Docs Customer Info Email Verification

Email Verification

Customer Info includes a built-in Email Verification feature that asks new customers to confirm their email address with a one-time passcode (OTP) during registration. It reduces fake sign-ups and ensures you have a valid, reachable email on file. It is off by default, works on its own, and does not require the separate Customer Email Verification plugin.

🚀 How it works

  • A customer enters their email on the WooCommerce registration form.
  • A verification popup asks for the code sent to that email.
  • They enter the OTP; on success, registration completes and they are logged in.
  • Registration is blocked until the email is verified — the account is created only after a correct code, so there are no half-finished, unverified accounts left waiting.
Where verification applies: it gates the WooCommerce registration form (My Account, and the “create an account” option at checkout where it uses that form). Accounts created by other means — an admin creating a user, an import, or another plugin’s programmatic sign-up — are not gated and will appear not verified until the customer verifies or you mark them manually.
Turning it on does not lock out existing customers. The check runs at registration only, so accounts that already exist keep working and simply show as Not verified until they verify or you mark them. Nobody is logged out or blocked from signing in.

⚙️ Settings

Go to WooCommerce → Customer Info, click the gear at the top-right, and open the Email Verification tab. The Settings sub-tab holds these options:

SettingDescriptionDefault
Verification enabledMaster switch. When off, the popup never opens and registrations are not gated.Off
OTP LengthDigits in the code: 4 to 8.6 digits
OTP ExpirationHow long a code stays valid (1 minute to 1 hour).10 minutes
Verification Email Resend LimitHow many codes can be requested within the 15-minute window before the customer is rate-limited.3 attempts
Resend Limit MessageShown when the resend limit is reached. Default: “Too many attempts, please contact us for further assistance.”(the text above)
A 4-digit code is easier to guess. The plugin limits wrong entries (see below), but a shorter code is weaker. Leave it at 6 digits, or go higher, unless you have a specific reason to shorten it.

Changes save as you make them — a Saved indicator confirms each one. Save settings writes everything at once, and Reset returns the settings on this tab to their defaults.

🔐 How the code is protected

  • Codes are generated with a cryptographically secure random generator.
  • Only a salted hash of the code is stored (never the code itself), in a short-lived record that is deleted when the code expires.
  • A wrong code can be tried at most 5 times before that code is invalidated and a new one must be requested.
  • Resends are throttled per email address and per IP within a 15-minute window, so the feature can’t be used to spam a mailbox.

🎨 Design customization

The Customization sub-tab has two editors, each with a live preview:

EditorWhat you can change
Email TemplateLogo, width, padding, background & text colours, accent colour, alignment, and the email subject, heading, body and footer text.
Popup DesignLogo, width, padding, background & text colours, accent colour, alignment, overlay colour & opacity, and the popup heading and body text. Use {{email}} in the body to insert the customer’s address.

Under Test in the Email Template editor, click Send test email to send a sample with a random code to the logged-in admin, so you can check the design in a real inbox.

🛠️ Managing verified status

  • An Email Verified column is added to the WordPress Users list, with Mark verified / Mark unverified row actions.
  • The Customers List shows the same status and offers Mark as verified / Mark as unverified in the row actions (the same control, worded slightly differently).
  • Manually marking a customer verified requires permission to edit that user (Administrator or Shop manager). It overrides the check, so use it only when you have confirmed the address another way.

🔗 Using it alongside Customer Email Verification (CEV)

The built-in feature is self-contained — you do not need any other plugin. If the dedicated Customer Email Verification plugin (free or Pro) is active, Customer Info automatically steps aside and lets CEV handle verification, so the two never run at once, and the Email Verification tab shows a notice that CEV is in control.

Which to use? The built-in OTP is enough if you just want to verify emails at registration. Reach for CEV / CEV Pro when you need more — verifying existing users, verifying at checkout and other flows, disposable-email and spam protection, and reminder emails. You do not run both; whichever CEV plugin is active takes over.

🧰 Troubleshooting

ProblemWhat to check
The OTP email never arrivesAlmost always email delivery, not the plugin. Check spam, and use an SMTP plugin so mail is sent from an authenticated sender for your domain. Use Send test email to confirm delivery.
The verification popup doesn’t appearVerification is off, a CEV plugin is active (it takes over), or a heavily customised registration template is not firing the standard WooCommerce registration hooks.
The code is always rejectedIt has expired (default 10 minutes), or 5 wrong tries invalidated it — request a new one. Check the server clock if codes expire instantly.
A genuine customer is stuckConfirm their address another way, then Mark verified on the Users list or Customers List to let them through.