Pocket Option Forgot Password and Reset Flow
Starting a Password Reset
Open the login screen from your own saved bookmark, choose the forgot-password link, enter the email address the account was registered with, and wait for the message that carries your reset link.
A password reset that emails a link to the address on file is the standard mechanism across this product category, and it is what you should expect here. The important part is not the mechanics, which are simple, but where you start from. Begin at the login screen you reach through a bookmark you saved yourself, from the address where you originally registered. Two operator-run addresses were verified against their public pages on 31 July 2026: pocketoption.com, with its login at pocketoption.com/en/login/, and po.trade, with its login at po.trade/en/login/. A reset link that arrives after you clicked a login link from an ad, a search result or a chat message is a reset you cannot vouch for.
Finding the forgot-password link
The link sits next to or below the password field on the sign-in form, and it is the only route you need. Here is the whole sequence, in order:
- Open your saved bookmark for the login page rather than searching for it.
- Check the address bar character by character before you type anything at all.
- Select the forgot-password link on the sign-in form.
- Enter the email address the account was opened with, not the one you use today if they differ.
- Submit the form and leave that tab open while you go to your mailbox.
- Open the reset message, follow its link, and set a new password on the page it opens.
- Return to the login screen and sign in with the new password to confirm it took.
If the form returns a generic message rather than telling you whether the address exists, that is normal behaviour and not a fault. Platforms deliberately avoid confirming which addresses have accounts, because doing so would hand a list to anyone probing.
Entering the right account email
People change mailboxes. They move from a work address to a personal one, abandon a university account, or open the account with a social sign-in and never think about email again. The address that matters is the one attached to the account, and it is the single most common thing readers get wrong at this step. If you registered through a social provider rather than with a password, there may be no password to reset at all, and the entry route is your provider account instead. Our page on the different ways into an account walks through what changes when an identity provider stands between you and the platform.
What the reset message should look like
Expect a short message with a single link, sent from the operator rather than from a person, and phrased without pressure. What it should never contain is a request for your current password, a code you are asked to read back to somebody, or a phone number to call for help completing the reset. Those are the shapes phishing takes around recovery, because a lockout is exactly the moment a reader is anxious and quick to comply. If two reset messages arrive and you only asked for one, treat the extra one as suspect and start again from your bookmark.
Start every reset from your own bookmark and the account's original email address, because those two choices remove most of what goes wrong later.
Completing the Reset Safely
Set a long, unique password you have not used anywhere else, store it somewhere you will find it again, then sign in once to confirm the change took effect before you close the tab.
The reset page is where you make a decision that either ends this problem or repeats it in six months. Length beats complexity: a long passphrase of unrelated words is harder to attack and easier to type on a phone than a short string of symbols you will forget by Thursday. Whatever you choose, it needs to exist in exactly one place on the internet, which is this account.
Choosing a password you can actually keep
Aim for something long, unique and boring. Three or four unrelated words with a number or separator does the job. Skip anything a stranger could guess from your public life: a birth year, a pet, a football club, the platform name with a digit stuck on the end. If a strength meter appears on the page, treat it as a rough hint rather than a verdict, because meters reward symbols more than they reward length.
Why reusing a password quietly costs you
A reused password is only as strong as the weakest site you ever typed it into. When some unrelated forum leaks its user table, attackers try the same address and password combination everywhere else, and a trading account is high on the list they try first. This is also why a reset you did not ask for deserves attention: it can mean somebody already has your address and is probing. If that is your situation, treat the reset as urgent and review the basic security settings on the account before you go any further.
Confirming the change actually took
Do not close the tab on a confirmation screen and assume you are finished. Sign in once with the new password, on the same surface you normally use. Two useful things follow from that. First, you learn immediately if the reset failed silently, which is rarer but much more annoying to discover a week later. Second, changing a password invalidates other signed-in sessions on essentially every platform of this kind, so anyone else who was signed in on another device gets pushed out. That is the practical way to end a session you cannot see. If you had a second factor switched on, expect to be asked for it again on your next sign-in, and check that your authenticator still produces accepted codes. A phone clock that has drifted will produce codes that look right and fail anyway, because time-based codes rotate on a roughly thirty-second clock shared between your app and the server.
Once you are back in, do the boring housekeeping while you are thinking about it: confirm the address on the account is one you still control, and update it if it is not. The page on changing your login details covers what to check.
A long, unique password plus one confirming sign-in turns a reset from a temporary patch into a fix that holds.
When the Reset Email Never Arrives
Check spam and promotions first, then confirm the address you typed matches the one on the account, then give delivery a little time before requesting another link. Most missing resets are one of those three.
Nothing in the inbox is the most common way a reset stalls, and it almost never means the platform ignored you. Automated mail gets filtered, delayed or delivered somewhere you were not looking. Work the causes in order rather than hammering the resend button, because repeated requests can invalidate earlier links and leave you chasing a message that no longer works.
Filters, promotions tabs and quarantines
Search your whole mailbox for the brand name rather than scrolling the inbox, and include spam, junk, promotions, updates and any archive folder. On a work or school address there may be a server-side quarantine you never see in the client at all, which your administrator controls. Some providers also silently route mail from financial and trading senders into a low-priority bucket. Once you find the message, mark it as not spam so the next one lands where you expect.
A wrong, mistyped or abandoned address
Look hard at the address itself. A single transposed character at registration is invisible for years, because you never need to receive mail to sign in with a password you remember. The same applies to a domain that has since changed hands or a mailbox your old employer switched off. If the address on the account is one you no longer control, no amount of resending will help, and the route forward is the one described in the next section.
Time, resends and knowing when to stop
Give delivery a few minutes before you assume failure. Requesting a new link repeatedly is the classic way readers create a second problem: repeated attempts on a login or reset form can trigger temporary rate limiting, which looks like a block and adds waiting to a problem that was only about mail delivery. Ask once, wait, check thoroughly, then ask again. Here is how the usual symptoms sort out:
| What you see | Likely cause | What to do |
|---|---|---|
| Form accepted, nothing in the inbox | Filtering into spam, promotions or a quarantine | Search the whole mailbox for the brand name, check every folder, then mark as not spam |
| Nothing anywhere, even after a full search | The address on the account is not the one you entered | Try older addresses you have owned, in order of when you might have registered |
| Link opens but says it is no longer valid | A newer request replaced it, or the link was already used | Request one more link and use the most recent message only |
| Form now refuses further requests | Temporary rate limiting after repeated attempts | Stop, wait, and try again later from the same bookmark |
| Sign-in still fails with the new password | Cached credentials, autofill, or a second factor prompt you missed | Type the password by hand once and work through the common login errors |
One more thing worth ruling out: a VPN or a filtering network can interfere with reaching the login page in the first place, so a page that will not load is a connection question rather than a password question. Fix the connection on your own network before you conclude the account is at fault.
Search the whole mailbox before you resend, because a second request can quietly invalidate the link already sitting in your promotions tab.
Resetting Without Email Access
If you cannot open the registered mailbox, recover the mailbox first with its own provider. That is the prerequisite, not an alternative. Only then does the platform reset flow have anywhere to send your link.
This is the hardest version of the problem, and it is worth being honest about the order of operations. A password reset delivers to an address. If that address is dead, the reset has nowhere to land, and no amount of contact with the trading platform changes that. So the mailbox is the first thing to fix.
Recover the mailbox before anything else
Go to your email provider and use its own account recovery: recovery phone, backup address, security questions, or whatever it offers. Providers keep these routes precisely for this situation, and a mailbox you recover is a mailbox that can then receive every future reset, not just this one. If the address belonged to an employer or a school and the organisation deleted it, treat it as permanently gone and move to the support route below. Do not create a new mailbox at the same address on a different provider and expect it to inherit anything.
Contacting support through the official route
When the mailbox is unrecoverable, the official support route is the only path left. Reach it from inside a signed-in account if you have another surface still signed in, or from the operator's own site, never from a phone number, chat handle or link that arrived in a message, an ad or a search result. Live chat, email or a ticket, and in-app help are the advertised categories. What you can usefully bring is evidence you are the account holder: the address used at registration even though you cannot open it, the approximate registration period, the sign-in method you used, and details of your own activity that only the account holder would know.
Set your expectations sensibly. Interface language is not staffing, response times are not published, and a case that turns on identity takes longer than a case that turns on a delivery failure. Keep a written record of every exchange, with dates. If your account is also showing a restriction notice rather than a plain password failure, the situation is a different one, and the page on login blocks explains why those need reading carefully before you act.
If identity checks are requested
Identity verification with photo ID, proof of address and proof of the payment method is the standard pattern in this product category, and a recovery case is a plausible moment for it. Where it comes up, the rule runs one way only: if the details on your account do not match your documents, you correct the account record so it matches the legal documents. You never adjust a document to match the account. A document that misstates identity or residence is fraud, and it will end the account rather than recover it. Send documents only through the official support channel you reached yourself, and remember that a genuine identity check never involves reading out a code, sharing a password, or letting anybody watch your screen. Anyone offering to recover the account for you, for a fee or otherwise, is not a recovery route.
The mailbox comes first, support comes second, and no third party belongs anywhere in the sequence.
Preventing Future Lockouts
Store the new password in a password manager, keep the address on the account one you actively control, and add a second factor with its backup codes written down offline.
You have just spent an afternoon on something that takes ten minutes to prevent. Three habits close the loop, and none of them need any product feature to be confirmed: they are all things you control on your own devices.
Let a password manager do the remembering
A password manager gives you a long unique password per site without the memory burden, and it defends against phishing in a way willpower does not: it fills credentials only on the address it saved them for. If a lookalike page asks you to sign in, the manager stays silent, and that silence is a warning worth listening to. Your browser or phone probably has one built in already. Whatever you use, protect it with a strong master password and a second factor of its own, because it is now the key to everything. Write the master password on paper and keep it somewhere physical rather than in a note on the same device.
Keep the recovery address current
The address on the account is your entire recovery path. Diary a check once or twice a year: open the mailbox, confirm you can still receive mail there, and update the account if you have moved on. Avoid tying a trading account to an address controlled by an employer or a school, since you lose it the day you leave. If you change providers, change the account address first and confirm the change lands before you close the old mailbox.
Add a second factor once you are back in
Two-factor authentication as a category is standard for this product category: authenticator app codes, emailed or texted codes, and backup codes. Where the option appears in your account settings, switching it on means a leaked password alone no longer opens the door. Three practical points about living with it:
- Codes from an authenticator app rotate on a roughly thirty-second clock, so set your phone to network time or codes will be rejected for no visible reason.
- Backup codes go somewhere offline, on paper or in your password manager, and never into a chat, an email reply or a support form.
- Changing your phone is the moment 2FA bites, so move or re-enrol your authenticator before you wipe the old device, not after.
Our page on signing in with 2FA covers how each factor type behaves in practice. One last piece of context worth carrying: this platform deals in fixed-time and digital options, which are high-risk, short-horizon speculation where capital can be lost in full and quickly, and most retail accounts in this product category lose money. No mainstream financial regulator authorisation is disclosed on the operator's public pages, and two public records point the other way: an FCA warning that the firm is not authorised to provide, promote or offer financial services or products in the UK, last updated February 2026, and a CFTC RED List entry recording it among foreign entities that appear to solicit US residents without registration. Account access is worth protecting properly, and it is also worth knowing what you are protecting access to.
A password manager, a live recovery address and offline backup codes together make the next lockout a non-event.
Questions readers keep asking
How long does a Pocket Option password reset link stay valid?
No expiry window is published on the operator's own pages, so treat the link as short-lived and use it as soon as it arrives. If it has stopped working, request a fresh one and use only the newest message, since a later request generally replaces the earlier link.
I never received the reset email. What should I check first?
Search your whole mailbox for the brand name, including spam, junk, promotions, updates and archive, and check any server-side quarantine on a work or school address. If nothing appears anywhere, the address you entered is probably not the one on the account. Try older addresses before requesting more links.
Can I reset my password if I no longer have the registered email?
Recover the mailbox with its own provider first, because a reset has nowhere to land without it. If the mailbox is permanently gone, contact the official support route from the operator's own site and bring what identifies you as the account holder. Nobody outside that route can recover an account for you.
Support asked for my password to help me reset it. Is that normal?
No, and it is the clearest signal you are not talking to support. Nobody legitimate ever needs your password, a one-time code, a 2FA code, a backup code or remote access to your screen. Stop the conversation, and reach support only from the operator's own site or from inside a signed-in account.
Does changing my password sign me out on my other devices?
On essentially every platform of this kind, yes, and that is exactly why a password change is the practical way to end a session you cannot see. Expect to sign in again everywhere, and to be asked for your second factor again if you have one enabled.
The reset worked but I still cannot sign in. What now?
Type the new password by hand once, since saved autofill often replays the old one. Then check for a second-factor prompt, an on-screen notice about a restriction, and your device clock if you use an authenticator app. If the page itself will not load, treat it as a connection problem on your own network first.