Skip to content
← Help

Verifying your organization's address

Every organization has one address of its own, proved by a code we email to it. It is the only identity fact SendGather actually checks, and almost everything else leans on it.

Use a shared mailbox, not your own. office@ rather than your own name. It outlives whoever currently holds the role, it is printed at the foot of every request you send, and it is where the approval goes if somebody ever needs to take over the organization.

It is the organization's, not yours

Your login proves you control an inbox. This proves the organization controls one — which is a different claim, and the one that matters to a stranger deciding whether a request is real.

Keeping them separate is what lets people come and go. An owner can hand over and leave without the organization losing its identity, and nobody has to stay on the account just because their name is on the address.

Why a code and not a link

The best address for an organization is usually a shared mailbox, and the person reading it is often not the person signed in. A six-digit code can be read out across a desk; a sign-in link would either log in the wrong person or simply not work for the one who needs it.

The code lasts thirty minutes and you get five attempts. Five is the whole security of six digits, so a spent one has to be re-sent rather than retried — and a typo that is too short or not a number does not cost you a try.

Free mailbox providers are refused

Gmail, Outlook.com, Yahoo and the rest cannot be an organization’s address. Anyone can open one in any name, so it proves nothing about the organization — and the whole value of printing the address in every request is that it does.

It is a real limit, not an oversight: a group with no email domain of its own cannot send through SendGather at all. See why you can’t send for what such a group can still do.

Changing it later

The old address keeps working until the new one confirms, so a typo can never strand you. What else it takes depends on where you are moving it to:

  • Same domain — a code to the new address, and that is all. The organization stays anchored where it was.
  • A different domain — the code, and then approval from the address you are moving away from. Re-anchoring an organization’s identity is more consequential than changing its owner, so the current address has to agree.

Starting a new change cancels any approval still outstanding. That is deliberate: an approval granted for one address must never be able to promote a different one somebody swapped in afterwards.

Whichever route it takes, everybody is told — every admin, the new address, and the old one. Nobody is asked to approve except in the cross-domain case; everybody finds out.

Two organizations on the same domain

This is allowed, and common — a district with several schools, a firm with several practices, a foundation running separate programmes. If another organization has already verified your domain we tell you so once yours confirms, because the state that causes trouble is the one nobody notices: two organizations with the same name and separate lists, where neither coordinator can see why the other’s requests are invisible.

Nothing is shared between them. It is a warning, not a refusal.

Only the owner can change it

It is the one setting that outlives everyone on the account. Other admins see the current address and who to ask.