That corporate discount code you found online may be losing its magic. Marriott has started requiring guests to verify their employment by email before they can book negotiated corporate rates, a shift that closes one of travel's most widely used loopholes.
Guests updating the Marriott app or booking on the website are now hitting a "Corporate Verified Rate" screen. Select a rate like the EY Global Partner Rate and the app asks you to confirm eligibility by verifying an email address. Reports on Reddit's Deloitte forum suggest email verification is spreading. Crucially, the system appears to match your email to a specific organisation — one tester tried an old university address, received a verification code, and unlocked only the university's own discount, not the company rate they were chasing.
This isn't entirely new territory for Marriott's fine print. Corporate rates have always required proof of eligibility at check-in, with hotels allowed to bump unauthorised guests to the standard rate. What's changed is the timing. Instead of an awkward midnight standoff at the front desk over a business card, the check now happens before you book — while you still have time to sort out a problem.
The logic from the hotel side is straightforward. Companies earn discounted rates by delivering extra room nights the hotel would otherwise lose. A code circulating freely online defeats that purpose, letting existing customers pay less for stays they'd have booked anyway.
History shows hotels loosen these rules when they're desperate. During the Great Recession, IHG's friends-and-family rate was effectively open to anyone — a marketing exec shared his authorisation and frequent flyers printed the forms, scoring roughly 40% off flexible rates, sometimes on suites. That arrangement finally ended December 31, 2025. The old IBM PartnerWorld scheme even let partners print IBM logos on business cards, giving them plausible proof at the desk. It was replaced by Partner Plus in 2023.
Email verification isn't airtight either. Contractors often travel on a client's negotiated rate without a client email address. Employees may be entitled to use their company rate on holiday — or not — while carrying the same address on every trip. Government rates can hinge on whether a stay is official business, which an email domain can't prove. Subsidiaries and acquired companies may use different domains entirely. Expect some friction as Marriott's system learns the actual scope of each agreement.
For everyday travellers, the practical takeaway is simple: only book rates you can genuinely demonstrate eligibility for. Marriott already runs this model for its own staff programme, Explore by Marriott Bonvoy, which verifies once and shows a digital badge in the app. Avis introduced similar corporate email checks four years ago. The age of the borrowed code is winding down — and getting caught means paying the rack rate anyway.
Why it matters: business travellers using their own employer's rate should verify ahead of booking rather than discover issues at check-in. Leisure travellers relying on codes from forums or colleagues should budget for standard prices, because the booking flow itself will now catch them.