/firebase-tutorials

How to allow only specific email domains in Firebase?

Learn how to restrict Firebase sign-ups to specific email domains with a step-by-step guide on setting up Firebase Auth, writing Cloud Functions, and secure deployment.

Matt Graham, CEO of Rapid Developers

Book a call with an Expert

Starting a new venture? Need to upgrade your web app? RapidDev builds application with your growth in mind.

Book a free No-Code consultation

How to allow only specific email domains in Firebase?

 

Step 1: Set Up Firebase Project

 

  • Go to the Firebase Console.
  • Click on Add project and follow the prompts to create a new project.
  • Choose your Google Analytics preferences.

 

Step 2: Set Up Firebase Authentication

 

  • Navigate to Build > Authentication in the Firebase Console.
  • Click on Get Started.
  • In the Sign-in Method tab, enable the Email/Password provider.

 

Step 3: Write Firebase Cloud Function

 

  • Open your terminal or command line interface.

  • Ensure you have the Firebase CLI installed. If not, install it using:

    npm install -g firebase-tools
    
  • Log in using your Google account:

    firebase login
    
  • Navigate to your Firebase project directory and initialize Cloud Functions:

    firebase init functions
    
  • Follow the prompts to set up your Cloud Functions environment.

  • Choose JavaScript or TypeScript for your language preference.

 

Step 4: Add Domain Whitelisting Logic

 

  • Open the generated index.js file in your functions directory.
  • Add the following code to listen for new user sign-ups and allow only specific domains:
    const functions = require('firebase-functions');
    const admin = require('firebase-admin');

admin.initializeApp();

exports.allowSpecificDomains = functions.auth.user().onCreate((user) => {
const allowedDomains = ['example.com', 'anotherexample.com'];
const email = user.email || '';
const emailDomain = email.split('@')[1];

if (!allowedDomains.includes(emailDomain)) {
return admin.auth().deleteUser(user.uid)
.then(() => {
console.log(Deleted user with disallowed domain: ${email});
})
.catch((error) => {
console.error('Error deleting user:', error);
});
}
return null;
});

  • Save the file.

 

Step 5: Deploy the Cloud Function

 

  • Deploy your function to Firebase using the command:

    firebase deploy --only functions
    
  • Wait for the deployment to complete successfully.

 

Step 6: Test the Domain Restriction

 

  • Try signing up with allowed and disallowed email domains.

  • Check the Firebase Authentication panel to ensure users with disallowed domains are deleted.

  • Monitor the Logs in Firebase Functions to review actions taken on sign-up:

  • Navigate to Functions in the Firebase Console.

  • Click Logs to see the triggering logs of your Cloud Function.

 

Step 7: Secure Your Implementation

 

  • Regularly update your whitelist of domains as needed.
  • Consider adding detailed logging for auditing purposes.
  • Implement additional security and error handling in your functions for production readiness.

 

Want to explore opportunities to work with us?

Connect with our team to unlock the full potential of no-code solutions with a no-commitment consultation!

Book a Free Consultation

Client trust and success are our top priorities

When it comes to serving you, we sweat the little things. That’s why our work makes a big impact.

Rapid Dev was an exceptional project management organization and the best development collaborators I've had the pleasure of working with. They do complex work on extremely fast timelines and effectively manage the testing and pre-launch process to deliver the best possible product. I'm extremely impressed with their execution ability.

CPO, Praction - Arkady Sokolov

May 2, 2023

Working with Matt was comparable to having another co-founder on the team, but without the commitment or cost. He has a strategic mindset and willing to change the scope of the project in real time based on the needs of the client. A true strategic thought partner!

Co-Founder, Arc - Donald Muir

Dec 27, 2022

Rapid Dev are 10/10, excellent communicators - the best I've ever encountered in the tech dev space. They always go the extra mile, they genuinely care, they respond quickly, they're flexible, adaptable and their enthusiasm is amazing.

Co-CEO, Grantify - Mat Westergreen-Thorne

Oct 15, 2022

Rapid Dev is an excellent developer for no-code and low-code solutions.
We’ve had great success since launching the platform in November 2023. In a few months, we’ve gained over 1,000 new active users. We’ve also secured several dozen bookings on the platform and seen about 70% new user month-over-month growth since the launch.

Co-Founder, Church Real Estate Marketplace - Emmanuel Brown

May 1, 2024 

Matt’s dedication to executing our vision and his commitment to the project deadline were impressive. 
This was such a specific project, and Matt really delivered. We worked with a really fast turnaround, and he always delivered. The site was a perfect prop for us!

Production Manager, Media Production Company - Samantha Fekete

Sep 23, 2022