Why reset flows get skipped
- You need a real, reachable inbox. Accounts created with made-up addresses can never receive a reset email.
- Passwords get lost. After a few resets, nobody remembers which password the test account has now.
- The edge cases matter most. Expired links, reused links and resets for addresses that don’t exist are where security bugs live.
How Proxy Mail QA helps
- Create an address, sign up with it, and save the password on the same row (or use Generate password).
- Use Forgot password in your app. The row shows a Reset password button as soon as the email arrives.
- Set a new password, then update the saved one so the next tester knows it.
- Add a note such as “reset twice, MFA off”, so the history of the account travels with it.
What to check in a password reset email
- The email arrives for a registered address, and the app’s response doesn’t reveal whether an address is registered.
- The link expires after the stated time, and works only once.
- Requesting a second reset makes the first link stop working.
- The reset page enforces the same password rules as sign-up.
- Other sessions are signed out after the reset, if that is your policy, and a “your password was changed” email follows.
- The link opens your real site, not
localhost(here’s why that happens).