<ul data-eligibleForWebStory="true">After user signup, confirm email ownership with self-contained link that expires.Use JWT for email verification, avoiding database lookup or external services. Include user ID and expiration time in JWT claims for added security.Generate token, send URL with token in email, decode token upon user click.Verify token validity, mark user as verified, prevent misuse with cooldowns.