Email Injection attacks

I’ve heard that it’s possible to halt email injection attacks by using
validate_request, but does anyone have an example of how to actually do
this? Thanks