Account security resource

Password Reset Email Template

A reset email should help the account owner complete a requested change without exposing a password or making an unsolicited request look trustworthy.

Plain-text preview

Keep the action and expiry easy to find, and tell the recipient what to do if they did not request a reset.

Subject: Reset your {app_name} password Hello {name}, We received a request to reset the password for your account. Use this secure link before {expiry_date}: {reset_url} If you did not request this change, you can ignore this email. We will not change your password unless the reset is completed. {company_name}

Use case and features

Use this transactional email after a user requests account recovery. It includes a request explanation, one clear action, an expiry placeholder, and reassurance that the password remains unchanged until the recipient completes the flow. A separate confirmation email can be sent after the password is actually changed.

Do not reuse this copy for password-change confirmation or sign-in OTP delivery; those events need different wording and links.

Implementation and limitations

The template is plain text and can be adapted into your email platform's HTML and text alternatives. Generate a high-entropy, single-use token on the server, store it safely, bind it to the account and purpose, enforce expiry, and invalidate it after use. Use HTTPS and avoid putting tokens in analytics, referrer logs, or support screenshots.

This page does not create reset tokens, verify identity, or send email. Rate-limit requests and responses, avoid account-enumeration leaks in the request flow, and test expired, reused, and invalid links.

Customize and use

Replace {app_name}, {name}, {expiry_date}, {reset_url}, and {company_name} from trusted server-side values. Make the expiry text match backend policy. Keep the URL on your verified domain, encode dynamic HTML values, and offer a support route that does not ask the recipient to share their reset link.

Copy the wording into your transactional email provider, then preview it with real test data, a narrow viewport, and images disabled. There is no package to install; use a staging account before production.

Accessibility, license, and preview

Use a descriptive reset-link label in HTML, readable contrast, logical headings, and a plain-text alternative. Avoid making a button image the only path to recovery. This preview shows copy only; check rendering in the email clients your audience uses.

No separate license is displayed for this sample. Review the Terms of Use and any resource-specific terms before reuse or redistribution. The sample is not a compliance or security guarantee.