The reason it seems that way to you is because you haven't tested it.
The email address has to be verified, but any of the verified email addresses can be used to reset passwords. There is no way to un-verify an email address besides deleting it and re-adding it.
If that's the case, I'll be reaching out to GitHub to clarify the wording once my test shows otherwise. I specifically pointed out that I was basing my understanding on the message they provide.
EDIT: I've confirmed the wording doesn't match the execution, and I've send a message to GitHub
Thanks! I sent them an email a year or two ago and they haven't addressed it. It is a bit of an edge case, and there's a workaround. So I'm not annoyed that they haven't fixed it, but I will be glad when they do.
Comments
The reason it seems that way to you is because you haven't tested it.
The email address has to be verified, but any of the verified email addresses can be used to reset passwords. There is no way to un-verify an email address besides deleting it and re-adding it.
If that's the case, I'll be reaching out to GitHub to clarify the wording once my test shows otherwise. I specifically pointed out that I was basing my understanding on the message they provide.
EDIT: I've confirmed the wording doesn't match the execution, and I've send a message to GitHub
Thanks! I sent them an email a year or two ago and they haven't addressed it. It is a bit of an edge case, and there's a workaround. So I'm not annoyed that they haven't fixed it, but I will be glad when they do.