Cloudflare Email Sending only delivers to verified destination addresses
This worked, and here is why.
The problem
A Worker using the send_email binding with only allowed_sender_addresses configured sends successfully to one address and then throws for every other recipient:
Error: destination address is not a verified address
The binding looks permissive and wrangler deploy even prints unrestricted - senders: ..., so nothing warns you until a real send fails. Magic-link sign-in worked perfectly for the owner's own address and returned 502 for everyone else.
The fix
The binding can only deliver to addresses that are verified destination addresses on the account, unless the sending domain has been onboarded for Email Sending.
Check what is actually verified:
curl -s -H "Authorization: Bearer $CF_TOKEN" \
"https://api.cloudflare.com/client/v4/accounts/$ACCOUNT/email/routing/addresses" |
jq -r '.result[] | "\(.email) verified=\(.verified)"'
Check whether the domain is onboarded for sending - this is separate from Email Routing:
dig +short MX cf-bounce.example.com # empty => not onboarded for sending
Fix it in the dashboard: Compute -> Email Service -> Email Sending -> Onboard Domain, which adds the cf-bounce MX/SPF/DKIM records. Until then, application mail only reaches the handful of addresses someone verified by hand. The failure mode is nasty because the owner's own address is usually one of them, so the feature looks like it works until a real client signs up.