# Sign-in and account security

> How signing in to Emailit works, from emailed one-time codes to passkeys, plus how to reset your password, change your email and keep your account safe.

This page covers how you sign in to the dashboard, what to do when you forget your password, and how to change your email, password and name. It applies to your personal account, not to API keys.

## How sign-in works

Every password sign-in needs a second step. Which one depends on your setup:

| Your setup | Step 1 | Step 2 |
| --- | --- | --- |
| Default | Email and password | A 6-digit code emailed to you, every time |
| Authenticator app enabled | Email and password | A code from your authenticator app, or a recovery code. No email code is sent. |
| Passkey | Choose the passkey | None. The passkey signs you in on its own. |

1. **Enter your credentials.** Go to [dash.emailit.com/login](https://dash.emailit.com/login) and enter your email address and password, then select **Sign in**.

2. **Enter the second factor.** If you use emailed codes, check your inbox for "Your Emailit sign-in code" and enter the 6 digits on **Check your email**. The code expires after 15 minutes. Select **Resend code** to get a new one. If you set up an authenticator app, enter its 6-digit code instead, or select **Use recovery code**.

To sign in with a passkey, select **Sign in with a passkey**, or pick your passkey from your browser's autofill suggestions in the email field.

After 5 wrong codes, sign-in is locked for 15 minutes and you see "Too many attempts. Please try again later."

> **Didn't try to sign in?:** If you get a sign-in code you didn't request, someone has your password. [Reset your password](#reset-your-password) right away and turn on [two-factor authentication](/docs/account/two-factor-and-passkeys/).

## Reset your password

1. **Request a link.** On the sign-in page, select **Forgot your password?**, enter your account email and select **Email reset password link**.

2. **Open the email.** Look for "Reset your Emailit password". For privacy, the page says a link was sent even if no account uses that address.

3. **Choose a new password.** Select **Reset password** in the email and set a new password of at least 8 characters. The link expires after 60 minutes and works once.

Requesting a new link cancels any earlier one. A password reset doesn't turn off your authenticator app, so you still need it at the next sign-in.

## Change your email address

1. **Open your account.** In the account menu at the bottom of the sidebar, select **Account**.

2. **Enter the new address.** Under **Change email**, type the **New email** and select **Send verification code**.

3. **Confirm the code.** Enter the 6-digit code sent to the new address and select **Confirm email**. Your sign-in email doesn't change until you confirm.

You can't switch to an address that another Emailit account already uses. Changing your account email doesn't change the billing email of any workspace. Update that in [Invoices and billing details](/docs/billing/invoices/).

Pending workspace invitations are tied to the address they were sent to, so accept them before you change your email, or ask for a new invitation.

## Change your password

Under **Change password**, enter your **Current password**, a **New password** of at least 8 characters, and **Confirm new password**, then select **Change password**.

## Rename your account

Under **Rename**, edit **Name** and select **Rename**. Emailit uses this name when it emails you.

## Delete your account

Account deletion isn't self-service. Email [support@emailit.com](mailto:support@emailit.com) from the address on your account. If you own workspaces, tell us what should happen to them. To delete stored email data, see [Data retention](/docs/data-retention/).

## Security recommendations

- **Turn on an authenticator app or add a passkey.** Both stop someone with only your password from reading your sign-in code in a compromised inbox. See [Two-factor authentication and passkeys](/docs/account/two-factor-and-passkeys/).
- **Use a unique password.** Use a password manager and don't reuse your email password.
- **Store recovery codes offline.** They're your way back in if you lose your phone.
- **Give teammates their own accounts.** Invite each person to the workspace instead of sharing a login. See [Members and roles](/docs/workspaces/members-and-roles/).
- **Use scoped API keys for code.** Apps and agents should use a sending-only key restricted to one domain, never your dashboard login. See [API keys](/docs/developers/api-keys/).
- **Remove people who leave.** An admin can remove a member under **Workspace → Settings → Members**.

## Related

- [Two-factor authentication and passkeys](/docs/account/two-factor-and-passkeys/)
- [Notification emails](/docs/account/notification-emails/)
- [Security and compliance](/docs/security/)

---
Source: https://emailit.com/docs/account/sign-in-and-security/
