Customer Info includes a built-in Email Verification feature that asks new customers to confirm their email address with a one-time passcode (OTP) during registration. It reduces fake sign-ups and ensures you have a valid, reachable email on file. It is off by default, works on its own, and does not require the separate Customer Email Verification plugin.
🚀 How it works
- A customer enters their email on the WooCommerce registration form.
- A verification popup asks for the code sent to that email.
- They enter the OTP; on success, registration completes and they are logged in.
- Registration is blocked until the email is verified — the account is created only after a correct code, so there are no half-finished, unverified accounts left waiting.
⚙️ Settings
Go to WooCommerce → Customer Info, click the gear at the top-right, and open the Email Verification tab. The Settings sub-tab holds these options:
| Setting | Description | Default |
|---|---|---|
| Verification enabled | Master switch. When off, the popup never opens and registrations are not gated. | Off |
| OTP Length | Digits in the code: 4 to 8. | 6 digits |
| OTP Expiration | How long a code stays valid (1 minute to 1 hour). | 10 minutes |
| Verification Email Resend Limit | How many codes can be requested within the 15-minute window before the customer is rate-limited. | 3 attempts |
| Resend Limit Message | Shown when the resend limit is reached. Default: “Too many attempts, please contact us for further assistance.” | (the text above) |
Changes save as you make them — a Saved indicator confirms each one. Save settings writes everything at once, and Reset returns the settings on this tab to their defaults.
🔐 How the code is protected
- Codes are generated with a cryptographically secure random generator.
- Only a salted hash of the code is stored (never the code itself), in a short-lived record that is deleted when the code expires.
- A wrong code can be tried at most 5 times before that code is invalidated and a new one must be requested.
- Resends are throttled per email address and per IP within a 15-minute window, so the feature can’t be used to spam a mailbox.
🎨 Design customization
The Customization sub-tab has two editors, each with a live preview:
| Editor | What you can change |
|---|---|
| Email Template | Logo, width, padding, background & text colours, accent colour, alignment, and the email subject, heading, body and footer text. |
| Popup Design | Logo, width, padding, background & text colours, accent colour, alignment, overlay colour & opacity, and the popup heading and body text. Use {{email}} in the body to insert the customer’s address. |
Under Test in the Email Template editor, click Send test email to send a sample with a random code to the logged-in admin, so you can check the design in a real inbox.
🛠️ Managing verified status
- An Email Verified column is added to the WordPress Users list, with Mark verified / Mark unverified row actions.
- The Customers List shows the same status and offers Mark as verified / Mark as unverified in the row actions (the same control, worded slightly differently).
- Manually marking a customer verified requires permission to edit that user (Administrator or Shop manager). It overrides the check, so use it only when you have confirmed the address another way.
🔗 Using it alongside Customer Email Verification (CEV)
The built-in feature is self-contained — you do not need any other plugin. If the dedicated Customer Email Verification plugin (free or Pro) is active, Customer Info automatically steps aside and lets CEV handle verification, so the two never run at once, and the Email Verification tab shows a notice that CEV is in control.
🧰 Troubleshooting
| Problem | What to check |
|---|---|
| The OTP email never arrives | Almost always email delivery, not the plugin. Check spam, and use an SMTP plugin so mail is sent from an authenticated sender for your domain. Use Send test email to confirm delivery. |
| The verification popup doesn’t appear | Verification is off, a CEV plugin is active (it takes over), or a heavily customised registration template is not firing the standard WooCommerce registration hooks. |
| The code is always rejected | It has expired (default 10 minutes), or 5 wrong tries invalidated it — request a new one. Check the server clock if codes expire instantly. |
| A genuine customer is stuck | Confirm their address another way, then Mark verified on the Users list or Customers List to let them through. |