---
title: "Verification codes"
description: "The sign-in code from a verification email, at the top of the message with a button to copy it."
url: "https://openemail.uk/docs/knowledge/reading/verification-code"
area: "Knowledge base"
category: "Reading & organising"
status: "live"
---

# Verification codes

The sign-in code from a verification email, at the top of the message with a button to copy it.

## Details

- When a message is a sign-in or verification email, its code sits at the top of the message in a card of its own, with Copy code beside it. The code is copied without spaces or dashes, so it pastes straight into a field that asks for six digits.
- The card appears only when OpenEmail is sure. The sender has to pass its domain’s checks, nothing about the message can be flagged, it cannot have arrived in Spam or Trash, and it has to hold exactly one code worded as one, such as a verification code, a one-time code or a security code, in any of the common languages. When two different codes appear, or the number could be an order, a booking, a meeting, a phone number or a promotion, there is no card and the message reads as it always did.
- Codes are read as mail arrives, and mail that arrived before this existed is read when you open it. Imported mail never shows a card, because nothing records whether its sender passed the checks.
- The REST API and the SDK return the code as verificationCode on every message, null when there is none, and the MCP server includes it for the latest message of a conversation, so an agent waiting for a sign-in code can read it.
