Loading

Email-to-Case & Org Wide Email Address Routing Address Verification Link Fails When Clicked by a Different Admin

게시 일자: Jun 30, 2026
상세 설명

After Summer '26, clicking an Email-to-Case routing address verification & Org Wide Email Address  link while logged in as a different admin from the one who created the address will cause the verification to fail. This is Working As Designed (WAD) — the verification link is intentionally session-bound to the admin who initiated it.

Symptoms:
• Clicking the verification link redirects to the Salesforce login page.
• After logging in, Device Activation intercepts the flow.
• The routing address remains unverified.
• The issue only occurs when a different admin clicks the link.

Root Cause:
This is intentional behaviour introduced in Summer '26. The EmailChangeVerification service enforces that the same user session must be used for both:
• Initiation — clicking "Send Verification" in Setup.
• Completion — clicking the verification link in the email.

If a different user clicks the link, the token mismatch triggers Device Activation which blocks the verification from completing. This is a security posture — not a bug.

Email-To-Case

Steps to Reproduce:
1. Log in as Admin A — create a new E2C routing address and click Send Verification.
2. Close all Salesforce browser tabs.
3. Open the verification email and click the link.
4. When redirected to login, log in as Admin B (different user).
5. Observe — Device Activation intercepts and verification fails.

Expected: Verification completes
Actual: Device Activation fires — verification fails

ORG Wide Email Address 

Steps to Reproduce:

  1. Log in as Admin A — go to Setup → Organization-Wide Addresses → Add a new Org-Wide Email Address and click Save.
  2. Close all Salesforce browser tabs.
  3. Open the verification email and click the link.
  4. When redirected to login, log in as Admin B (different user).
  5. Observe — Device Activation intercepts and verification fails.

  Expected: Verification completes successfully.

  Actual: Device Activation fires — verification fails.

 

 

Affected Versions:
Summer '26 and later

솔루션

Email-To-Case

Resolution / Workaround:

Option 1 — Preferred:

Forward the verification email to the admin who originally created the routing address. That admin logs in and clicks the link. The inbox the email arrives in does not matter — only the logged-in identity matters.

Option 2 — Different admin needs to verify:
1. The new admin logs into Salesforce.
2. Goes to Setup → Email-to-Case → Routing Addresses.
3. Clicks Send Verification again — this generates a new token bound to their session.
4. Opens the new verification email and clicks the link while still logged in.
5. Verification completes successfully.

ORG Wide Email Address 

Resolution / Workaround:

Option 1 Preferred:  Forward the verification email to the admin who originally added the Org-Wide Address. That admin logs in and clicks the link. The inbox the email arrives in does not matter — only the logged-in identity matters.

Option 2 Different admin needs to verify:

  1. The new admin logs into Salesforce.
  2. Goes to Setup → Organization-Wide Addresses.
  3. Clicks the verification link next to the unverified address (or deletes and re-adds it) — this generates a new token bound to their session.
  4. Opens the new verification email and clicks the link while still logged in.
  5. Verification completes successfully.

 

추가 자원


• This is confirmed Working As Designed — no fix is planned.
• This behaviour is specific to routing address verification

Knowledge 기사 번호

005388172

 
로드 중
Salesforce Help | Article