- How does reset password link work?
- Why do I keep getting password reset emails?
- How long should a password reset link be valid?
How does reset password link work?
The typical password reset link is emailed to the user and contains a unique token that in some manner identifies the user. By clicking the link, the user proves they have access to the email associated to the account, and has now authenticated using a second factor.
Why do I keep getting password reset emails?
If you received a password reset email that you didn't request, don't panic! Sometimes, these requests for password changes can happen when someone is mistyping their domain or username, using the lost password/username tools.
How long should a password reset link be valid?
A good password reset link should last for 1 hour at most, this gives enough time for users with different browsers or devices to be able to access it. However, there are some instances when it may be beneficial to have a link that lasts longer or shorter than an hour.