This hooks into WooCommerce’s checkout validation, verifies the email, and adds a checkout error (blocking order placement) if the address is undeliverable or disposable.

The code

<?php
// Add to functions.php or a site-specific plugin.

add_action('woocommerce_after_checkout_validation', function ($data, $errors) {
    $email = $data['billing_email'] ?? '';
    if (empty($email)) {
        return;
    }

    $api_key = getenv('ROCKETVERIFIER_API_KEY'); // rv_live_... or rv_test_...
    $response = wp_remote_post('https://api.rocketverifier.com/v1/verify', [
        'headers' => [
            'Authorization' => 'Bearer ' . $api_key,
            'Content-Type'  => 'application/json',
        ],
        'body'    => wp_json_encode(['email' => $email]),
        'timeout' => 10,
    ]);

    if (is_wp_error($response)) {
        // Fail open — don't block checkout on a RocketVerifier outage.
        error_log('RocketVerifier request failed: ' . $response->get_error_message());
        return;
    }

    $body = json_decode(wp_remote_retrieve_body($response), true);
    $result = $body['data'] ?? null;

    if (!$result) {
        return;
    }

    if ($result['status'] === 'undeliverable') {
        $errors->add('validation', 'The email address you entered does not appear to be valid. Please double-check it before placing your order.');
        return;
    }

    if (!empty($result['domain']['disposable'])) {
        $errors->add('validation', 'Please use a permanent email address so we can send your order confirmation and shipping updates.');
    }
}, 10, 2);

Testing against the sandbox

Temporarily set ROCKETVERIFIER_API_KEY to a sandbox key (rv_test_...) and place a test order with an @sandbox.rocketverifier.com address to confirm the error messages display correctly at checkout, before switching to a live key for production.

# In wp-config.php or your server environment, for local testing only:
putenv('ROCKETVERIFIER_API_KEY=rv_test_your_sandbox_key');

Why validate at woocommerce_after_checkout_validation specifically

This hook runs after WooCommerce’s own built-in field validation (format, required fields) but before the order is actually created, so a RocketVerifier rejection behaves exactly like any other checkout validation error — the customer sees it inline and can correct their email without losing their cart.