Channelsbeginner

Verify the address before a channel switch

Turn on Verify the address before switching to require a visitor to enter a one-time code sent to the email or phone number they give before their conversation moves to that channel.

5 min read

Verify the address before a channel switch

When a visitor asks to move a Web Chat conversation to email, SMS, or WhatsApp, they type in an address on the spot. Nothing stops them from typing an address that isn’t theirs — by mistake, or to see someone else’s replies. Verify the address before switching closes that gap: before the conversation moves, the visitor has to prove they can actually read what’s sent to the address they gave.

This article covers the verification toggle itself. For the base channel-switching setup — enabling the switch button, choosing which channels are offered, customizing the switch message — see Configure channel switching.

What it does

With Verify the address before switching turned on, Atender sends a one-time code to the email address or phone number the visitor enters. The conversation is only moved to that channel after the visitor enters the correct code back into the widget. If they never enter it, the conversation stays where it is — it does not silently switch, and it does not fail silently either. The team still has a record of the requested switch and the address the visitor gave, so an agent can follow up manually if needed.

Where to find it

  1. Go to Settings → Web Chat and open the widget you want to change.
  2. Turn on Show channel switch button if it isn’t already — the verification setting only appears once channel switching is enabled.
  3. Under Channel switching, turn on Verify the address before switching.
  4. Save the widget.

When you need it

Turn this on any time a wrong or made-up address could send someone else’s conversation history to a stranger, or leave a visitor waiting on replies that go nowhere because they mistyped their own address. It’s the difference between “the visitor said this is their email” and “the visitor proved this is their email.”

Leave it off if your visitors are already authenticated in some other way before they reach the switch form, or if the extra step is more friction than the risk warrants for your use case.

What counts as trusted, and what doesn’t

  • An address already on the visitor’s contact record is trusted and skips the code. If the visitor’s email or phone number is already stored on their contact, Atender treats that as sufficiently proven and switches immediately — no extra step for a visitor you already know.
  • An address the visitor just typed in is not trusted, even if it looks valid. It has to go through the one-time code before the switch happens.
  • An address an agent enters on the visitor’s behalf is not put through this check. The verification step exists to confirm what an anonymous visitor claims about themselves, not to gate agents.

Limits

  • WhatsApp switches are refused while this is enabled. There’s no one-time code flow for WhatsApp, so if a visitor requests a WhatsApp switch, it won’t go through as long as this setting is on. If you need WhatsApp switching, leave this setting off, or offer WhatsApp only alongside channels visitors can verify.
  • It needs a working email or SMS sender. The code has to actually be delivered. If your tenant’s email or SMS sending isn’t configured correctly for the channel the visitor picked, the visitor won’t receive a code and won’t be able to complete the switch. Check your sending configuration if visitors report never getting a code.
  • It doesn’t retroactively verify addresses already on file. Trust is based on what’s already stored on the contact, not on some separate approval step you have to run.

Where this applies

The same verification requirement applies everywhere a conversation can move to a visitor-supplied address, not just the switch button in the chat window:

  • The widget’s manual channel switch form — the flow a visitor triggers themselves mid-conversation.
  • The AI handover email follow-up — when an AI agent hands off and offers to follow up by email.
  • The outside-hours auto-switch — when a widget is configured to move conversations to another channel outside opening hours.

If a visitor abandons the code entirely on any of these flows, the requested switch is held rather than dropped — the team still sees the address the visitor typed and can decide whether to follow up manually.

See also

Tags

How ToSecurityConfiguration