Free tools Windows power users keep installed
One-click scans. No signup required.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
For SMS phone login, keep a consecutive-failure count tied to the subscriber account and authenticator, and do not reset it when someone requests another code. Set a code lifetime, accept each code only once, and throttle wrong guesses. NIST’s current guidance requires effective throttling for short out-of-band codes, but it does not prescribe one universal retry limit or cooldown schedule.
What NIST requires for SMS one-time codes
NIST SP 800-63B-4, published July 31, 2025, is the current edition of the guideline and supersedes the previous SP 800-63B. It is written for federal digital identity systems; other organizations can use it as a security reference, but its agency-specific language is not automatically a law for every service. NIST’s publication record gives the edition and publication details.
For out-of-band authentication, the verifier generates a random secret, sends it to the user, and waits for the user to return it through the primary channel. The current guideline sets several requirements for this flow:
- Authentication is invalid if it is not completed within 10 minutes.
- The generated secret must contain at least six decimal digits or equivalent.
- A given secret must be accepted only once during its validity period.
- Because these short secrets are below 64 bits, the verifier must effectively limit consecutive failed attempts on the subscriber account.
- Generating a replacement secret must not reset the failed-authentication count.
These requirements are in NIST SP 800-63B-4. Expiration and one-time redemption are distinct controls: a code can be within its validity period and still be unusable if it has already been redeemed.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How many wrong SMS OTP attempts should you allow?
NIST’s general throttling rule sets a ceiling of no more than 100 consecutive failed attempts using a specific authenticator on one subscriber account, unless that authenticator’s specific requirements say otherwise. The standard explicitly says, “The limit of 100 attempts is an upper bound, and agencies MAY impose lower limits.” Treat 100 as a maximum in that guidance, not a recommended setting for a six-digit SMS flow.
The guideline does not choose a universal lower limit for every application. Pick a lower threshold according to the threat model and user-access requirements. The important implementation properties are that attempts are counted consistently, throttling takes effect, and a resend does not give the user or an attacker a fresh set of guesses.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Does NIST specify an SMS OTP cooldown?
No single cooldown or resend timer is prescribed in the cited guidance. NIST says a verifier may use increasing waits as an account approaches its maximum consecutive-failure allowance. Its example describes a wait that grows from “30 seconds up to an hour.” This is an optional technique, not a required schedule or a recommendation that every service use those exact endpoints.
A fixed delay is simpler to explain and implement. A progressive delay can slow repeated guessing while avoiding an immediate hard lockout after a small number of mistakes. Whichever policy you choose, define what triggers the wait, how long it lasts, and what happens when the limit is reached; do not imply that the timer alone prevents phishing, SIM swapping, number takeover, or abuse of the code-sending endpoint.
Rank #3
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Keep resend, expiry, and attempt counting separate
A robust flow gives each control its own rule. This makes it easier to reason about both security and what the user sees:
- Code validity: expire an out-of-band code no later than the applicable 10-minute limit.
- Redemption: accept a code only once during its validity period.
- Failed guesses: count consecutive failures at the subscriber-account/authenticator level and apply effective throttling.
- Resends: define whether a newly generated code supersedes earlier codes, but never clear the failure count just because a new code was generated. NIST states: “Generating a new authentication secret SHALL NOT reset the failed authentication count.”
- Issuance frequency: separately limit repeated requests to send a code. This protects the delivery channel and service from abuse; it does not replace limits on code guesses.
- Recovery: explain the wait and provide a viable recovery or alternate-authenticator route where appropriate.
After a successful authentication, NIST says previous failures for authenticators used should be disregarded and the retry count should be reset, subject to the guideline’s stated assurance-level and session condition. Apply that success behavior deliberately rather than tying resets to resends or unrelated login activity; see the standard’s throttling and reset provisions.
Rank #4
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Reduce guessing without creating an easy lockout attack
A strict lockout can block a legitimate subscriber, and an attacker may deliberately trigger that lockout against someone else. NIST lists optional ways to reduce that risk, including bot detection or mitigation before authentication, increasing waits as failures accumulate, and risk-based signals such as IP address, geolocation, request timing, and browser metadata. These signals can supplement authentication and throttling; they are not themselves an authenticator.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11SMS also has risks that a cooldown cannot solve. NIST classifies PSTN out-of-band authentication as restricted, and SMS is not phishing-resistant. Its guidance recommends considering signals such as device swaps, SIM changes, number porting, or other abnormal behavior before sending a PSTN secret. The NIST FAQ also says agencies must verify that the destination is a phone rather than an IP address such as VoIP, among other applicable requirements. See the NIST Digital Identity Guidelines FAQ for PSTN and SMS clarifications.
Best Value
- NIST Certification: FIPS 140-3 validated for government and regulated organizations (Overall Level 2, Physical Security Level 3).
- Works with 1000+ Accounts: Supported by Google and Microsoft accounts, Identity Access Managers, password managers and 1000+ popular services. It works with operating systems and browsers including Windows, macOS, Chrome OS, Linux, Chrome, and Edge.
- Fast & Convenient Login: Plug in your YubiKey via USB-C and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required.
- Most Secure Passkey: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- Built to Last: Made from tough, waterproof, and crush-resistant materials. Made in Sweden with the highest security standards.
When a service relies on phone access, users should understand that access to both primary and secondary channels is required. NIST’s customer-experience guidance recommends contextual, consistent messages and code-transfer features such as copy and paste. Tell the user why they must wait and when another attempt is available instead of leaving them at an unexplained dead end. The guidance supports clear status messaging; it does not establish a required resend interval. See NIST’s customer-experience considerations.
Quick Recap
Implementation checklist
- Use a random code with at least six decimal digits or equivalent.
- Expire it within the applicable 10-minute validity window and prevent replay.
- Maintain consecutive failed-attempt counts across resends for the same subscriber account and authenticator.
- Choose an application-specific threshold below the applicable NIST upper bound when your risk and usability assessment calls for it.
- Choose a defined delay or progressive-wait policy, and make its effect visible to users.
- Limit code issuance separately from code-entry attempts.
- Offer suitable alternate authentication or recovery, and account for PSTN risks rather than treating SMS as phishing-resistant.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

