You cannot recover a password you have forgotten — you can only reset it

No company stores your actual password in a way that lets them send it back to you. If they could read it, hackers could too. Instead, services store a mathematical fingerprint of your password. When you forget it, you do not retrieve the old one — you create a new one through a reset link or recovery process.

The difference matters because it changes what you need to do right now. You will need access to either the email address or phone number attached to your account. If you have lost access to both, the process is longer and may require you to prove your identity in other ways.

Key Takeaways

  • Password recovery always means creating a new password, not retrieving your old one, because companies cannot read passwords they have stored securely.
  • You will need access to the email address or phone number linked to your account to receive a reset link or code.
  • If you have lost access to both your email and phone, contact the service's support team with proof of identity — this takes longer but is still possible.
  • Write down new passwords in a physical notebook or use a password manager so you do not lose access again.
  • Two-factor authentication makes your account harder to break into, but it also means you need backup recovery codes saved somewhere safe.

Reset your password using your email address

On the login page of any service, look for a link that says "Forgot password," "Reset password," or "Can't sign in." Click it. You will be asked to enter the email address associated with your account.

The service sends a reset link to that email inbox. Open the email, click the link, and you will be taken to a page where you create a new password. Make it something you have not used before and something you can remember — or write it down somewhere safe, like a physical notebook kept in your home.

The reset link usually works for a limited time, often 24 hours. If you wait too long, you may need to start over and request a new link.

Reset your password using your phone number

Some services let you reset using a phone number instead of email. On the "Forgot password" page, select the option to receive a code by text message or phone call instead of email.

You will receive a code — usually four to eight digits — by text or voice call. Enter that code on the reset page, then create your new password. This works the same way as email reset, but it is faster because you do not have to open another app to check your inbox.

If you no longer have access to that phone number — because you changed carriers, lost the phone, or the number was reassigned — you will need to use the email recovery method instead, or contact support.

What to do if you cannot access your email or phone

If you have lost access to both the email and phone number on file, you cannot complete an automated reset. Instead, contact the service's support team directly. Look for a "Contact us" or "Support" link on the login page or the company's website.

Be ready to prove you own the account. Support will ask for information like the last four digits of a credit card you used, the date you created the account, or answers to security questions you set up. Some services ask you to take a photo of your ID. The process usually takes a few days to a week.

This is why keeping a recovery email and phone number current matters: it is the fastest way back in if you forget your password.

Use a password manager to avoid this in the future

A password manager is software that stores all your passwords in one locked vault. You remember only one master password — the one that opens the vault. When you need to log in somewhere, the manager fills in your username and password for you.

Popular password managers include Bitwarden (free), 1Password, Dashlane, and LastPass. They work on phones, tablets, and computers. If you forget a password stored in the manager, you can look it up without going through a reset process.

The trade-off is that if you forget your master password, you lose access to everything inside. Most managers let you set up a recovery email so you can regain access to the vault itself, but not to the individual passwords inside it. Write down your master password or store it somewhere very safe.

Set up recovery codes if you use two-factor authentication

Two-factor authentication (often called 2FA) adds a second step to login: after you enter your password, you must also enter a code from your phone or an authenticator app. It makes your account much harder to break into, but it also means you can get locked out in more ways.

When you turn on two-factor authentication, the service gives you a set of recovery codes — usually 8 to 10 one-time codes you can use if you lose access to your phone or authenticator app. Write these down on paper and store them somewhere safe, like a drawer in your home. Do not store them in a note on your phone or in an email — if you lose your phone, you need these codes to be somewhere else.

If you lose both your password and your two-factor method, you will need those recovery codes or you will have to contact support and prove your identity.

What to do if someone else knows your password

If you think someone else has your password — because they told you, or because you used it on a website that was hacked — change it when ready, even if you remember it. Do not wait until you are locked out.

Go to the login page, enter your current password, and look for a "Change password" or "Security settings" option. You will be asked to enter your current password once more, then create a new one. Make it different from any password you have used before.

If the account has been hacked and the attacker has changed your password or added a recovery email, you may not be able to change it yourself. In that case, use the "Forgot password" process to regain control, or contact support when ready.

Frequently Asked Questions

Can a company send me my old password if I ask them to?

No. If a company could read your password, it would mean their security is broken and hackers could read it too. Any company that offers to send you your old password is not storing passwords safely and you should stop using that service. Legitimate companies only offer password reset, not password recovery.

How long does a password reset link stay active?

Usually 24 hours, but it varies by service. Some links expire after one hour, others after several days. If your reset link has expired, go back to the "Forgot password" page and request a new one. It will arrive within minutes.

What if I reset my password but still cannot log in?

Make sure you are typing the new password correctly — passwords are case-sensitive, meaning capital letters matter. If you are still locked out, try the reset process again. If that does not work, contact the service's support team and describe what happened.

Is it safe to write down my passwords?

Writing passwords on paper and storing them in your home is safer than reusing the same password everywhere or storing them in an email. The risk is low if only you have access to that notebook. A password manager is safer because it encrypts your passwords, but a written list in a locked drawer is better than no backup at all.

What should I do if I get locked out of my password manager?

Most password managers let you set a recovery email when you sign up. Use that email to regain access to the manager itself. Once you are back in, you can see all your stored passwords. If you did not set up a recovery email, contact the manager's support team — they can verify your identity and help you regain access.