GitHub documentation mentions emails may not be verified and that this data is provided during API calls.
We will have to update how OAuth works to grab this info from a respective provider and use that to determine if a user is verified, never assuming that just because an email is grabbed from OAuth signup that the user is automatically verified.