I’m building a consumer app on ICP that relies on Internet Identity’s verified-email attribute so a user can prove control of an email address before an action completes.
Coverage as measured against the live II config today (2 Sep 2026, rdmx6-jaaaa-aaaaa-aaadq-cai):
- The magic-email DKIM path accepts a fixed allowlist of 24 consumer domains (gmail/googlemail, outlook/hotmail/msn/live, icloud/me/mac, yahoo/ymail, aol, zoho, fastmail.com/.fm, hey, yandex.com/.ru, mail.ru, qq, 163, 126, naver, daum), matched exactly, so regional variants such as
yahoo.co.ukfall outside it (as reported in another thread in June). enable_dnssec_email_recovery = false.- Beyond that, Google sign-in yields a verified email for Google-hosted addresses, Microsoft sign-in for personal Microsoft accounts (work/school tenants excluded, as far as I can tell from the code), and Apple sign-in yields none (
email_verification = Unknown).
Three roadmap questions for the II team:
- Is the DKIM allowlist expected to grow? Is there a process for requesting a domain, or the regional variants of domains already listed?
- Is there a target release for enabling the DNSSEC path, which would generalize verification beyond the allowlist?
- Are Microsoft work/school (Entra ID) accounts planned for
verified_emailsupport via the Microsoft OpenID integration?
Even a rough timeline helps a lot. It decides how much I invest in handling addresses that can’t be verified today. Thanks!