Overview
Resetting a password
- Refresh or reset the login screen if the browser retains old login values.
- Select the password-reset link from the email sent to the registered account or OTP email address.
- The system sends another email containing the username and password. One report states that the system generates a new password and sends it to the registered email address.
Receiving one-time passwords
- OTP delivery is reported differently: most information identifies email as the delivery method, while another report identifies the registered phone number.
- The OTP email address is the same as the contact email address.
- During login, the system sends a six-digit OTP to the user's email.
Updating the OTP contact information
- After a new email address is changed and saved, OTPs are sent to the new email address.
- After a new phone number is entered and saved, the system sends an OTP to that new number.
Accessing and editing the system
- The system can be accessed and edited through Microsoft Edge.
Identifying the login username
- A domain name is generally used as the username for account access.
- If a password-reset attempt fails, the username may contain extra characters or information at the beginning.
Interpreting the location shown for a login
- The displayed login location is determined by the IP address in use and may not be accurate.
Verifying identity
- The identity-verification system asks the user to confirm their birth year in the Buddhist Era calendar.
Escalating a computer login problem
- The support team may need to receive the issue for investigation and coordination.
- For a computer login problem, the agent may request the laptop's brand and model.
- A call center is available 24 hours a day for customers who need assistance.
How To
Resetting a forgotten password
- Open the website login page and select Forgot password or Reset password.
- Enter the account username. This may be the registered email address; for an internationalized domain username, enter its
xn--prefixed form carefully. Alternatively, copy the domain name into a text editor, remove unwanted information at the beginning, and use the cleaned value. - Submit the reset request. Some reset flows request the username or email address again on the next page before selecting Reset Password.
- Check the registered email account for the password-reset message. If it is not in the inbox, check the other or junk-mail folder.
- Open the password-reset link or button in the email. If the email provides a generated password, use that password to log in.
- If prompted, enter the new password twice and select the option to update the account information. In flows that provide a generated password, change it after logging in to a password of your choice.
- Return to the login page and sign in with the new password. Enter the one-time password when prompted; one reported flow uses a six-digit OTP received by email.
If self-service reset does not work, try a different browser. If it remains unsuccessful, contact support from the domain owner's email and request a verification code to change the password. A support agent may also initiate the reset; wait for the reset email after the agent does so.
Changing the phone number used for OTPs
- Log in to the account and go to the home page or profile page.
- Open the profile icon or menu in the upper-right corner.
- Select Account and Security Settings.
- In the phone-number field used for OTPs, select the pencil or Edit icon.
- Complete the OTP verification. Depending on the flow, enter the OTP sent to the old phone, enter an additional OTP requested after selecting the edit option, or request an OTP before the change.
- Enter the new phone number.
- Enter the OTP sent to the new phone, if requested, and select Save to submit the change.
- Log in again to check whether the phone number was updated.
In one administrator flow, the administrator logs in to the customer's business using the administrator's own account, opens the administrator's Account page, selects the option to change the customer's OTP phone number, verifies with an OTP sent to the administrator's phone, enters the customer's new phone number, and completes the second verification with an OTP sent to the customer's new phone.
If the old phone cannot receive the OTP or the back office cannot be accessed, send a request from the website owner's email to the published support email. Identify the website and provide the new phone number. Support will investigate or change the phone number after receiving the request. The customer may instead provide additional contact information for a callback; the relevant support team will investigate and contact the customer with an update.
Changing the email address used for OTPs
- Log in to the website account.
- Open Settings or General Settings.
- Open the Account section.
- Enter the new address in the customer email or OTP-receiving email field.
- Save the new address.
An alternative path is to return to the main dashboard, open the website system, select Home, open Profile, select Edit Profile, open Account and Security, and change the User Email field. Another reported path is Member > Member Information, followed by entering the new email address and selecting OK. After changing the email address through Member Information, contact support again so the email address can be updated.
Completing account login with OTP verification
- Open the website and select the login menu.
- Choose the first login option when the login page presents multiple options.
- Enter the website name or username as requested.
- Enter the existing password.
- Check the registered email account or phone for the OTP.
- Enter the OTP to complete login.
If an OTP is no longer available, request a new OTP. A mobile OTP may be delayed depending on the mobile network. To test whether SMS delivery is working, log in to the OTP system again and check whether it sends an SMS as before.
Troubleshooting failed login or missing OTP
- Close the login tab and reopen the website.
- If a login OTP does not arrive, the agent can log out of the backend system. Clear the device cache, then try logging in again.
- In Google Chrome, open the three-dot menu, select a new incognito window, enter the existing password, and try logging in there.
- Refresh the browser page with Ctrl+F5.
- Open a new browser tab and try logging in again. If that fails, try accessing the account from a computer.
- Try a different browser if login or password reset does not work.
Resolving a blocked password-confirmation link
- Before opening the link in the email, copy its URL.
- Send the copied URL to support through the published support messaging channel.
- If the link opens to a blocked page, capture a screenshot that includes the green Show button near the bottom of the page.
Support may remotely access the customer's device to copy the URL if the customer prefers. Social-support staff can receive the issue through the messaging channel and pass it to another staff member.
Granting support access to the backend or email-sending system
- Support sends an access or authorization request by email when it needs to enter the backend or the email-sending system.
- The customer must open the emailed request and select Accept.
Requesting cancellation of OTP verification
- Send the cancellation request from the account owner's email to the published support email.
- Include the name of the website being used.
- Include details explaining the request.
Before OTP is disabled, support may explain the security implications by email or during a call.
Checking an account record
Support can check the customer's record using the email address used for access or the owner's email address.
Joining an invitation
- If the invitation is not in the inbox, check the junk folder and the calendar.
- After receiving the invitation, select Join.
Recovering a suspended account
Support coordinates with the relevant department to investigate and unlock a suspended account.
Contacting support
Support can be contacted 24 hours a day.
Rules & Requirements
OTP verification and security
- Website system access currently requires an OTP, including the first login, when the OTP is sent to the registered email address.
- Do not disclose an OTP to an agent.
- An OTP remains valid for five minutes.
- Repeatedly requesting OTPs may lock the account.
- Changing the phone number linked to the account or used to receive OTPs requires another OTP. The system requests this OTP after the phone-number change is initiated, and the customer must provide it to authorize the change.
- If the customer can access the website back office, the OTP phone number can be changed there.
- The OTP-receiving email address can be changed by changing the email address in the member information or account profile settings. Changing the registered user email requires an OTP.
- The system does not allow an additional email address to be added.
- OTP receipt can be disabled at the customer's request. Disabling OTP reduces security, removes an access-verification check, and increases the risk of unauthorized access. Without OTP, anyone who knows the password can access the website backend.
Changing the registered email address
- A request to change the registered email address must be submitted using the account owner's registered email address.
- If the customer cannot access the registered email address or the back-office system, documentary evidence is required.
- When a domain is registered in an individual's name, a copy of the registrant's identity card is required as supporting evidence.
- After the email address is changed, OTPs are sent to the new email address instead of the previous address.
- The existing password remains unchanged after the account email address is changed.
Recovering a forgotten password
- The password-recovery request must use the email address registered for the account.
- A password does not need to be entered on the initial password-recovery page.
- The password-reset message is sent to the account owner's email address.
- After the password is reset, the person who previously managed the website can no longer access the account using the old password.
- Support staff cannot view or retrieve customer passwords, and passwords are not stored by support.
Staff access to customer systems
- Support staff cannot enter a customer's website administration area.
- In another reported access arrangement, an agent can inspect the website backend after the customer approves an access request sent by email.
- Support staff do not log in using the customer's email account when requesting access to the customer's email-sending system.
- Access history can be reviewed, but customer passwords cannot be seen.
Login details and devices
- The backend username is the customer's domain name.
- A customer who can log in to the website backend can change the username themselves.
- The same email address and password must be used to log in from a mobile device or a computer.
Account lockouts
- Repeated login attempts can cause the account to become locked.
- The system locks after more than three unsuccessful birth-year confirmation attempts.
- Support must be contacted to unlock the system after it is locked.
Suspected phishing emails
- Emails claiming to be from the service provider but containing incorrect customer details may be spam or phishing emails.
Computer login problems
- Customers experiencing a computer login problem may send a screenshot of the error through R-Chat or the provider's LINE channel.
Compiled from 236 facts observed across 49 customer calls.