"does%20this%20work%20with%20memberpress%20or%20paid%20memberships%20pro%3F\"><h3>Does this work with MemberPress or Paid Memberships Pro?<\/h3><\/dt>\n<dd><p>Yes. Both MemberPress signup and Paid Memberships Pro registration\/checkout are validated against your allowed domains list.<\/p><\/dd>\n<dt id=\"which%20contact%20and%20form%20plugins%20are%20supported%3F\"><h3>Which contact and form plugins are supported?<\/h3><\/dt>\n<dd><p>AEDR automatically validates email fields in Contact Form 7, WPForms, Elementor Pro forms, Gravity Forms, and Fluent Forms, using the same allow-list you configure once in Settings \u2192 Domain Restriction.<\/p><\/dd>\n<dt id=\"does%20this%20work%20on%20wordpress%20multisite%3F\"><h3>Does this work on WordPress Multisite?<\/h3><\/dt>\n<dd><p>Yes. AEDR validates email domains during multisite user signup as well as single-site registration.<\/p><\/dd>\n<dt id=\"how%20do%20i%20customize%20the%20error%20message%20shown%20to%20blocked%20users%3F\"><h3>How do I customize the error message shown to blocked users?<\/h3><\/dt>\n<dd><p>You can customize the error message shown for restricted domains in the plugin settings under the \"Custom Messages\" section.<\/p><\/dd>\n<dt id=\"can%20i%20bulk%20import%20or%20export%20my%20list%20of%20allowed%20domains%3F\"><h3>Can I bulk import or export my list of allowed domains?<\/h3><\/dt>\n<dd><p>Yes. Use the CSV Bulk Upload feature to import a large list of rules at once, and the Export to CSV feature to download your current list for backup or review.<\/p><\/dd>\n<dt id=\"will%20this%20affect%20users%20who%20already%20have%20an%20account%3F\"><h3>Will this affect users who already have an account?<\/h3><\/dt>\n<dd><p>No. AEDR only validates email domains at the point of new registration. Existing user accounts are never affected, logged out, or deleted, even if their email domain is later removed from the allowed list.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20help%20stop%20spam%20or%20fake%20registrations%3F\"><h3>Does this plugin help stop spam or fake registrations?<\/h3><\/dt>\n<dd><p>Yes. Because only email domains you explicitly trust can complete registration, AEDR is commonly used to block spam bots, disposable\/throwaway email signups, and fake accounts that target open registration forms.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20i%20don%27t%20add%20any%20rules%3F\"><h3>What happens if I don't add any rules?<\/h3><\/dt>\n<dd><p>If no domains are configured, AEDR does not restrict registration \u2014 all email addresses are allowed, exactly as with a default WordPress install.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20collect%20or%20share%20any%20personal%20data%3F\"><h3>Does this plugin collect or share any personal data?<\/h3><\/dt>\n<dd><p>No. AEDR does not collect, store, or transmit any personal data to third parties. It only reads the email address submitted during registration to check it against the domain rules you configure yourself.<\/p><\/dd>\n<dt id=\"will%20this%20plugin%20slow%20down%20my%20website%3F\"><h3>Will this plugin slow down my website?<\/h3><\/dt>\n<dd><p>No. AEDR is lightweight, performs a single fast comparison against your configured rules at the moment of registration, and adds no measurable overhead to page load or checkout speed.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.5.0<\/h4>\n\n<ul>\n<li>Fix: LearnDash Login &amp; Registration modal (and any other registration flow bypassing the standard <code>registration_errors<\/code> filter) no longer allows restricted email domains to register.<\/li>\n<li>Feature: Added BuddyPress \/ BuddyBoss registration support.<\/li>\n<li>Feature: Added MemberPress registration support.<\/li>\n<li>Feature: Added Paid Memberships Pro (PMPro) registration support.<\/li>\n<li>Feature: Added Gravity Forms email field validation support.<\/li>\n<li>Feature: Added Fluent Forms email field validation support.<\/li>\n<li>Feature: Added Tutor LMS student and instructor registration support.<\/li>\n<li>Feature: Added Advanced Custom Fields (ACF) email field validation support.<\/li>\n<\/ul>\n\n<h4>1.4.1<\/h4>\n\n<ul>\n<li>Fix: Exclude <code>\/bridge<\/code> directory and <code>pnpm-lock.yaml<\/code> from distribution zip via <code>.distignore<\/code>.<\/li>\n<\/ul>\n\n<h4>1.4.0<\/h4>\n\n<ul>\n<li>Feature: Rule type labels \u2014 each rule shows its type (Domain \/ TLD \/ Exact email \/ Wildcard) inline in the admin panel.<\/li>\n<li>Feature: Live rule preview \u2014 shows an example address the rule will match as you type.<\/li>\n<li>Feature: Test email checker \u2014 enter any address to instantly see if it would be Allowed or Blocked.<\/li>\n<li>Feature: Wildcard rule support \u2014 <code>*.example.com<\/code> matches any subdomain of example.com.<\/li>\n<li>Feature: Duplicate detection \u2014 duplicate rules are removed on save with an admin notice.<\/li>\n<li>Feature: CSV import summary \u2014 import results now show Imported \/ Skipped duplicates \/ Invalid rows counts.<\/li>\n<li>Enhancement: <code>AEDR_Rule_Parser<\/code> and <code>AEDR_Rule_Matcher<\/code> classes introduced for clean, testable validation logic.<\/li>\n<li>Enhancement: CSV processor now accepts TLDs, exact emails, and wildcard rules in addition to plain domains.<\/li>\n<li>Enhancement: PHPUnit unit tests added for all new classes.<\/li>\n<\/ul>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>Feature: Added support for TLD-based matching (e.g., allow all emails from <code>.cz<\/code>).<\/li>\n<li>Feature: Added support for full email address matching (e.g., allow <code>user@example.com<\/code>).<\/li>\n<li>Enhancement: Updated Admin UI with clearer descriptions and placeholders for new matching types.<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>Feature: Added Support for <strong>WPForms<\/strong> and <strong>Elementor Pro<\/strong> email field validation.<\/li>\n<li>Feature: Added Support for <strong>Contact Form 7<\/strong> email field validation.<\/li>\n<li>Feature: Added Export to CSV feature for allowed domains.<\/li>\n<li>Feature: Added CSV Bulk Upload for allowed domains.<\/li>\n<li>Feature: Added client-side and server-side validation for file uploads.<\/li>\n<li>Security: Hardened plugin with nonce and capability checks.<\/li>\n<li>Security: Applied late escaping throughout the admin interface.<\/li>\n<li>Security: Hardened CSV import logic against large files and malicious content.<\/li>\n<li>Bug Fix: Fixed WooCommerce registration errors hook (changed from action to filter).<\/li>\n<li>Enhancement: Added case-insensitive domain validation support.<\/li>\n<li>Enhancement: Refactored to Clean Architecture (separated Validator and CSV Processor).<\/li>\n<li>Enhancement: Settings are now cached for better performance.<\/li>\n<li>Improvement: Cleaned up code and improved domain sanitization.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>WooCommerce customer registration email domain check support added.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release with support for allowed domains and custom error messages.<\/li>\n<\/ul>","raw_excerpt":"Restrict WordPress user registration to allowed email domains, block spam signups, and secure WooCommerce, LearnDash, and form registrations.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/195529","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=195529"}],"author":[{"embeddable":true,"href":"https:\/\/ar.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/rockscoder"}],"wp:attachment":[{"href":"https:\/\/ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=195529"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=195529"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=195529"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=195529"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=195529"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/ar.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=195529"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}