---
title: "Verify viewer email addresses (Email Verification)"
slug: "/help/demos/personalize/variables/email-verification"
topic: "demos"
last_updated: "2026-08-11T07:24:32.261Z"
---

## **About This Feature**

**Email Verification** adds a second step to the email gate: after a viewer types their address, Walnut mails them a one-time link. They can only open the demo or playlist after they click that link. It stops fake emails, typos, and shared inboxes from muddying your analytics — you know every session came from a real, reachable address.

### **Snapshot 📸**

**Feature Status:** Available to all customers who use the email gate.

**Role Access:**
**Configure workspace defaults:** Admin
**Turn on per demo or per playlist:** Admin, Editor, Presenter
**Verify email:** Any viewer

**Location:** **Company Settings → Access Control**, and the **Share** panel of any demo or playlist.

---

## **How Verification Works for the Viewer**

1. The viewer opens a shared demo or playlist and enters their email in the gate.
2. Walnut mails them a verification link. The waiting screen tells them to check their inbox and offers a **Resend** and **Change email** path.
3. Clicking the link opens the demo, and the viewer gets a **grant** that skips the gate on this browser for a while — so they can come back later without repeating the flow.
4. On a **playlist**, verifying once at the outer gate unlocks every demo inside. Viewers do not re-verify per demo.

Logged-in Walnut colleagues (Owners and workspace users) are exempt from the gate on assets they can already access.

---

## **Turn On Email Verification**

Email Verification sits on top of the existing **Collect viewers email** gate — turn the gate on first.

### **Workspace default (Company Settings)**

Open **Company Settings → Access Control**. Beneath **Collect Viewers Email**, use the **Email verification** control:

| **Setting** | **What it does** |
| --- | --- |
| **Off** | New demos and playlists won't ask viewers to verify their email address. |
| **On** | New demos and playlists start with verification on. Creators can turn it off on their own assets — to prevent that, pick Required. |
| **Required** | New demos and playlists require Email Verification, and creators can't turn it off. Demos and playlists that already exist keep their own setting. |

The **Non-work domain access** toggle sits alongside — turn it on if you want to accept `@gmail`, `@yahoo`, and `@outlook` addresses through the gate.

### **Per demo or playlist (Share panel)**

Open **Share** on any demo or playlist. Under **Collect viewers email**, flip the **Require email verification** sub-toggle. New playlists seed this from the company default and from the workspace's non-work-domain setting.

If your workspace default is **Required**, the sub-toggle is locked on newly created assets — existing demos and playlists keep whatever they had before the switch.

---

## **Playlist Behavior**

- **One gate for the whole hub.** A viewer who verifies at the playlist gate can open every demo it contains without seeing another gate.
- **Themed to your playlist.** The verification screens use the playlist's own colors and take the full screen, matching the hub's brand rather than the default Walnut chrome.
- **Custom-domain aware.** If the playlist is served on your custom domain, the verification link points back to that domain — not to `app.walnut.io`.
- **Rate-limited.** Requests for the verification link are rate-limited per email address, per IP, and per asset, so the feature can't be used to relay unwanted mail.

---

## **What Viewers See in the Email**

The verification mail is branded, includes your company logo, names the specific demo or playlist in the CTA ("Open *Q3 Product Tour*"), and links back to the authenticated app if the viewer needs to retry. The waiting screen offers **Resend link** and **Change email address** so a viewer who mistypes or loses the mail is never stuck.

---

## **FAQs**

**Do existing demos and playlists start requiring verification automatically?**
No. Changing the workspace default only affects newly created assets. Existing demos and playlists keep their own settings until you flip the sub-toggle on each one.

**How long does a verification last?**
Once a viewer clicks the link, their browser holds a grant for the demo or playlist so they can return without re-verifying. Clearing cookies or switching browsers requires a fresh verification.

**Does verification work with allow lists and specific-viewer lists?**
Yes. If you've restricted the demo to specific viewers or domains, verification runs on top of that check — the viewer's address still has to pass the list, and then they still verify.

**What happens if the viewer never clicks the link?**
Nothing. Without a valid grant they simply cannot open the demo. You'll see no session recorded, which is the point: fake or unreachable addresses stay out of your analytics.

**Can I preview the verification screen?**
Yes. In **Company Settings → Access Control**, click **Preview** next to Collect Viewers Email — the mocked player shows the gate, the waiting screen, and the branded verification mail together.

---

## **Related Resources**

[Identify viewers with email gates](/help/demos/personalize/variables/email-gates)
[Restrict who can view a demo](/help/account/company-settings/restrict-viewer-access)
[Company Settings](/help/account/company-settings)
