After Summer '26, clicking an Email-to-Case routing address verification link while logged in as a different admin from the one who created the routing address will cause the verification to fail. This is Working As Designed (WAD) — the verification link is intentionally session-bound to the admin who initiated it.
Symptoms:
• Clicking the verification link redirects to the Salesforce login page.
• After logging in, Device Activation intercepts the flow.
• The routing address remains unverified.
• The issue only occurs when a different admin clicks the link.
Root Cause:
This is intentional behaviour introduced in Summer '26. The EmailChangeVerification service enforces that the same user session must be used for both:
• Initiation — clicking "Send Verification" in Setup.
• Completion — clicking the verification link in the email.
If a different user clicks the link, the token mismatch triggers Device Activation which blocks the verification from completing. This is a security posture — not a bug.
Steps to Reproduce:
1. Log in as Admin A — create a new E2C routing address and click Send Verification.
2. Close all Salesforce browser tabs.
3. Open the verification email and click the link.
4. When redirected to login, log in as Admin B (different user).
5. Observe — Device Activation intercepts and verification fails.
Expected: Verification completes
Actual: Device Activation fires — verification fails
Resolution / Workaround:
Option 1 — Preferred:
Forward the verification email to the admin who originally created the routing address. That admin logs in and clicks the link. The inbox the email arrives in does not matter — only the logged-in identity matters.
Option 2 — Different admin needs to verify:
1. The new admin logs into Salesforce.
2. Goes to Setup → Email-to-Case → Routing Addresses.
3. Clicks Send Verification again — this generates a new token bound to their session.
4. Opens the new verification email and clicks the link while still logged in.
5. Verification completes successfully.
Affected Versions:
Summer '26 and later
Option 1 — Preferred:
Forward the verification email to the admin who originally created the routing address. That admin logs in and clicks the link. The inbox the email arrives in does not matter — only the logged-in identity matters.
Option 2 — Different admin needs to verify:
1. The new admin logs into Salesforce.
2. Goes to Setup → Email-to-Case → Routing Addresses.
3. Clicks Send Verification again — this generates a new token bound to their session.
4. Opens the new verification email and clicks the link while still logged in.
5. Verification completes successfully.
• This is confirmed Working As Designed — no fix is planned.
• This behaviour is specific to routing address verification
005388172

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.