Check the code first
If your authenticator app still has a Resend entry but the codes are rejected:- Use the entry your authenticator app created when you turned on MFA in Resend.
- Set your phone’s clock to update automatically. A phone clock that is off produces codes that don’t match.
Reset MFA with your recovery code
Your recovery code is the single code Resend showed when you turned on MFA. It has ten characters split by a dash, in the formatXXXXX-XXXXX.
1
Turn off MFA with your recovery code
Using your recovery code turns off MFA and allows you to sign in with your usual method.To use your recovery code, sign in with your usual method and enter your recovery code when Resend asks for your authenticator code. (View help if you do not have a recovery code.)The recovery code works once. Using it also:
If you also lost access to the email address you sign in with, see our
recover access to a team
support article.
- Signs out every other active session on your account.
- Sends an email titled “Your Resend two-factor authentication was reset” to your email address.
2
Turn on MFA again
Enable MFA on again from your Profile with your new device. Resend shows you a new recovery code when you do. Save it before you close the dialog. See how to add MFA for more details.If you receive that email and did not use your recovery code, reset your password and contact support immediately.
MFC recovery code security
Resend shows the recovery code once, when you turn on MFA, and does not show it again. Copy it and store it somewhere other than the device that holds your authenticator app, such as a password manager.What does not remove MFA
- A password reset. After the reset, sign in still asks for the authenticator code.
- Another team member. MFA belongs to each login, not to the team. Another member, including an admin, cannot reset or disable it for you.
If you do not have a recovery code
You can ask support to remove MFA for you.-
Contact support from Help. In your first message, include:
- The email address you sign in with.
- A domain that is already on the account.
- A note if you never turned on MFA yourself, so support can review the account before anything changes.
-
Support will reply with a verification value that is unique to your request. Add it as a DNS record on that domain to prove you own it:
Most DNS providers display this record as
verification.yourdomain.com. The host must be exactlyverification. - Once the record is in place, reply the support conversation and name the domain with the verification record.