E-mail Domain Checks
The internal check confirms affiliation by confirming control of an e-mail address at a recognised domain. No external provider, no document, no cost.
Where to find it
Architect Panel → Security:
- User Verification — the console — providers, types, checks and their history
Architect Panel → Integration & Connections:
- E-mail Accounts — the account the confirmation is sent from
How it works
The type lists acceptable domains. The user gives an address at one of them, receives a message, and follows the link. Control of the address is the evidence.
Domain patterns
Domains are listed separated by semicolons, and wildcards are supported. The shipped Student type uses *.ac.uk;*.sch.uk;*.edu; Healthcare Worker uses nhs.net;*.nhs.uk.
So you can accept an entire sector with a pattern, or name individual organisations exactly. Both are useful: a pattern for a whole sector, exact domains for a partner list.
What it actually proves
Be precise about this, because it determines whether the check is fit for your purpose. It proves the person controls an e-mail address at that domain today.
It does not prove their name, their role, or that they are currently employed — a university address often outlives graduation, and a leaver may keep access to a mailbox for weeks. For "is this person part of this community", that is fine. For "is this person authorised to make clinical decisions", it is not.
Where it is excellent
- Sectors with reliable domain conventions — academia, the NHS, government.
- Partner organisations whose domains you know.
- Anywhere the consequence of a wrong result is a discount rather than access to something sensitive.
Where it is not enough
- Populations with no consistent domain — teachers at independent schools, self-employed professionals.
- Anything where currency matters and a stale mailbox would mislead you.
- Anywhere the affiliation gates access to personal data about others.
In those cases an external affiliation provider checks against an actual register rather than a mailbox.
Be careful with wildcards
A pattern accepts every subdomain, including ones you have not thought about. Before adding one, consider who else holds an address under it — a broad academic wildcard admits staff, students, alumni and contractors alike.
If the distinction matters, name domains explicitly.
Watch the link timeout
The user must follow the link within the type's timeout. Where the message may sit in an inbox — a work address checked twice a day, or a shared mailbox — 30 minutes is not enough, and expired links are the main source of support for this check.
Check deliverability first
The whole check depends on a message arriving. Confirm your sending domain is properly configured, and test against one of the domains you intend to accept — corporate mail filters are the usual obstacle, and the failure looks to the user like the service is broken.
Worked example
A service accepts nhs.net;*.nhs.uk for its clinician type. Ninety per cent of clinicians verify in under a minute at no cost. The remainder — private practice and locum staff without an NHS address — are routed to an external affiliation provider, so nobody is excluded by the cheap route not covering them.
Recommendations
- Use it wherever the domain convention is reliable.
- Be clear it proves mailbox control, not employment.
- Prefer exact domains to wildcards where the distinction matters.
- Provide a fallback route for people the domains do not cover.