A user registers on your forum with a valid e-mail. You set your forum to do e-mail validation. After he validates at a valid address like "bob@aol.com", he somehow changes his e-mail on record to something like "billgates@microsoft.com"?
I know an e-mail change has to be validated as well. However, is it possible a user can trick my forum and get that kind of address in there?