I kind of wish we could just pass a law that says you have to validate email addresses before attaching them to accounts at all. Because otherwise, competitive pressure will keep pushing people towards not doing it and aiming this gun at their foot in the name of conversions.
In the absence of a law: If your service insists on allowing unverified email addresses, you should store them in a completely different place in your database from verified ones. Maybe even obfuscate them with some encoding. Do whatever you can to make it really hard for anyone to accidentally rely on an unverified address. Ideally make it impossible for anyone except the team in charge of authentication to even see an unverified address.
On another note, holy shit. So many people (myself included) chose Google Domains specifically because they thought it would be secure and trustworthy, because it's Google. Won't make that mistake again.