Email Verify Pro adds an email-verification flow to WHMCS. It sends verification links, shows an overlay to unverified clients and redirects requests on selected client-area pages to verification.
The overlay and page hooks are not a guarantee that every WHMCS route, API or custom integration is inaccessible before verification. Test your actual client area, especially shared accounts and custom themes, before relying on the module for access restrictions.
Installation
- Back up your WHMCS files and database. Use the module package and PHP environment supported by your WHMCS installation.
- Upload the module to
/modules/addons/email_verify_pro/. Do not rename the folder. - Open System Settings > Addon Modules, or Setup > Addon Modules in older layouts.
- Activate Email Verify Pro, enter your license key and select the administrator roles allowed to use it.
- Open Addons > Email Verify Pro to configure verification and styling.
General settings
- Enable Email Verification System: Enable the verification hooks.
- Token expiry: How long a verification link remains valid. The initial value is 60 minutes.
- Allow Resend After: Minimum delay between resend requests. The initial value is 2 minutes.
- Maximum Resend Attempts: Limit for resend requests in the tracked 24-hour window. The initial value is 7.
The overlay resend handler stores counts in the database rather than only in the browser session. Other resend entry points do not all use that same limiter, so these settings must not be treated as a universal sending limit.
Email and overlay
Open Setup > Email Templates and edit the template named Email Verification. Keep its verification-link merge field intact. The module generates the link from your WHMCS System URL and uses the index.php?m=email_verification&verify= route. Do not rename that route to match the addon folder.
The Styling tab controls the overlay, modal, text, buttons and animations. Overlay visibility has a separate setting. Use Email Settings to review the template guidance and the support contact displayed to customers.
English, Dutch and Russian language files are included. Additional translations can follow the format of lang/english.php.
Customer workflow
- A new client registration triggers a verification email when the system is enabled.
- The customer opens the link before it expires.
- The module records successful verification and clears the token.
- If the link expires, the customer can request another email. The overlay resend handler applies the configured cooldown and request window.
The module also has hooks for email-change requests and WHMCS's native verification completion. Check both paths on your installation instead of assuming that a successful registration test covers them.
Administration and stored data
The addon has General Settings, Styling, Email Settings, Unverified Users and Verified Users tabs. Verification information also appears in the client profile.
Activation creates mod_email_verify_pro for settings and mod_email_verify_pro_rate_limit for resend tracking. The module uses and updates the existing verification fields in tblusers; it does not add those fields to the WHMCS core schema.
The daily WHMCS cron clears expired tokens and old rate-limit records. Deactivation preserves the module tables. That is different from saying the module never changes WHMCS data.
Test before enabling for customers
Use a test account to check registration, delivery, the verification link, expiry, resend cooldown, email changes and logout. On a shared account, test each linked user separately: the page checks resolve a user through the client-account relationship, so this article does not promise independent enforcement for every linked login.
Troubleshooting
- If emails do not arrive, check WHMCS mail delivery, the Email Verification template, the System URL, email logs and the recipient's spam folder.
- If the overlay is missing, check activation, system enablement, the separate overlay setting and whether the theme renders the relevant WHMCS hooks.
- If a link fails, request a fresh link and check the configured expiry. Do not share verification tokens in screenshots or support tickets.
- If requests are rate limited, wait for the cooldown or tracked window rather than repeatedly clicking resend.
Send support your module, WHMCS and PHP versions, the active theme, reproduction steps and a redacted error message.