Practical guide · verified against the real thing
Forgot your password? The recovery playbook, done safely
In one line: The order that avoids lockouts and traps: email first, official flows only, and the post-reset cleanup most people skip.
Everyone forgets passwords; the systems exist for exactly this. What turns a five-minute recovery into a bad week is doing the steps in the wrong order, or through the wrong door. This is the safe sequence.
Rule zero: arrive at the door yourself
Never reset through a link in a message you did not request. "Your password was changed, click here to secure your account" is the classic phishing shape — see how to read a link before tapping. Open the service's own site or app and use its Forgot-password flow there. A real reset email, to be clear, is fine to act on — if you requested it. Unsolicited reset emails mean someone else is trying your door; ignore the link and change the password directly instead.
1. Email first, always
Your email address is the recovery key to everything else — every "reset password" flow ends in your inbox. If the forgotten account is your email itself, recover it before touching anything else, and check its recovery settings (phone number, backup address) are current while you are in there. Recovering a bank login is trivial when your email is solid, and impossible when it is not.
2. The reset itself
Use the official flow, prove identity the way the service asks, and choose a new password that is long and not reused anywhere — let a generator do it. Put it straight into your password manager before you close the tab; "I'll write it down later" is where passwords die. If the manager itself is the forgotten account, recover it with its master-password recovery options or its emergency kit — services like Bitwarden document this precisely because it cannot be done socially.
3. The cleanup most people skip
For any account that may have been accessed by someone else — not just forgotten — the reset is step one of three. First: sign out all other sessions (most services have exactly this button in security settings). Second: check for attacker persistence — unknown forward rules in email, unknown linked devices, unknown app passwords, a changed recovery phone. Third: re-enable or refresh two-factor authentication, and regenerate backup codes if there is any chance the old list was seen.
4. Recovery codes are the spare tyre
If you enabled 2FA and have your backup codes, a lost password with a lost phone is still a five-minute recovery: use one code at the 2FA prompt, then regenerate the list (a used code is a spent code) and put the fresh list somewhere that is not the phone doing the approving.
5. When recovery simply fails
The honest limit: with no working email, no recovery codes and no 2FA fallback, some accounts cannot be recovered — and that is the system working, because the same door is open to strangers. Services with account-recovery forms (the big email providers among them) ask questions only the real owner would survive; answer them patiently from a usual device and location. Prevention beats recovery every time this happens: 2FA on the email, current recovery details, and the manager holding the rest.
Next