Unverifiable
- Michael Kolodner

- 4 hours ago
- 4 min read
Salesforce is making things so hard! (Again.) This time I think it's relatively unintentional, but should have been eminently foreseeable. Based on a change introduced in the Summer '26 release it's now a major pain in the butt to verify an organization-wide email address.

If you've tried it recently, you would have found that you set up the org-wide email address, the person with access to that in-box clicks on the link, they log in, but the address never shows up as Verified. Lather.
Rinse.
Repeat.
Try as you might, it doesn't work.
I only managed to get it to work by accident after about my third try, when I just asked the recipient to forward me the verification email. I clicked the link. I logged in. It was verified.
Unfortunately that's "working as designed," according to this Knowledge article. With the most recent release the verification link must be clicked by the user that initiated the verification in the first place.
This is a change in behavior. And while it's certainly possible that I missed the notice about it, this wasn't well publicized. (Maybe it's somewhere in the release notes, but I can't find it.) Honestly, even if Salesforce had shouted this from the rooftops, we were a little busy with other security-related changes and would have missed it.
This was poorly conceived. And very poorly executed.
What's Wrong
It might not be that bad that the person that initiates the verification for a new organization-wide email address must also be the person that clicks on the verification email (because after clicking, they must log in to the account that initiated the verification). But this is a change from how it used to work and it's basically secret lore.
When the admin initiates the verification there is no instruction of any sort that the verification must be completed by that admin (rather than the recipient). Not on initial creation

nor when waiting for it to verify.

And when the verification email arrives to the in-box there is still no instruction that the link should be clicked by the admin that initiated the verification.

There's not even any instruction that you'll have to log in after clicking. (In the past all you had to do was click; you did not have to log in after clicking.)
After you click the link and are taken to the login screen, it gives no indication that the verification will fail if you aren't logging in as the user that initiated the verification.
Come on, Salesforce, at least give us a fighting chance at figuring this out!
Workarounds
Can we get this to work? Yes. But it takes a level of coordination between admin and holder of email in-box that's a higher bar than usual. And if you don't even know you need to do it—I feel the need to remind you once again that it didn’t work this way a month ago!—it's an extremely confusing change of behavior and is guaranteed to cause pain and suffering.
Think about it: how often is the admin creating an organization-wide email address going to be the one that has access to the email box in question?
I would argue, "Not very often."
If the admin is part of the program team (or sales operations, or any of a dozen other kinds of departments that might house Salesforce admins other than IT) they probably don't have any control over the email server beyond their own email address.
Even if the Salesforce admin is part of the IT department that controls the email server settings, it’s pretty likely that the email being set up as organization-wide will not be an in-box the admin uses. (That's kinda' the point, in fact, of organization-wide email addresses. They're meant to either allow us to set up Salesforce to send as a particular person other than ourselves or as a shared address such as programs@ or info@.)
If the admin is part of the shared address's team they might have access to that shared email box, but my hunch is that even this is generally infrequent.
And if they're on a different team they definitely won't have access.
Not to mention that if the admin is a consultant they're not even in the email system of their client in the first place. Setting up org-wide email addresses is usually part of initial implementation, so it's likely being done by a consultant…
So if the person starting the verification can't act directly as the person receiving it, they have to let that recipient know what to do. But since Salesforce hasn't provided instructions at any point in the process, that's not very likely to happen.
Work Together in Realtime
If you have an existing relationship with the person that will receive the verification email, you can ask them to forward you that email. Obviously it's going to be best to ask for that in advance. And they need to know what you're talking about and what to look for as far as email they'll be forwarding to you. (And possibly why.)
I actually think your best bet is to set up that org-wide email address cooperatively in realtime.

Get on a Zoom together.
Have the recipient log into the mailbox in question.
Then initiate the verification.
Ask them to open the email, NOT click on the link, and copy/paste the link into the chat window.
You can then click the link and log in right away.
It may take a moment to coordinate when to get onto a call together but it will probably save time overall!




