unauthorised login

  • Unknown's avatar

    My account had a email login that was not me, how can I prevent this

    The blog I need help with is: (visible only to logged in users)

  • Hi there,

    When exactly did you receive this email? The last email login I see on your account was three days ago, at which point the email was also verified for the first time since the account was created.

    There is no way to know who requested a login link to your site, and also no way to prevent login emails from going out. All that’s needed to request a login email is for someone to type your username or email address into the login page, so anyone who knows one of those two details can request it.

    But they won’t be able to access your account unless they also have access to your email account. That is how email login works, and why it’s the most secure way to log into an account. As long as you make sure no one else has access to your email account, no one can access your WordPress.com account either.

    For an extra layer of security you can enable two-step authentication, then even if someone gained access to your email, they won’t be able to log into your account unless they also had your mobile device where you receive the login codes. Add two-step authentication on your email as well, and that’s about as secure as it’s possible to be.

    Enable Two-Step Authentication

  • The topic ‘unauthorised login’ is closed to new replies.