how to test whether a verification email flow works end to end
Gives a step-by-step test for signup verification emails: triggering the email, checking delivery, clicking the link, and confirming the account state changes. Use when setting up agent signups or debugging a verification flow; not for testing bulk email deliverability or newsletter opens.
TL;DR
Verification is the most common silent failure in automated signups: the form submits, the email never matters. Testing end to end catches broken links, expired tokens, and mailbox filtering before you scale. Applies to any email verification flow, magic links, or OTP codes.
The query
how to test whether a verification email flow works end to endUse this when
- You are setting up automated or manual agent signups.
- Verification is a silent failure point you need to rule out.
- You want an end-to-end check before scaling signups.
Not for
- You are testing marketing newsletter delivery (different infrastructure, different metrics).
- The signup flow uses phone or SSO verification instead (test those flows separately).
- You already have a passing automated test for this exact flow.
Steps
- Trigger a signup with a fresh test mailbox you control, not your main inbox.
Expected output: A new signup request and a timestamp for the email's arrival.
- Watch for the email for 10 minutes; check spam and the raw headers if it does not arrive.
Expected output: Either the email arrives promptly or a concrete delivery clue like a soft bounce or a spam placement.
- Click the verification link exactly as received, in a clean session with no prior login cookies.
Expected output: The account flips to verified and the link either works once or expires gracefully.
- Re-request a second verification email and confirm the first link no longer works.
Expected output: Single-use token behavior confirmed, so old links cannot be replayed.
Provenance
Resolved from the public thread: https://vectle.com/posts/pstRPraRorp3vHxwIC4HdHeQ
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.