Recommended Free Tools
A self-service password reset is not merely a convenience feature. It is an alternate route into an account, so its proof, delivery channel, rate limits and notifications must be at least as carefully protected as the normal sign-in. The crucial distinction is whether a user is replacing a forgotten password while another authenticator still works, or recovering an account after losing the authenticators required to prove ownership.
Resetting a password is not always “account recovery”
NIST SP 800-63B-4, published in July 2025, separates two operations that product interfaces often combine under a single “Forgot password?” link.
Replacing a forgotten password
If the subscriber can still authenticate with one or more other authenticators, replacing the forgotten password is the binding of a new authenticator, not account recovery. For example, a user who can sign in with a registered passkey or another approved factor may establish a new password after that successful authentication.
Recovering access after authenticators are lost
When the necessary authenticators are unavailable, the service must perform account recovery. That can involve saved or issued recovery codes, a recovery contact, or repeated identity proofing. The method has to match the account’s assurance level; a low-friction email link is not automatically adequate for a high-assurance account.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Why a reset flow can become a security weakness
The recovery proof may be weaker than the account
An attacker does not need to defeat the normal login if the reset route accepts weaker evidence. Public facts, guessed answers, old addresses and similar knowledge-based questions are poor proof of account ownership. NIST’s FAQ explains that self-service reset requires authenticating the account owner and that knowledge-based questions are not acceptable under the cited digital-authentication guidance. NIST also prohibits prompting users to use knowledge-based authentication when choosing passwords.
The delivery channel can be taken over
A code sent by text, voice, email or post is exposed to compromise of that channel. A newly established recovery address must be verified. A recovery process should therefore assess not only whether a code is random, but also who controls the destination and whether that destination is independent of the account being recovered.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
The endpoint can be abused for denial of service
OWASP’s Forgot Password Cheat Sheet warns against locking an account because of forgotten-password activity. Someone who knows a username could repeatedly trigger the flow and prevent the legitimate owner from signing in. Rate-limit code attempts and suspicious requests without turning the reset feature into an attacker-controlled lockout switch.
Recovery itself can be fraudulent
NIST states that “An account recovery event always causes one or more notifications to be sent to the subscriber to help detect the fraudulent use of account recovery.” Notifications should reach the subscriber or a designated contact through a channel that is not silently replaced during the same event.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What NIST requires for recovery at different assurance levels
NIST SP 800-63B-4 recognizes saved recovery codes, issued recovery codes, recovery contacts and repeated identity proofing. A service provider (CSP) must support one or more recognized methods, and an application-specific method—such as interaction with an agent—may be used when supported by documented risk analysis.
| Account situation | Permitted recovery proof described by NIST | Important controls |
|---|---|---|
| Maximum AAL2 account | Two recovery codes obtained by different methods; one recovery code plus authentication with a bound single-factor authenticator; or repeated identity proofing where the account was identity-proofed | Methods must be combined rather than relying on one weak channel |
| AAL3 account identity-proofed at IAL3 | Successful biometric comparison against the biometric collected at attended initial identity proofing | Higher-assurance recovery has stricter identity requirements |
| Account with another working authenticator | Authenticate with that authenticator and bind a replacement password or other authenticator | Treat as authenticator binding, not as a weaker recovery shortcut |
These are requirements within NIST’s CSP framework. They are not universal laws for every product or jurisdiction, but they provide a defensible baseline for designing a recovery policy.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Recovery-code design: randomness is only the beginning
Saved recovery codes
NIST says a saved recovery code must contain at least 64 bits from an approved random bit generator. The subscriber should keep it offline—for example, printed or written down—and stored securely. The CSP stores only a hash, throttles attempts, invalidates a code after it is used and issues a replacement.
Displaying a code once and then leaving it permanently valid defeats those lifecycle controls. A service should also make the remaining-code status clear so users can replace a compromised set before an emergency.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteBest Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Issued recovery codes
Issued codes must contain at least six decimal digits, or an equivalent amount of information, and attempts must be throttled. NIST specifies maximum validity periods by delivery method:
| Delivery method | Maximum validity in NIST SP 800-63B-4 |
|---|---|
| Text or voice | 10 minutes |
| 24 hours | |
| Postal delivery within the contiguous United States | 21 days |
| Postal delivery outside the contiguous United States | 30 days |
Those windows are NIST requirements for its framework, not a blanket rule for every service or country. The service should record issuance, expire unused codes, invalidate them after successful use and notify the subscriber.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Comparing common self-service recovery methods
| Method | Proof strength and independence | Main exposure | Operational safeguards | User impact |
|---|---|---|---|---|
| Working alternate authenticator | Usually strongest because it uses an already bound factor | Depends on that authenticator remaining under the user’s control | Require normal authentication, log the binding event and notify the subscriber | Fast and familiar |
| Saved recovery code | Can be strong when generated with sufficient randomness and kept offline | Loss, theft or insecure storage by the subscriber | Hash at the CSP, throttle, invalidate after use and issue a replacement | Immediate if stored safely; otherwise recovery may be delayed |
| Issued code by text or voice | Proof is tied to control of the phone channel | Number takeover, interception or compromised voicemail | Six-digit minimum, throttling, 10-minute maximum validity and notification | Convenient, but dependent on mobile access |
| Issued code by email | Proof is tied to control of the mailbox | Compromised email account or replaced recovery address | Verify a new address, throttle and limit validity to 24 hours | Accessible when the mailbox works; slower if it does not |
| Postal code | Depends on control of the physical delivery address | Mail interception and long delivery time | Apply the applicable 21- or 30-day maximum and notify the subscriber | Slow, but does not require a working online channel |
| Knowledge-based questions | Weak and often discoverable; not accepted as the cited NIST reset proof | Public records, social engineering and guessing | Do not use as the sole reset proof | Easy to answer but unsafe |
| Human-assisted recovery | Varies with the agent’s procedure and evidence | Social engineering and inconsistent decisions | Document the risk analysis, require strong records and notify the subscriber | Can help users without other channels, but may take longer |
Designing a safer reset journey
- Classify the event. Determine whether a working authenticator is available. If it is, use authenticated binding of a replacement authenticator. If not, invoke the account-recovery policy.
- Match proof to assurance. Identify the account’s AAL and any identity-proofing level before selecting a recovery method. Do not let a low-assurance channel silently downgrade a higher-assurance account.
- Prefer independent evidence. For maximum AAL2 recovery, combine two codes from different methods, a code with a bound single-factor authenticator, or repeated identity proofing where available.
- Protect every code. Generate codes with approved randomness, store saved-code hashes rather than plaintext, throttle guesses, enforce expiry for issued codes and invalidate a code after use.
- Verify recovery destinations. Require verification before accepting a newly established recovery address or contact.
- Prevent reset-triggered lockouts. Apply request and attempt throttles, anomaly detection and notification instead of locking the account merely because someone initiated a forgotten-password flow.
- Notify after recovery. Send a clear event notice to the subscriber or designee, including what changed and how to report fraud.
- Record and review. Log issuance, delivery, successful use, failed attempts, replacement of codes and changes to recovery contacts. Review unusual patterns without exposing sensitive code values.
What users should do before they need recovery
- Keep recovery codes offline and secure; do not leave them in an unprotected note or shared mailbox.
- Maintain more than one approved authenticator where the service supports it.
- Verify that recovery email addresses and phone numbers are current, controlled by you and protected with their own strong authentication.
- Read recovery notifications promptly. A notice for an event you did not initiate is a reason to use the service’s fraud or support channel immediately.
- Use unique passwords, but do not treat a password manager or a memorable answer as a substitute for an account’s required recovery assurance.
Questions a security team should ask before enabling self-service reset
- What exact evidence proves ownership, and is it independent of the account being recovered?
- Can an attacker who knows only a username trigger a lockout or consume the user’s recovery options?
- How are codes generated, stored, throttled, expired and invalidated?
- What happens when a recovery address, phone number or contact is changed?
- Does the recovery path preserve the account’s AAL, or quietly lower it?
- Which notifications are sent, to which destinations and at what point in the event?
- How does an agent handle ambiguous cases without making social engineering the easiest route?
The Bottom Line
Self-service reset is safe only when it is treated as a security-sensitive authenticator-binding or recovery operation. Eliminate knowledge questions, preserve the account’s assurance level, control code lifecycles, resist denial-of-service abuse and notify the subscriber every time recovery succeeds.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

