iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
“WHMCS verification failure” can describe four different problems, and each has a different fix. Start with the exact message you see and where it appears. A CAPTCHA score rejection, a CAPTCHA site key that is not authorized for your domain, an unverified client email address, and a mail server rejecting the sender address each have their own cause and their own first check. Trying the wrong fix usually wastes time, so match the message first.
Match the message to the right fix
Use this table to find the section that applies to your error. The source material is WHMCS’s own documentation, reviewed for the 8.13 and 8.10 documentation sets (pages last modified in August 2026). Menu labels can shift between releases, so confirm them against your installation.
| What you see | What it means | Read this section |
|---|---|---|
Captcha verification failed. Contact support for more information. |
The CAPTCHA provider scored the visitor as too suspicious for the current threshold. | Fix a CAPTCHA score rejection |
ERROR for site owner: Invalid domain for site key |
The CAPTCHA site key is not authorized for the domain WHMCS is running on. | Fix an invalid site-key domain |
| A client sees an unverified email banner and never completes verification | The validation link was not used in time, or the client did not log in to finish the process. | Fix client email verification |
Sender Verify Failed |
The sending address WHMCS uses does not exist, or is invalid, on the SMTP server. | Fix Sender Verify Failed |
Fix a CAPTCHA score rejection
This error means the CAPTCHA service scored the visitor below what your configured threshold allows. WHMCS’s troubleshooting article notes that the settings are often too restrictive, so the threshold is the first thing to review. Do not change anything else yet.
Adjust the score threshold
- Go to Configuration > System Settings > General Settings > Security.
- If you use Google reCAPTCHA v3, lower the reCAPTCHA Score Threshold.
- If you use hCaptcha, raise the hCaptcha Score Threshold.
- Save the change and submit the form again from a normal browser session to see whether the error clears.
The direction is easy to reverse by accident. WHMCS documentation states that “hCaptcha and reCAPTCHA v3 both use score thresholds, but their scoring systems are inverted.” A change that makes one provider stricter will make the other looser, so check which provider you use before you move the slider.
#1 Best Overall
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
WHMCS does not publish a universal numeric threshold, and this guide does not supply one. If Module Logging is enabled, open Configuration > System Logs and look at the scores recorded for real visitors. Choose a threshold that lets legitimate submissions through on your own traffic, then test it.
When the error appears on whmcs.com
WHMCS’s customer-facing CAPTCHA article covers submissions on whmcs.com itself. It lists three possible causes: use of a VPN or shared network, an ISP-assigned IP address that has a poor reputation, and possible malware on the visitor’s device. It is not a diagnosis for a self-hosted installation.
Rank #2
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
- Existing clients: sign in to the account and retry.
- Visitors who are not clients: disconnect from the VPN or shared network, refresh the page, and submit again.
- Still failing: ask an IT professional, network administrator, or your ISP to check the connection. WHMCS states that its customer-service team cannot bypass the check.
Fix an invalid site-key domain
The message ERROR for site owner: Invalid domain for site key is an authorization problem, not a scoring problem. Changing the threshold will not help. The provider has a list of domains allowed to use the key, and the domain WHMCS is running on is not on it.
- Note the exact hostname the WHMCS admin or client area loads from, including any subdomain.
- Sign in to your Google reCAPTCHA or hCaptcha dashboard and add that hostname to the key’s allowed domains.
- Confirm the matching site key and secret are the ones saved in WHMCS under the CAPTCHA settings.
- Reload the page that showed the error.
This error often follows a move to a new domain or subdomain, or a switch to a different CAPTCHA type. If you did not change the domain, check whether the CAPTCHA type was changed recently. If you do not want to manage a third-party account, WHMCS also allows switching to its default CAPTCHA option, which does not require a reCAPTCHA or hCaptcha account.
Rank #3
- USB-C or tap via NFC for easy authentication on any compatible device. No drivers needed; optional Kensington software available for advanced management features.
- Works across Windows, macOS, iOS, Android, ChromeOS, and supports Passkeys and Apple ID.
- Slim, keychain-ready form for easy carry and on-the-go authentication
- IP68-rated for dependable performance
- FIDO CTAP 2.1 for enhanced security features (e.g. resident credentials, Passkey support) and backwards compatibility with CTAP 2. FIDO2 L2 certified security for phishing resistant protection against identity theft and unauthorized access.
Fix client email verification
WHMCS sends a verification message when a new user registers or an existing user changes their email address. The client clicks the link, then signs in to the Client Area to finish verification.
Timing and resending
WHMCS documentation states that “The validation link in each verification email is valid for 60 minutes.” This is the validity window for each link, as documented in the Client Email Verification article (WHMCS 8.10 documentation, last modified in August 2026).
Rank #4
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
- If the link has expired, the client signs in to the Client Area.
- The client selects the resend option in the verification banner to receive a new link.
- Until verification is complete, an unverified client can still use the Client Area, their services, and support resources. Verification is not a login barrier.
Checking status as an administrator
Open the client’s profile and check the verification status on the Summary tab. If the status stays unverified after the client confirms they clicked a fresh link, ask them to check spam folders and confirm the address on their profile is correct.
Fix Sender Verify Failed
Sender Verify Failed is a mail-server error about the sender identity. It is unrelated to CAPTCHA or to a client’s account. WHMCS documentation states that “This error indicates that the sending email address is invalid or does not exist on the SMTP server.” Your job is to make the WHMCS sender field match a real mailbox on that server.
Best Value
Check the system email address
- Go to Configuration > System Settings > General Settings > General.
- Find the system-mail Email Address field.
- Confirm that the address exists as an account on your SMTP server, and that the mailbox can send.
Check the support ticket import address
If the error appears while WHMCS imports support-ticket replies, check the From Address under the Mail tab. It must also match a real account on the SMTP server. Use the account that receives the replies, and avoid placeholder addresses.
Other email-sending failures
If the error is different, or email is failing for other reasons, open Configuration > System Logs and filter to the time of the failure. WHMCS’s email-sending guidance (covering WHMCS 8.0 and higher) separates problems into SMTP connection failures, rejected credentials, invalid senders, template syntax or security errors, and server rejections. Act on the exact logged error. Changing unrelated mail settings rarely resolves a specific message.
Recover admin access when CAPTCHA blocks sign-in
On a self-hosted installation, a CAPTCHA configuration can lock administrators out of the Admin Area. WHMCS documents a database recovery step for this case. It changes configuration directly, so use it only when you cannot reach the settings through the interface.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →- Confirm that you are working on the correct installation and have direct access to its database.
- Take a database backup and record the change before you run anything.
- Run the following SQL statement against the WHMCS database:
UPDATE tblconfiguration SET value = '' WHERE setting = 'CaptchaSetting';
- Sign in to the Admin Area and reconfigure CAPTCHA under Configuration > System Settings > General Settings > Security.
- Re-enable an appropriate CAPTCHA method only after you have verified the threshold and domain settings described above.
WHMCS presents this as an emergency recovery step, not a routine fix. If you are unsure whether you have database access, ask the person who manages the server rather than running the query.
Version and interface notes
- The CAPTCHA and email-sending steps follow WHMCS 8.13 documentation, last modified in August 2026.
- Client email-verification details follow WHMCS 8.10 documentation, last modified in August 2026.
- The whmcs.com CAPTCHA article applies only to submissions on whmcs.com, not to every installation.
- Menu names can differ between releases. If a label does not match, look for the same setting group in your version’s General Settings.
WHMCS’s documentation does not publish success rates for these fixes, so no single step is guaranteed to resolve a given installation. Use the exact error text and the logs to decide which section applies.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

