Hello Auth0 Support Team,
We have a question regarding email update verification in Auth0.
Scenario
A user signs up using Email/Password with the email:
nihal@myworth.ai
Later, the user attempts to update their email address to:
nihal@abc.ai
Question
What is the recommended and secure approach in Auth0 to verify that the user requesting the email change is a valid and authenticated user before updating the email on their account?
Specifically, we would like guidance on:
Whether Auth0 supports email change verification flows out of the box
Best practices to:
Confirm the user’s identity (e.g., re-authentication, MFA, password re-entry)
Verify ownership of the new email address
How to prevent unauthorised email updates if a session is compromised
Our Goal
We want to ensure that:
Only the rightful account owner can update the email
The new email address is verified before becoming active
The process aligns with Auth0 security best practices
Any documentation references or recommended implementation patterns would be very helpful.
Thank you for your support.
Best regards,
Team myworth.ai