Use the site's own Forgot password link
A sign-in page with the Forgot password link highlighted
Go to the site directly — type the address yourself rather than clicking a link in an email. Then use its Forgot password link.
Security & Privacy / Security
Get back into a locked account, then set up a password manager and two-factor so it never happens again. Written for people who have never used one.
The 30-second fix
Before anything else, find the account's own Forgot password link and use the email or phone number you signed up with. Do not use a reset link from an email you did not ask for.
If that sorted it, you are done. If not, keep reading — the rest takes about 25 minutes.
You do not need to write passwords on paper, and you do not need to change every password today. Start with email, then bank, then everything else.
There are two separate jobs here and it matters which you do first.
Do them in that order. Recovering an account is urgent; the setup is what stops it recurring.
A sign-in page with the Forgot password link highlighted
Go to the site directly — type the address yourself rather than clicking a link in an email. Then use its Forgot password link.
An inbox showing a password reset email
The reset email should arrive within a minute or two. If it does not, check spam and junk, and search your inbox for the site's name. Reset links expire quickly, so use it the moment it arrives.
A phone showing a six-digit verification code
Most sites now send a code to your phone or email as a second check. Enter it on the site. This is two-factor working as intended — it is what keeps someone else out even if they know your password.
A password field showing a long passphrase
Long beats complicated. Three or four random words strung together — copper-tractor-lantern-nine — is both stronger and easier to remember than P@ssw0rd1.
A password manager app showing a list of saved logins
Install one on your phone and your computer. Bitwarden is free and open-source; 1Password and Dashlane are paid and very polished. Any of them is a huge improvement on a notebook.
The manager remembers every password so you only have to remember one — the master password. Make that one a long passphrase and never reuse it anywhere.
A password manager generating a long random password
From now on, when you sign up somewhere, let the manager generate a long random password. You will never type it. That is the point.
Security settings showing two-step verification enabled
Turn on two-factor for your email first, then your bank, then everything else. Email is the master key to every other account, because that is where password resets go.
Use an authenticator app when offered. Text messages are a decent fallback, not the best choice.
Recovery codes written on a card stored in a drawer
Every account gives you one-time recovery codes when you turn on two-factor. Print them or write them down and put them somewhere physical — a drawer, a safe, a wallet. If you lose your phone, these are the only way back in.
Email first, then bank, then the rest. If you only do one thing today, turn on two-factor for your email account — that single step protects everything else by making sure nobody can reset your other passwords.
If none of that helped, it is usually a hardware or account problem rather than a settings one — and that is exactly the kind of thing worth handing to someone for an hour. Book a session →
If the steps above did not do it, that is what I am here for — remote, flat rate, plain language. You watch everything I do.
Book a session →REMOTE SESSIONS ONLY — ANYWHERE IN THE US — FLAT RATE, UP FRONT
More from the maker of this network.
What two-factor authentication really is · Small tools that respect the person using them