WooCommerce
Email Verification
Plugin
The WooCommerce email verification plugin that stops fake signups and spam orders — OTP at registration, checkout and login.
Version 3.0.3 • Last updated: September 2026 • Compatible with WooCommerce 11.0.1 • WordPress 7.1
Email Verification
OTP-based customer verification
Alex Wilson — Signup
OTP verified · [email protected]
Jane Roberts — Checkout
Guest verification · [email protected]
Mike Kim — Login
New device detected · OTP sent
Spam Registrations Blocked
94% reduction this month
Spam Registrations
-94% Reduced
Is your customer database polluted with fake accounts?
Bots, fake signups, disposable emails, and free-product hunters quietly poison your customer data, deliverability, and analytics. It's time to verify every customer touchpoint.
Without Email Verification
-
Bot Signups & Fake Accounts
Spambots create accounts in seconds. Your user database fills with garbage that breaks analytics and bounces emails.
-
Free Product Abusers
Fake emails sign up for free trials, free products, and promotional offers repeatedly. Real customers never see them.
-
Disposable Email Flood
Mailinator, GuerrillaMail, 10minutemail — temporary email providers let abusers create unlimited fake accounts.
-
Unauthorized Logins
Stolen credentials from data breaches give attackers access to real customer accounts. No second layer of security.
With Email Verification
-
OTP Email Verification
Every signup, checkout, and suspicious login requires a one-time password sent to a real email address. Bots and fakes blocked at the door.
-
Paid-Order Gatekeeping
Delay account activation until a non-zero paid order is completed. Keeps fake accounts and coupon abusers from exploiting free downloads or trials.
-
Disposable Email Blocking
A curated blocklist of 430 known disposable providers, plus AI pattern matching that catches temp-mail domains registered this morning. Add your own rules on top.
-
2FA Authentication
Add Google Authenticator, Authy, or Microsoft Authenticator as a second layer for sensitive operations — globally or per role.
-
Auto-Cleanup Engine
Daily cron jobs automatically remove stale unverified accounts and clean up your customer database — with built-in safeguards.
AI Fraud Detection That Runs Entirely on Your Server
Scores every signup, catches brand-new throwaway domains before blacklists update, and halts coordinated bot clusters before they touch your store database.
Zero External APIs • Zero Customer Data Leaks
All AI evaluation, risk scoring, and regex pattern matching run directly inside your WordPress installation.
Score every signup before it becomes a customer
One number, built from four signals, with you deciding what happens at each level.
A blocklist can only answer yes or no. Risk scoring gives every registration and guest checkout a score from 0 to 100, built from several weak signals that are only alarming together — a random-looking mailbox, an unfamiliar domain, a plus-address pattern, a run of signups from one IP address. You choose what happens in each band: let it through, ask for a one-time code, or block it outright. Low, Balanced, and Strict move the cutoffs without you having to think in numbers.
Sensitivity Threshold Presets
| Sensitivity | Ask for a code from | Block outright from |
|---|---|---|
| Low | 55 | 85 |
| Balanced (Default) | 40 | 70 |
| Strict | 30 | 55 |

Catch temp-mail domains that aren't on any list yet
New throwaway services appear faster than blocklists can be updated.
The built-in list covers 430 known disposable providers. The new pattern matcher goes further: it reads the shape of a domain instead of looking it up, so a temp-mail service registered this morning is rejected the first time someone tries it on your store. Mainstream mailbox providers are never touched, and your own excluded domains always win — so a false positive is one line to fix, not a support ticket.

Stop the whole bot run, not one signup at a time
Some attacks only look wrong when you see them together.
One registration from a bot run looks unremarkable. Twenty of them inside ten minutes do not. Cluster detection watches for the shapes a coordinated attack makes — many addresses from one network sharing a browser fingerprint, sequential addresses on one domain, a sudden flood on a single domain — and blocks further signups once a burst crosses your threshold. It's the layer that catches what per-signup rules are designed to let through.

Ask every customer for a code, every time
For stores that would rather not decide which logins look risky.
Login Authentication normally challenges only unfamiliar sign-ins. Switch this on and every customer gets a one-time code at every login — useful straight after a spam attack, or on a wholesale store where protecting account access matters more than streamlining it. Administrators, editors, and shop managers are never prompted, so you can't lock yourself out of your own store.

Verify Every Customer Touchpoint in 4 Steps
Trigger Verification
At signup, checkout, or suspicious login, CEV PRO sends a 6-digit OTP to the customer's email. The action pauses until they verify.
Validate the Email
Behind the scenes, CEV checks disposable email blocklists, runs DNS-based MX record validation, and verifies the address is reachable.
Customer Verifies
Customer enters the OTP code in the verification popup. If 2FA is enabled, they also confirm via Authenticator App. Verified.
Auto-Cleanup Unverified
Daily cron jobs handle the rest — re-engage lapsed signups with reminder emails, auto-delete stale accounts (with safeguards).
Everything You Need to Verify, Secure, and Clean Up
From OTP verification to 2FA, disposable email blocking to DNS validation — everything a WooCommerce email verification plugin should do.

OTP-Based Email Verification
Send a one-time password to the customer's email at every critical touchpoint — signup, checkout, login from new device, or after inactivity. Real emails verified; bots and fakes blocked at the door.
- 6-digit OTP via email (no third-party services required)
- Verification at signup, checkout, and login
- Configurable expiry time
- Resend OTP option for failed deliveries
- No coding required — works out of the box
- Fully customizable email content

Smart Form — Branded Login & Registration
Replace WooCommerce's default login and registration form with a fully-branded Smart Form. Pick from four ready-made layouts, let customers register with email or phone, and offer password or OTP-based login. Place it on My Account or any page via shortcode.
- 4 ready-made template layouts
- Optional My Account page takeover
- Password, Email OTP, or Phone OTP login
- Place anywhere with [cev_smart_form] shortcode
- Email or phone (SMS) registration
- 4 SMS gateways: MSG91, Twilio, Vonage, WhatsApp

Phone (SMS) Verification
Verify customers via SMS OTP as an alternative to email verification. Customers can register and verify with their phone number using MSG91, Twilio, Vonage, or WhatsApp as the SMS gateway.
- SMS-based OTP verification
- 4 supported gateways: MSG91, Twilio, Vonage, WhatsApp
- Register with phone number instead of email
- Works with Smart Form and standard WooCommerce registration
- Configurable SMS message content
- Fallback to email OTP if SMS fails

Two-Factor Authentication (2FA)
Add Google Authenticator, Authy, or Microsoft Authenticator as a second layer of security for customer logins. Block credential-stuffing attacks even when passwords are compromised in data breaches.
- Google Authenticator support
- Authy & Microsoft Authenticator support
- Works with any TOTP-compatible app
- QR-code setup for customers
- Optional or required per user role
- Backup codes for account recovery

Role-Based Verification Rules
Enforce verification rules per user role. Require 2FA only for administrators and shop managers. Skip verification for trusted VIP customers. Tailor security to your store's operational structure.
- Per-role verification settings
- 2FA enforcement per role
- Skip verification for trusted roles
- Granular control for complex stores
- Works with custom role plugins
- Per-role policy override

Paid-Order Gatekeeping
Prevent free product and coupon abusers by delaying customer activation until their first paid order is completed. Accounts created via $0 or zero-total checkout orders will remain in "pending paid order" status and won't have customer access until a genuine payment is confirmed.
- Block free/coupon product abusers
- Keep zero-total checkout accounts in pending status
- Activate only when order status is completed with non-zero total
- Detailed paid order verification history
- Manual override to activate users manually
- Works seamlessly with standard WooCommerce gateways

Verification Analytics Dashboard
Know exactly how CEV PRO is protecting your store. The new Analytics tab shows signups, verification rate, blocked spam totals, average time-to-verify, top blocked disposable domains, and a signup-to-verify funnel chart.
- Total signups + verified vs unverified breakdown
- Spam registrations blocked
- Average time-to-verify metric
- Top blocked disposable domains chart
- Signup-to-verify funnel visualization
- Date range filters: 7, 30, 90 days or custom

Disposable Email Blocking
Block signups from temporary email providers (Mailinator, GuerrillaMail, 10MinuteMail and 430 more). The bundled list ships with the plugin and the AI matcher catches new ones. Add your own blocked domains and customize the rejection message.
- 430 bundled disposable email domains
- Admin-defined custom block list
- Catches signups before they're created
- Eliminates a major spam vector

DNS-Based MX Record Validation
Before sending an OTP, CEV PRO validates that the email domain actually has working mail servers (MX records). Catches typos, fake domains, and non-existent providers — saves you SMS costs and reduces bounces.
- Real-time MX record DNS lookup
- Catches typos (gmail.con, yaho.com)
- Blocks fake/non-existent domains
- Improves email deliverability reputation

B2B Allowlist & Block Specific Addresses
Run a B2B store or restricted-access community? Allow only specific domains to register (e.g., partner.com, customer.org). Or block specific email addresses that have abused your store before.
- B2B Allowlist mode
- Block specific email addresses
- Per-domain or per-address rules
- Perfect for partner-only stores

Automatic Database Cleanup
Daily cron jobs automatically remove stale unverified records and auto-delete unverified WP user accounts — with safeguards. Never pay for storage or send emails to unreal customers again.
- Auto-delete unverified user accounts
- Hard 30-day minimum retention safeguard
- Skips users with orders/subscriptions
- Preview accounts before deletion

Force Re-Verify All Customers
Take control during security incidents or system updates. Instantly flip all verified customer accounts back to unverified status in bulk. Upon their next login, customers will be prompted to verify their access via email or SMS OTP. Safe background batching protects your server from timeout errors.
- Bulk unverify entire customer base with one click
- Background queue processing to prevent server timeouts
- Optional exclusion lists for specific trusted user roles
- Stops credential-stuffing and bot waves dead in their tracks
- Real-time visual queue progress bar and status
- Fully logged database security action

Re-engagement Reminder Emails
Don't lose lapsed signups. Automatically email unverified users at 1-hour, 24-hour, 3-day, and 7-day intervals with a one-click verification link. Fully customizable via the email customizer.
- Auto-send reminders at 1h / 24h / 3d / 7d intervals
- One-click verification link in email
- Bulk send from Unverified Users table
- Bring lapsed signups back before you delete them

Fully Customizable Verification Popup
Match your brand identity. Customize the verification popup layout, colors, text, and branding so verification feels native — not bolted on.
- Color and layout customization
- Custom logo upload
- Multi-language support
- Live preview while editing
Why Stores Choose Email Verification
Store owners choose this verification plugin because fake signups cost them real money — in wasted postage, failed deliveries and support time.
Eliminate Spam Registrations
Bot signups blocked at the door.
Block Disposable Emails
430 temporary email providers rejected automatically.
2FA Security Layer
Authenticator app protection for sensitive accounts.
Role-Based Rules
Enforce 2FA per user role, not site-wide.
DNS Validation
Reject fake domains before sending OTPs.
Auto-Cleanup Engine
Daily cron removes stale unverified accounts.
Re-engagement Automation
Recover lapsed signups with reminder emails.
Verification Analytics
See exactly what spam you're blocking.
B2B Allowlist Mode
Only approved domains can register.
Better Email Deliverability
Verified addresses = lower bounces.
HPOS & Block Checkout Ready
Built for modern WooCommerce.
Ongoing Updates & Priority Support
Regular updates and dedicated support.
CEV Free vs. Pro: What You Get
| Features | Free | PRO |
|---|---|---|
| Basic Registration Verification | ✓Included | ✓Included |
| Checkout Verification | —Not included | ✓Included |
| Login Verification (New Device) | —Not included | ✓Included |
| 2FA via Authenticator AppNEW | —Not included | ✓Included |
| Role-Based Verification RulesNEW | —Not included | ✓Included |
| Verification Analytics DashboardNEW | —Not included | ✓Included |
| Disposable Email Blocking (3,000+)NEW | —Not included | ✓Included |
| DNS-Based MX ValidationNEW | —Not included | ✓Included |
| B2B Allowlist ModeNEW | —Not included | ✓Included |
| Block Specific Email AddressesNEW | —Not included | ✓Included |
| Auto-Cleanup Verification LogNEW | —Not included | ✓Included |
| Auto-Delete Unverified UsersNEW | —Not included | ✓Included |
| Re-engagement Reminder EmailsNEW | —Not included | ✓Included |
| OTP / Popup Verification | ✓Included | ✓Included |
| Customizable Email Templates | ✓Included | ✓Included |
| Customizable Verification Popup | —Not included | ✓Included |
| Login Notification Emails | —Not included | ✓Included |
| HPOS Compatible | —Not included | ✓Included |
| WooCommerce Block Checkout | —Not included | ✓Included |
| Priority Support | —Not included | ✓Included |
| Upgrade to CEV PRO |
Looking for the free version?
Get started with Customer Email Verification for WooCommerce free on WordPress.org — essential email verification features.
Frequently Asked Questions
Verification emails are sent by your WordPress installation, so deliverability depends on how your site sends mail — not on CEV PRO itself. WordPress’s default PHP mail is frequently filtered as spam. If codes are landing in junk folders, connect an SMTP service such as SendGrid, Postmark, Brevo or Amazon SES and authenticate your sending domain with SPF and DKIM records. Once your domain is authenticated, OTP emails reach the inbox reliably.
If you want verification that runs entirely on your own server, this one. Most alternatives send every customer email address to a third-party API for validation, which means your customer data leaves your store and you pay per check. Customer Email Verification does the OTP flow, disposable-domain blocking and DNS validation inside WordPress, with no external service and no per-verification cost.
They can request a new code using the resend button on the verification popup. If a customer still can’t complete verification, you can mark their account as verified manually from the WordPress admin, so nobody is ever locked out of buying from you.
CEV PRO checks an address before it ever sends a code. DNS-based MX record validation confirms the domain has working mail servers, disposable-domain blocking covers known throwaway providers, and the AI Temp-Mail Matcher catches new throwaway services that aren’t on any blocklist yet. Version 3.0.2 added AI risk scoring and bot-cluster detection, which stop coordinated signup runs rather than one address at a time. You can also enable paid-order gatekeeping, which holds customer activation until a first paid order completes.
Verification adds one step: the customer enters a code sent to their email. You control where it applies — registration, guest checkout, login from a new device, or only for specific user roles — so you can protect the touchpoints that are actually being abused without adding friction everywhere else.
Yes. CEV PRO supports both the classic checkout and the newer block-based Cart and Checkout, and fully supports High-Performance Order Storage.
Your plugin keeps working and no tracking data is lost — nothing switches off. What stops is plugin updates and priority support.
Your licence renews at the same price you paid — we never raise it at renewal. The 1 year plan is $119 and renews at $119 a year. The 2 year plan is $190.40 and renews at $190.40 every two years. The 20% saving on the 2 year plan applies to every renewal, not just your first term, so it stays at that price for as long as you keep the licence.
Yes. Your licence renews each year so you keep receiving updates and support. We email you 7 days before each renewal, and you can cancel any time from your account.
Everything, with no exclusions. If CEV Pro isn't right for your store, request a refund from your Orders page at https://www.zorem.com/my-account/orders/ within 14 days of purchase and we'll refund you in full.
No. Each licence activates on a single site, and staging and development installs count as separate sites. If you build on a staging copy before pushing live, choose the 5 Sites licence.
Yes, as often as you need. Deactivate the licence on the old site from your account, then activate it on the new one — there's no limit on how many times you can move it.
Install and activate CEV PRO — the free plugin deactivates itself automatically, so there's no risk of running both at once. Your verification settings, email design and verified-customer records live in the same place and carry straight across, so there's nothing to export and nothing to set up again. Just add your licence key on the License tab and you're done. (You can safely delete the free plugin afterwards.)
Yes. CEV Pro is tested against WooCommerce 11.0.1 and WordPress 7.1 and fully supports High-Performance Order Storage. We ship a compatibility update alongside every major WooCommerce release.
Priority email support from the team that builds the plugin. We usually reply within 24 hours — often much sooner.
Yes. Role-based rules let you apply different requirements per user role, for example requiring two-factor authentication for administrators and shop managers while customers only verify at signup. You can also run a B2B allowlist so only approved domains can register, and block specific addresses outright.
Explore Other Zorem Plugins
Zorem builds a connected set of WooCommerce plugins: fulfillment and post-purchase tools for everything after the order, and store management tools for running the shop behind it. Trusted by over 80,000 store owners.
Advanced Shipment Tracking Pro
The Most Powerful Fulfilment Manager for WooCommerce. AST PRO provides powerful features to easily add tracking info to WooCommerce orders, automate the fulfillment workflows and keep your customers happy and informed.
Country Based Restriction for WooCommerce
The Country Based Restriction (CBR) uses the WooCommerce Geolocation and allows you to restrict products and payment gateways based on the customer country.
Customer Info for WooCommerce
The Customer Info plugin provides a centralized dashboard for store admins to quickly access customer details, order history, and address information. This plugin improves customer support and account management by integrating with WooCommerce Subscriptions, HelpScout, and Intercom.
View as Customer for WooCommerce
The plugin does not have any settings, once installed a VIew As Customer menu will appear on the WordPress admin bar in the frontend of the store and will allow to switch to view the store as any customer. To switch back to the admin account, admins will need to log out from the customer account.