A Switch Is Only as Good as Reachable People
A switch is only as good as the people who can still be reached when it fires. Killswitch beneficiary verification checks contact info before delivery depends on it: silent checks for bad emails and phones, one-click Verify for recipients, and optional quarterly reachability. Problems show as badges and switch health warnings while you can still fix them.

You can set a perfect check-in schedule, attach the right documents, and write the letter you hope someone never needs. None of that matters if the email bounces and the phone number was typed wrong three years ago.
A deadman switch is a delivery promise. Delivery only works when the people on the other end can still be reached. That trust layer shipped as beneficiary verification.
Until now, Killswitch could remind you to check in, show switch health, and prepare share links. What it could not do was prove, ahead of time, that a beneficiary's contact info was still a place mail and texts can land. You got receipts for your own side of the system. The other side stayed assumed. That assumption is where plans quietly fail.
Why do estate plans fail quietly on contact info?
Estate plans rot in quiet ways. An old Gmail with a typo. A carrier number that got reassigned. A sibling who moved and never updated anyone. On paper the switch looks healthy. The day it fires, the delivery has nowhere to go.
You already get check-in reminders and delivery receipts. Now you can know whether the people you named are still reachable, before anything depends on it.
What does beneficiary verification actually check?
Verification is a layered check. It is not a claim that we own someone's inbox or that we magically know a phone belongs to them.
Silent checks when you add or edit a beneficiary. No email goes out. Killswitch catches obvious typos ("did you mean gmail.com?"), looks for bounce-style evidence that an address is dead, and uses MX hints to see whether a domain looks able to receive mail. For phones, a validity lookup confirms the number is real and routable. Problems show up as badges on your beneficiary list.
Those silent checks are hints and evidence, not ownership proof. A clean badge does not mean "this inbox is theirs forever." It means the contact info does not look broken on the surface.
How does one-click Verify work?
Click Verify next to a beneficiary and Killswitch sends them a single email. It leads with your name, explains what Killswitch is, and asks for nothing but a click. After they confirm the email, US and Canadian numbers can optionally be confirmed with a one-time code on the same page. The recipient chooses "Text me a code." There is no international phone OTP, and the text step is never forced.
Quarterly reachability, only if they opt in. After someone verifies, they can choose a one-click "still reachable?" check every quarter. It is opt-in, never forced. If they stop answering, you get warned while there is still time to sort it out, before anything fires.
Verification ages out. Status expires after a year. Answered reachability checks keep it fresh automatically. People change addresses. The system should expect that.
How does verification stay respectful?
Beneficiaries did not sign up for Killswitch mail. So verification requests are rate-limited, every message has a one-click decline or stop, and those choices are honored immediately.
Decline is not one blunt button. There are two modes:
- Don't contact before fire. They can stop verification and reachability mail, and delivery still stands when a switch fires.
- Remove entirely. If someone asks to be taken off, you are alerted and guided to talk with them directly. That is a relationship problem first, a settings problem second.
Invite volume stays capped so nobody gets spammed: a cooldown per beneficiary, a lifetime cap, and a daily owner limit. Enough to verify the people who matter. Not enough to turn Killswitch into noise.
How does verification affect switch health?
Verification status feeds each switch's health check.
Plain never-verified does not tank switch health. You see a badge. That is the nudge.
Critical health warnings fire when every recipient has hard dead-address evidence: real bounce proof, not "we haven't heard back yet." Warnings also appear for partial trouble (expired verification, stale reachability, or some but not all unreachable addresses) on the switch page and in health digests, so you see the problem while you can still fix it.
Recovery is automatic where it can be. Share links repair themselves when you fix an email typo. Missing links get re-created when you open the switch, and again in a daily sweep even if you don't. Verified phones show a check. Each switch shows who is verified, who isn't, and whether delivery links are ready.
What is a decision maker for?
You can mark one beneficiary as your decision maker.
If delivery fails hard after a switch fires, they get a fact-only heads-up: something went wrong, and here is how to reach support. They never receive anyone else's files. They never get share links for other people's packages. Just the alert that the plan needs a human.
Support-side contact fixes stay transparent. If a failed address can only be corrected through Killswitch support (Admin Correct contact), it requires evidence the address is actually dead. You and every other beneficiary are notified the moment it happens. Delivery waits 72 hours before proceeding. Support does not quietly rewrite anyone's contact info.
How does reachability differ from encryption?
Killswitch encrypts your documents at rest with AES-256 and moves them under TLS in transit. That is how the vault stays protected.
Verification is a different promise. It is the promise that when a switch fires, the notification has somewhere real to land. Encryption protects the package. Reachability protects the delivery.
Both matter. Only one of them has historically been visible before the day you hope never comes.
What should you do now?
- Open your beneficiaries. Fix any badges from the silent checks.
- Verify the people who would actually receive something.
- Offer quarterly reachability to anyone who wants to stay current. Leave it off for everyone else.
- Name one decision maker for your account, the person who should get a heads-up if a fired delivery fails hard.
- Watch switch health. Treat critical warnings as unblockable work, not optional polish.
You do not need a perfect contact book on day one. You need the places that matter to stop being assumptions.
A switch is a promise to someone you trust. That promise is only as strong as the email and phone that still reach them.
Beneficiary verification is live so you can see that trust, maintain it, and get warned when it drifts, before anything fires.
FAQ
What is beneficiary verification?
A layered check that the contact info for people you named can still receive mail and texts before a switch depends on delivery. It includes silent checks, optional one-click Verify, and optional quarterly reachability.
Do silent checks send email to beneficiaries?
No. Silent checks run when you add or edit a beneficiary. They catch typos, bounce-style evidence, MX hints for mail domains, and phone validity lookups. Problems show as badges. No email goes out.
What happens when someone clicks Verify?
Killswitch sends them a single email that leads with your name, explains Killswitch, and asks for a click. After email confirm, US and Canadian numbers can optionally get a one-time text code. International phone OTP is not available, and the text step is never forced.
Does never-verified tank switch health?
No. Plain never-verified shows a badge as a nudge. Critical warnings fire when every recipient has hard dead-address evidence (real bounce proof). Partial trouble such as expired verification or stale reachability also surfaces as warnings on the switch page and in health digests.
What can a decision maker see?
If delivery fails hard after a switch fires, the decision maker gets a fact-only heads-up and how to reach support. They never receive anyone else's files or share links for other people's packages.
How long does verification last?
Status expires after a year. Answered quarterly reachability checks (opt-in only) keep it fresh automatically.