The website owner would send a user's email address to a third party (your service) before the user can give consent. For European websites that's tough with GDPR regulation.
Yeah, that would be a problem. I'm thinking it could just send the first part of the email address (before the @ sign) or instead just license an encrypted blob to the company which they can run.