
內容簡介
### 總結:
Registration Email Blocker 是一個 WordPress 外掛,用於限制可以用於網站使用者註冊的電子郵件域名。此外掛旨在協助俄羅斯網站所有者部分遵守有關使用者授權要求的聯邦法案406-FZ。
### 問答:
1. Registration Email Blocker 是什麼?
- Registration Email Blocker 是一個 WordPress 外掛,用於限制可以用於網站使用者註冊的電子郵件域名。
2. 這個外掛如何協助達到合規要求?
- Federal Law 406-FZ 要求俄羅斯網站使用特定授權方法,如電話號碼、ESIA 或俄羅斯控制的系統。Registration Email Blocker 可以幫助在以下方面達到合規:
- 防止使用外國電子郵件域名進行註冊(黑名單模式)
- 只允許使用批准的域名進行註冊(白名單模式)
- 識別現有使用者的不符合要求的電子郵件地址
- 向使用者發送要求更改電子郵件的通知
- 提供所有註冊嘗試的審核日誌
3. Registration Email Blocker 在法律合規方面有何重要聲明?
- 此外掛是一個技術工具,並不能保證完全符合聯邦法案406-FZ。網站所有者必須確保完全的合法合規性,建議諮詢律師有關適用法規。
4. Registration Email Blocker 提供哪些關鍵功能?
- 二種操作模式:黑名單模式(阻止特定域名)或白名單模式(僅允許特定域名)
- 靈活的執行:硬阻止模式或警告模式
- 現有使用者管理:自動識別具有不符合要求電子郵件地址的使用者
- 大量電子郵件通知:向受影響的使用者發送更改電子郵件的請求
- 詳細日誌記錄:包含 IP 地址和時間戳的完整註冊嘗試歷史紀錄
- WooCommerce 整合:控制註冊和結帳過程中的電子郵件域名
- 域統計:分析所有網站使用者使用的電子郵件域名
- CSV 匯出:匯出具有不合規電子郵件的使用者列表
- 預配置域名列表:外國和俄羅斯流行電子郵件服務的現成列表
- 管理員例外:選項可豁免管理員域名檢查
5. 誰需要使用 Registration Email Blocker 外掛?
- 需要遵守聯邦法案406-FZ 的俄羅斯網站所有者
- 需要控制使用者註冊的管理員
- 在俄羅斯營運並要求客戶電子郵件的 WooCommerce 商店
希望以上問答能幫助你更好地了解 Registration Email Blocker 外掛。
外掛標籤
開發者團隊
原文外掛簡介
Registration Email Blocker decides which email domains are acceptable on your site. Run it as a blocklist to refuse the providers you name, or as an allowlist to accept only the ones you approve.
The check is applied everywhere an address can be set, not only on the registration form:
the WordPress registration form
the profile screen and “Add New User” in wp-admin
the WordPress REST API
WooCommerce registration
the WooCommerce checkout, both the classic shortcode and the newer block based checkout
the “Account details” page of the WooCommerce My Account area
Checking email changes matters as much as checking registration. If only the registration form is guarded, an account can be created with an accepted address and switched to any other one a minute later. That option is on by default and can be turned off.
What it does
Two modes. Blocklist refuses the domains you list; allowlist accepts only the domains you list. Subdomains are matched in both directions, so listing example.com also covers mail.example.com.
Two levels of strictness. Refuse the address outright, or allow it and record the attempt.
Internationalized domains. Names such as почта.рф are converted to their punycode form when saved, so they match real addresses. Entries that are not valid domain names are reported back to you rather than silently dropped.
Administrators are exempt by default, so a mistake in a domain list cannot lock you out of your own site.
Report on existing accounts. See which accounts use a rejected domain, grouped by domain, and export the list as CSV.
Batched notifications. Ask affected users to change their address. Mail is sent in small batches with a progress bar and a stop button, and anyone notified recently is skipped, so a timeout cannot restart the run from the beginning.
A log you can live with. Attempts are recorded with a configurable level of detail, kept only as long as you choose, and trimmed automatically once a day. Repeated attempts from the same IP address within a minute are recorded once, so a bot cycling through addresses cannot inflate the table.
Editable defaults. Both domain lists ship pre-filled and can be changed freely; a button restores them to the versions shipped with the plugin whenever you want the newest entries.
Privacy
The plugin stores registration attempts in a table in your own database. Nothing is sent anywhere else, and no external service is contacted.
You decide how much is kept:
email addresses in full, partially masked, reduced to the domain, or not stored at all
IP addresses in full, anonymized, or not stored at all
a retention period after which entries are deleted automatically
The plugin registers a personal data exporter and eraser, so log entries are included in the export and erasure requests WordPress produces under Tools → Export/Erase Personal Data, and it suggests text for your privacy policy.
The connection address is used by default; forwarded headers such as X-Forwarded-For are trusted only if you state that the site is behind a reverse proxy, because a visitor can otherwise put any value there.
A note on what a blocklist can do
A blocklist only refuses the domains you thought of. Somebody who wants an account will find a provider that is not on the list. When the set of acceptable providers is actually known, the allowlist is the mode that holds.
The plugin is a technical control over email domains. It does not by itself make a site compliant with any particular legislation, and the site owner remains responsible for their own legal obligations.
Russian Federal Law 406-FZ
The plugin was originally written for Russian site owners working towards Federal Law No. 406-FZ, which requires authorization through a phone number, ESIA, a biometric system or another Russian-controlled system.
This plugin implements none of those. It only controls the email domain used at registration, which the law does not address directly. Treat it as one piece of housekeeping, not as a compliance solution, and take legal advice about your own obligations.
Support
Questions and bug reports are welcome on the plugin’s support forum on WordPress.org.
Developer: Studio Playner — https://profiles.wordpress.org/altcreative/
Support Development
This plugin is free and will stay free. If it saves you time, you can support its development through YooKassa.
Contributions go towards new features, compatibility with new WordPress and WooCommerce releases, and answering support questions.
License
This plugin is licensed under the GPL v2 or later.
Copyright (C) 2026 Studio Playner
This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 2 of the License, or (at your option) any later version.
