How it works

A reset email shouldn't be a surprise you find too late.

Here's exactly what SAFE2RECOVER does between the moment someone hits “forgot password” and the moment anything actually happens.

1

The setup (once)

You change one setting on the accounts you want to protect: their recovery email becomes your SAFE2RECOVER address. Nothing else about how you log in changes.

2

Every day after

A login code arrives → we deliver it instantly and text it to you. A reset or recovery email arrives → we hold it. It never lands in your inbox, and never forwards anywhere.

3

The decision

We text you: “A password reset for your bank just arrived. Was this you?” Approve, snooze, or reject. If it wasn't you, the attacker is left with nothing.

Upgrading buys speed, never safety

The hold-and-approve protection is identical on every plan, including Free. What the paid plans change is how fast things reach you, and how much they cover:

  • Instant text codes: your login codes are texted to your phone the second they arrive, instead of emailed after a short delay.
  • Approvals by text: a held reset alerts your phone as well as your email.
  • Quiet hours and escalation: set when you're reachable and how persistently we should alert you.
  • More protected addresses: 3 on Bronze, 10 on Silver, 30 on Gold.
What an attacker sees: nothing. They trigger the reset, the email vanishes into your gate, and the link expires unused. They never get the one thing they came for.

What stays exactly the same

Your logins. Your passwords. Your apps. Your 2FA codes still reach you, by instant text on paid plans, by email on Free. SAFE2RECOVER only ever steps in for the dangerous mail: the resets and recovery requests that mean someone is trying to get in. See what we can and can't see →

How we handle 2FA email codes

There is an important distinction between a 2FA login code and a recovery email. SAFE2RECOVER treats them completely differently.

2FA codes and OTP emails pass straight through: no hold, no approval step. On paid plans the code is texted to your phone the instant it arrives; on Free it's forwarded by email after a short delay of about five minutes. Either way, logging in never waits on our say-so.

Recovery and reset emails are held. The distinction is what the email is for: a 2FA code proves it's you logging in right now. A password-reset email hands full account access to whoever received it. That is the dangerous mail. Only that class of email: resets, account-recovery requests, security-change confirmations, triggers the checkpoint.

Rule of thumb: if an email lets someone into your account without your password, we hold it. If it helps you log in, it passes through.

The hold

The most dangerous window in an account takeover is the first few minutes. Attackers script the entire sequence: trigger the reset, click the link, change the password, lock you out, in under ninety seconds. The moment you get a notification (if you get one at all) the damage is done.

The hold changes this. When a reset or recovery email arrives, SAFE2RECOVER holds it and sends you an approval request. The email is not released until you say yes, however long that takes. In practice that means:

  • Automated attack scripts that expect instant delivery fail
  • You have time to see the alert and decide, even if it lands at 3am
  • The attacker's reset link is still waiting, useless, when it expires

This works the same on every plan: the mail stays held until you approve it, and an unapproved reset link simply expires unused. The only difference is how the approval request reaches you, by email on Free, by text as well on paid plans.

The email approval workflow

When a held email is waiting, here is exactly what happens:

  1. You get an SMS. We send you a text: the account the email is from, the type of email (password reset, account recovery, security change), and the time it arrived.
  2. Three choices. Reply to approve, snooze, or reject.
    • Approve: the email is released to your inbox. Your reset link arrives and you complete the change you requested.
    • Snooze: the hold window extends. Use this when you need time to think or confirm with someone else.
    • Reject / ignore: the email is discarded. The attacker's reset link never arrives, expires without being clicked, and the account is untouched. No further action needed.

The workflow is designed so that doing nothing is the safe outcome. An attacker who triggers a reset and gets silence, no link, no delivery, no access, has failed. The approval step is only needed when the reset was legitimate.

Alternative lockout attacks: the back door 2FA leaves open

Most account security advice focuses on the front door: use a strong password, enable two-factor authentication. Good advice. But there is a second door that 2FA was never designed to protect: account recovery.

Account recovery exists to let you back in when you're locked out of your main login, forgot your password, lost your phone, can't get your 2FA code. It is deliberately designed to bypass your normal authentication. That's the point. And that is the attack surface.

An alternative lockout attack, sometimes called an account-recovery attack, works like this:

  1. The attacker visits your account's "forgot password" page
  2. They request a reset to your recovery email address
  3. If that recovery email is unguarded, the reset link goes straight to whoever controls the inbox
  4. They click the link, set a new password, and lock you out, all without ever knowing your original password or your 2FA code

This is especially dangerous when someone already has access to your recovery email, an ex-partner, a family member, someone who previously shared your account. They don't need to guess or phish anything. They just click "forgot password."

SAFE2RECOVER closes this gap. Your recovery email is now a checkpoint that does nothing without your approval. The back door that your 2FA couldn't see is locked. Read more about the recovery gap →

Official help and reporting

These are the official Australian services. They are free and they are the ones to trust:

Keep reading

Lock the back door for free.

Two minutes to set up. No card. Your day doesn't change.

Get protected for free