A confirmed sign-in address at the domain is the proof. There is no second code.
If you can sign in with a confirmed address at the product's own domain, that is the proof. Claiming takes one click and there is no second code to wait for.
If you sign in with a personal address instead, there is a DNS route. Either way, this page covers what claiming does and does not get you.
Sign in with your address at the domain, open its listing, and press Claim this listing. We compare the domain of your confirmed sign-in address against the listing's domain, and that is the whole check.
There is no second email because there is nothing a second email would prove. Signing up as someone at a domain you do not control is free; confirming the address is not, and you already did that to sign in.
Plenty of founders sign in with a personal address. Use the DNS route instead: we give you a token, you add it as a TXT record at _appwatch on the domain, and we look it up.
We check the bare domain too, so putting it there works. We ask for _appwatch first because a verification string sitting next to your SPF and DMARC records is the kind of thing somebody deletes while tidying up.
You can send us corrections to your listing, and you can see how it is doing: how often it it turned up in results and how often somebody opened it. Those numbers are approximate, and they leave out bots.
It does not hide the listing, change what we check, or affect where you appear. None of that is for sale.
The ability to edit your listing yourself. You send us a change, a person reads it, and we make it. That is the only reason anyone trusts what AppWatch says: the records are what we saw, not what each company says about itself.
Nobody can set the state directly, including us. See live, dead and unknown.
Tell us. We keep how each claim was proved and when, so this is something we can settle rather than a question of who asked first.