A fully managed end-to-end service for digitally signing code, documents, and applications. (formerly Trusted Signing)
The gmail.com address is almost certainly your answer. Organization validation requires the primary email to be on a domain the business owns. From the Quickstart:
"Enter a monitored email address on a domain owned by the legal business entity."
The secondary email has to be on that same domain. Gmail doesn't satisfy either, and it isn't something the validation team can waive, since the certificate is asserting your organization's identity.
The fix is a mailbox on a domain your business owns, then a fresh validation request using it. Whether you can simply start a new one, or whether the failed request has to be cleared first, I'm not certain. The FAQ does say that when a validation already exists under a different primary email you need to contact support to continue onboarding, but that's written for existing requests rather than failed ones. Try the new request first, and if it's blocked, that's when the support route applies.
On the support plan, you don't need one for this. The Quickstart says identity validation issues go through Microsoft Q&A rather than a support ticket, so you're in the right place. I'm a volunteer rather than a moderator so I can't route it, but a Microsoft moderator picking up this thread is the path if the new request doesn't work.
Help make this community better for everyone: if this answer resolved your issue, please accept it or leave an upvote. If not, share more details in a comment so we can continue the discussion and find the right solution.