# Respondent email verification

Require a one-time code so email answers are real, reachable addresses.

## Respondent email verification

Ask respondents to confirm their email answer with a one-time code before the form accepts the submission. Every verified answer in your inbox is a real, reachable mailbox.

<h2 id="what-it-does">What it does</h2>
<p>
  Respondent email verification is a per-question rule on <strong>Email</strong> fields. When it is on, the respondent confirms the address
  they typed with a 6-digit code that formbase emails to them. The form does not accept the submission until the code checks out, so fake or
  mistyped addresses never reach your inbox. Turning the rule on requires a Business plan.
</p>

<h2 id="turning-it-on">Turning it on</h2>

Validation</strong>.',
    },
    {
      title: 'Turn on Require email verification',
      description:
        'The switch sits under <strong>Verification</strong> and carries a Business badge. Turning it on needs Business; turning it off works on any plan.',
    },
    { title: 'Publish as usual', description: 'The published form now asks respondents to verify before they can submit.' },
  ]}
/>

<p>
  Verification is not offered for email questions inside <a href="/building-forms/repeating-groups">repeating groups</a> — the server skips
  grouped questions too.
</p>

<h2 id="respondent-experience">What respondents see</h2>
<ol>
  <li>
    After typing a correctly formatted address, a <strong>Verify email</strong> action appears under the input.
  </li>
  <li>formbase emails a 6-digit code to that address. The code expires after 10 minutes.</li>
  <li>
    The respondent enters the code and the field shows a green <strong>Verified</strong> pill.
  </li>
</ol>
<p>
  Code didn't arrive? <strong>Resend</strong> unlocks after 30 seconds. Five wrong codes retire the code and the respondent asks for a new
  one. Disposable-mailbox domains are refused outright, with "Use a non-temporary email address."
</p>
<p>
  Respondents cannot leave the page or submit while a verification-required email question holds an unverified answer. The server checks the
  same thing on submit, so the rule cannot be bypassed by a hand-made request.
</p>
<p>
  If your form sends from a <a href="/branding-domains/custom-email-domains">custom email domain</a>, verification codes use it too.
</p>

<h2 id="same-address">Same address, multiple questions</h2>
<p>
  A verification belongs to the address and the respondent's session, not to the question. If two email questions hold the same address, one
  verification covers both. Changing the value re-checks it: a new address must be verified again.
</p>

<h2 id="good-to-know">Good to know</h2>
<ul>
  <li>
    <strong>Drafts</strong> — a respondent who leaves and resumes a saved draft from the same link keeps their verified addresses. Opening
    the form fresh in another browser starts a new session, so they verify again.
  </li>
  <li>
    <strong>Edit after submit</strong> — verified email answers are locked. Respondents cannot change them when editing a completed
    submission. See <a href="/submissions-analytics/edit-after-submit">edit after submit</a>.
  </li>
  <li>
    <strong>Downgrades</strong> — if your plan drops below Business, published forms keep accepting submissions and stop asking anyone to
    verify. Republishing is blocked while the rule is still on, so turn the switch off (possible on any plan) before you publish again.
  </li>
</ul>

> ℹ️ **Verifying answers vs. gating access**
> <p>
>     This rule verifies an email <em>answer</em>. To require respondents to sign in before they can open the form at all, use the{' '}
>     <a href="/sharing-publishing/authentication-gate">authentication gate</a> instead.
>   </p>

<h2 id="next-steps">Next steps</h2>
<div class="not-prose grid gap-3 sm:grid-cols-2">
  - [Field settings](/building-forms/field-configuration) — Validation rules and per-field options
  - [Edit after submit](/submissions-analytics/edit-after-submit) — What respondents can change later
  - [Authentication gate](/sharing-publishing/authentication-gate) — Require sign-in or a password to submit
  - [Plans & pricing](/subscription-billing/plans-pricing) — What each plan is for
</div>
