Auto re-pair HubSpot contact when linked Salesforce email is invalid

We have duplicate Salesforce Contacts representing the same person that we cannot always merge, usually because they sit on different Accounts for legitimate business reasons. Salesforce selective sync is not really feasible for us either, as our HubSpot integration user setup cannot reliably exclude only the unwanted duplicate Contact.

To stop HubSpot syncing with the wrong duplicate, we often invalidate the email on that Salesforce Contact, while keeping another Salesforce Contact with the original valid email.

However, once HubSpot is already paired to the old Salesforce Contact ID, it often keeps trying to sync to that record and throws “Invalid email requested for portalId…” errors, instead of re-pairing to another Salesforce Contact with the valid email. This is especially confusing because HubSpot does seem able to re-pair on its own in some scenarios, so it is not clear when the “most recently updated Salesforce record” behaviour applies and when the existing Salesforce Contact ID pairing takes precedence.

We had to ask HubSpot Support to temporarily unlock the read-only Salesforce Contact ID property so we could clear it and let HubSpot re-pair. That worked, but it is not a sustainable process.

Could HubSpot either automatically re-search Salesforce and re-pair to another valid matching Contact/Lead when the linked record fails email validation, or provide an admin/API-supported way to clear or re-pair the Salesforce Contact ID?