Password Reset Process: Security Concerns When Only Email Is Required

  • ANTHONY PANTO
    Asked on November 16, 2025 at 7:02 PM

    All a person needs is to have the email and can request to change password. This doesn't seem secure?

  • Profile Image
    Raymond JotForm Support
    Replied on November 17, 2025 at 12:00 AM

    Hi Anthony,

    Thanks for reaching out to Jotform Support. As long as your email is secured and no one has access to it, no one else would be able to reset your Jotform account password. If your concern about account security, you can easily Enable the Two-Factor Authentication to make your account more secure. You'll need to have third-party authenticator apps such as Google Authenticator, Duo, or Authy installed on your phone first. After that, here's how to turn the Two-Factor Authentication on:

    1. On your Workspace page, click on your Profile Image/Avatar in the upper right.

    2. In the menu that shows, click on Settings.

    3. Go to the Security tab on the left side of the screen.

    4. Toggle Two-Factor Authentication to the On position.

    
Password Reset Process: Security Concerns When Only Email Is Required
Image-1

    5. In the menu that pops-up, enter your Jotform password, and then click on Verify.

    
Password Reset Process: Security Concerns When Only Email Is Required
Image-2

    6. Scan the QR code using your authenticator app or enter the code in it. 

    7. In the Enter the Generated Code field, type the 6-digit code generated by your authenticator app.

    8. Then, click on Enable 2FA in the lower right of the pop-up menu.

    
Password Reset Process: Security Concerns When Only Email Is Required
Image-3

    9. Copy the Recovery Codes, or click on Download in the lower right of the pop-up box. 

    10. Finally, click on the X icon in the upper right of the pop-up box to close it.

    
Password Reset Process: Security Concerns When Only Email Is Required
Image-4If you lose access to your authenticator app, you can use your recovery codes to log in to your account — just make sure to keep them safe.

    Let us know if you need any more help.