Artifact Signing: Identity validation says "Email verification failed" but no email was ever sent (kssq.com Verified)

George Wells 0 Reputation points
2026-03-18T18:02:00.2733333+00:00

I need a human from the Artifact Signing / identity validation team to inspect the logs for this tenant and explain why the verification email is never dispatched, and what exact change is required so that validation can complete. I need a manual log review for Artifact Signing identity validation. The failure is in Microsoft's backend, not email delivery.

Facts:

Tenant name: kssq.com

Tenant ID: a7a5309f-1262-45a3-909c-cd732148fa39​

Subscription: “Azure subscription 1” (trial with remaining credit shown in portal)​

Primary email used for validation: ******@kssq.com

I own the kssq.com domain and business. I have been a GoDaddy reseller for more than 15 years, and kssq.com is my company domain.

Mail system: Microsoft Exchange for kssq.com (not GoDaddy mail, not Gmail). External email to ******@kssq.com is working and tested from multiple senders.

Custom domain status in Microsoft Entra ID → Custom domain names:

NETORGFT11500575.onmicrosoft.com – Status: Available

kssq.com – Status: Verified​

Identity validation behavior:

I submitted an Artifact Signing identity validation using ******@kssq.com as the email address.

I NEVER received any verification email/link for identity validation on ******@kssq.com.

I DID receive other emails from Azure/Microsoft at this same address, including the email telling me that my identity validation had failed due to “Email verification failed”.

I have thoroughly checked spam/junk and other folders, and I have confirmed there is no local mail‑filtering issue. Other people have successfully sent me test mails.

Key point: The problem is not on my side with DNS, Exchange, or spam filtering. The domain kssq.com is Verified in this tenant, and normal email delivery to ******@kssq.com works. Yet the Artifact Signing validation reports “Email verification failed” without any verification email ever being delivered.

Request:

Please check the identity validation logs for:

Tenant ID: a7a5309f-1262-45a3-909c-cd732148fa39

  Subscription: Azure subscription 1
  
     Primary validation email: [******@kssq.com](mailto:******@kssq.com)
     
     Confirm:
     
        Whether any verification email was actually generated and sent to [******@kssq.com](mailto:******@kssq.com) for my latest validation attempt.
        
           If it was sent, what delivery status is recorded (bounce, block, internal error, etc.).
           
              If it was NOT sent, at what internal step the validation failed (for example AU10TIX verification, VC issuance, role check, tenant/domain policy, or something else).
              
              Provide the specific backend failure reason (error code / step), not just the generic “Email verification failed”.
              
              Confirm whether I can safely submit a NEW identity validation request now that:
              
                 kssq.com is a Verified custom domain in this tenant
                 
                    [******@kssq.com](mailto:******@kssq.com) is my Exchange mailbox on that domain
                    

or whether something in my tenant configuration still needs to be changed first.

This issue is directly blocking my ability to deliver software via downloads to potential customers and existing customers. Windows SmartScreen is warning on my unsigned binaries, and I cannot obtain an Artifact Signing certificate because the identity validation keeps failing at the “Email verification” phase without ever sending me the verification email.

I need a human from the Artifact Signing / identity validation team to inspect the logs for this tenant and explain why the verification email is never dispatched, and what exact change is required so that validation can complete.

I will greatly appreciate any help with resolving this.

Artifact Signing
Artifact Signing

A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)

0 comments No comments

1 answer

Sort by: Newest
  1. AI answer

    2026-03-18T18:02:21.6966667+00:00

    Manual log inspection for a specific tenant or identity validation request can't be performed here. For this scenario, the supported paths are:

    1. Create a new identity validation request
      • When email verification fails, the documented remediation is to submit a new identity validation request.
      • Ensure the primary email address is an individual mailbox (not a distribution list) and can receive emails with links from external senders.
      • If the email verification link expires (not clicked within 7 days), a new identity validation request is required; links can’t be resent for the same request.
    2. If email verification still fails with a new request
      • Use Azure Support to have the Artifact Signing team review the case. Provide:
        • Tenant ID
        • Subscription ID/name
        • Artifact Signing account name
        • Identity Validation Id (from the Identity Validation details pane in the Azure portal)
        • The primary and secondary email addresses used
      • You can also post on Microsoft Q&A with the artifact-signing tag for additional assistance, but tenant‑specific log review and backend checks are done via Azure Support.
    3. Confirm prerequisites and configuration
      • Verify that the New identity button is active and that the account used has the Artifact Signing Identity Verifier role.
      • For public identity validation, ensure all required fields (organization name, website URL, business identifier, address, etc.) are accurate and match public records.
      • If identity validation fails for reasons other than email verification and additional documentation is requested, there are only three attempts to upload documents. After that, onboarding can’t proceed for that request.
    4. If identity validation repeatedly fails and can’t be resolved
      • If the Microsoft validation team can’t validate the information even after requested documentation is provided, onboarding to Artifact Signing can’t proceed. In that case, the guidance is to delete the Artifact Signing account to avoid being billed for unused resources.
    5. When it is safe to submit a new identity validation
      • A new identity validation request can be submitted at any time, provided the required role is assigned and the previous request is not being reused for email verification.
      • If a new identity validation is needed for the same organization but with a different primary email address while another validation exists, contact Azure Support to continue onboarding.

    For the specific backend reason codes, delivery status, or internal step where email verification fails, only Azure Support and the Artifact Signing team can access and interpret those logs.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.