Email Sign-In Codes
How Forbidden Finance email sign-in codes work: a 6-digit code valid for 5 minutes, always available behind Email me a code instead, and why a code email never contains a sign-in link.
Overview
An email sign-in code is a 6-digit code sent to your email address to finish signing in. It is a full sign-in factor, issued by the same system that checks your passkey and your authenticator app — not a workaround bolted on the side.
Each code is valid for 5 minutes. After that it stops working and you request a new one.
The point of email codes is recovery. Phones get lost, authenticator apps get wiped when you move to a new device, and a passkey lives on hardware you might not have with you. Rather than leave you stuck in a support queue, every account can fall back to a code sent to the address we already have for you.
What a Code Email Looks Like
Knowing exactly what to expect is what makes a fake obvious:
- Subject: "Your Forbidden Finance login code"
- Sender: the same address the rest of our security email comes from — there is nothing new to add to your contacts
- Body: a 6-digit code, and an instruction to type it in
A login code email never contains a sign-in or verification link. There is nothing in it to tap that signs you in — the only way to use a code is to type it into Forbidden Finance yourself. (The standard footer does carry a Privacy Policy link, so the email is not link-free; the point is that no link in it will ever sign you in.)
What the Sign-In Screen Asks For
The second-step screen adapts to what you have enrolled. It asks for the strongest factor you actually hold, and offers email as the alternative.
If you have a passkey only
The screen is titled "Confirm it's you", with the subtitle "Use the passkey saved on this device to finish signing in." and a "Use passkey" button. Below it sits the link "Email me a code instead".
If you have an authenticator app only
The screen is titled "Two-factor authentication", with the subtitle "Enter the code from your authenticator app", a "Verification code" field and a "Verify" button — plus "Email me a code instead".
If you have both a passkey and an authenticator app
The screen is titled "Two-factor authentication", with the subtitle "Enter the code from your authenticator app, or confirm with your passkey." It shows the "Verification code" field with "Verify", a "Use passkey" button, and "Email me a code instead".
If you have neither
The screen is titled "Two-factor authentication" and reads:
We sent a code to j***@403fin.io.
Enter it below to finish signing in.
Your address is masked, so you can confirm which inbox to check without the whole address being on display. Type the code into the "Email verification code" field and tap "Verify". "Send code" and "Resend code" are on the same screen when you need one.
Using the Email Fallback
Start signing in as usual
The second-step screen appears and asks for your strongest enrolled factor.
Tap Email me a code instead
Every account with a passkey or an authenticator app has this link. Tapping it is what sends the code — nothing goes out before that.
Read the masked address
The screen shows where the code went, masked like j***@403fin.io. Check that inbox for "Your Forbidden Finance login code".
Enter the 6 digits
Type the code into the "Email verification code" field and tap "Verify". You have 5 minutes from the moment the code was sent.
Switching back to your usual method
Once you are on the email screen, a link back to your stronger factor appears: "Use passkey instead", "Use authenticator app instead", or "Use passkey or authenticator instead" when you have both enrolled.
Switching back sends nothing and cancels nothing. A code already sitting in your inbox stays valid for its full 5 minutes, so you can change your mind, dig your phone out, change your mind again, and still use the code you were sent.
What This Means for Your Inbox
A code is never emailed automatically to an account that holds a passkey or an authenticator app. It takes that explicit tap on "Email me a code instead", so no code is ever sent to an account with a stronger factor unless a person asks for one.
If a Forbidden Finance login code turns up that you did not ask for, do not enter it, and email [email protected] so we can look at the account with you.
Limits and Lockouts
Code requests are capped at 3 in any 15-minute period. This stops your inbox being flooded by someone hammering the button. Past the cap, the screen says:
We could not send a code right now. Please wait a few minutes and try again.
Wait a few minutes and tap "Send code" again — the cap clears on its own.
Three wrong codes temporarily lock the account. You will see:
Your account has been temporarily locked for your protection. Please try again later, or unlock your account from the mobile app's profile page or by signing in with a passkey.
That message lists your three ways out: wait and try again later, unlock the account from the profile page in the mobile app, or sign in with a passkey if you have one enrolled.
Wherever you are in this flow, the screen carries a support line — "Lost access to your passkey or authenticator? Email [email protected]" if you hold a strong factor, and "Need help signing in? Email [email protected]" if you do not.
Frequently Asked Questions
The code has not arrived. What should I do?
Check your spam or junk folder first, and confirm the masked address on screen is the inbox you are actually looking at. If it still has not arrived, ask for another with "Resend code" — you can request up to 3 codes in any 15-minute period. If you hit that cap, wait a few minutes and try again.
Can I turn the email fallback off?
No. It is the recovery path that stops a lost phone or a wiped authenticator app from becoming a lost account, and it is what keeps you out of a support queue at the worst possible moment. What you can do is make it irrelevant day to day: enroll a passkey or an authenticator app, and that is what you are asked for first — a code is only sent if you tap for one.
Is an emailed code as strong as a passkey?
No, and we would rather say so plainly. A code is a shared secret that travels through your inbox: anyone with access to that inbox can read it, and it can be typed into a convincing fake page. A passkey can do neither — it never leaves your device, and it will not work on a site that is not really ours. Email codes are a recovery path; passkeys remain our recommendation for everyday sign-in.
What happens if I get locked out?
After 3 wrong codes the account locks temporarily and tells you so on screen. Waiting is the simplest fix. You can also unlock the account from the profile page in the mobile app, or sign in with a passkey if you have one enrolled. If none of those get you back in, email [email protected] from the address on the account.
Will a code ever be sent without me asking?
Not to an account with a passkey or an authenticator app enrolled — for those, a code only goes out after you tap "Email me a code instead". If you have no other factor enrolled, email is how you sign in, and the screen tells you the code has been sent and shows the masked address it went to.
I switched back to my passkey. Is the code I was sent now dead?
No. Moving between methods does not invalidate anything. The code you already have stays valid for its full 5 minutes, so you can return to "Email me a code instead" and still use it.
Related Articles
Passkeys
Set up the phishing-resistant method we recommend.Authenticator App (TOTP)
Use a 6-digit code from an authenticator app.Security Overview
How your account and data are protected.Login Problems
Troubleshoot sign-in and two-factor issues.Need more help? Contact us at [email protected].