Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress errorsReset a WordPress Password When the Email Does Not Arrive

Reset a WordPress Password When the Email Does Not Arrive

If you have forgotten a WordPress password, the built-in reset link is the safest place to start. When the reset email never arrives, you can still recover an account through another administrator, WP-CLI or, with care, the database.

The message you might see

Forgotten WordPress password or the reset email never arrives

Different wording, or a file path in the message? Paste it into our free error finder to see which plugin or theme it comes from.

What a failed WordPress password reset means

The normal WordPress recovery process starts at /wp-login.php with Lost your password?. WordPress sends the reset link to the email address stored against that user account.

If the message does not arrive, decide whether the problem is the account or the email path. An old account email, spam filtering, a site-wide mail failure or an SMTP configuration problem can all prevent delivery even though the user still exists.

If you control the site through another access method, use that to confirm the account details and restore access without weakening security.

Why WordPress password reset emails fail

The account email can be correct while WordPress email delivery is failing more generally. Test whether other site emails are arriving before assuming the password-reset function itself is broken.

  • The reset email is filtered. Check spam, junk and any corporate quarantine system.
  • The user email is outdated. The reset link goes to the email stored for that WordPress user, not necessarily the address you currently use.
  • WordPress mail is failing. A hosting mail restriction, broken SMTP integration or invalid sending credentials can affect password resets along with form notifications.
  • A security plugin changes login behaviour. It may limit attempts, add two-factor authentication or block the current IP.
  • The login problem is not the password. Cookies, redirects or a PHP error can make a correct new password appear not to work.

If other WordPress messages are also missing, fix the mail path as a separate issue rather than repeatedly resetting the user.

How to reset a WordPress password safely

Use the first method available to you. Before editing site files or the database, take a full backup of both files and database. Never share an existing password in a ticket or email.

  1. Use the built-in reset link. Request one reset, check the account inbox and spam folder, and use the newest link if several messages later arrive.
  2. Ask a second trusted administrator to reset the account. They can open Users, edit your profile and set a new password. They should not need your old password.
  3. Use WP-CLI if you have authorised server access. This is preferable to editing the password field directly because WordPress handles the account update.
wp user reset-password username --show-password

If WP-CLI is not available, phpMyAdmin can be used as a fallback. Open the correct WordPress database, locate the users table for the site's actual table prefix, then edit only the intended account. In user_pass, enter a new strong temporary password and select the MD5 function before saving. WordPress accepts the MD5 value for this recovery path and rehashes it with its current password system after the next successful login. Change the password again from your WordPress profile after you are back in.

If a security plugin is preventing a legitimate owner from reaching the login process, use your host's file manager or SFTP to rename that specific plugin folder inside wp-content/plugins. Do not delete the plugin. Restore its folder name after access is recovered and review the lockout or two-factor settings before reactivation.

When a password problem needs technical help

Stop if you are unsure which database or user row belongs to the live site, if you cannot take a reliable backup, or if the account email or administrator role changed without permission. Unexpected account changes can indicate a security incident.

Get help as well if the reset succeeds but wp-admin still redirects, shows a critical error or immediately locks the account again. Those symptoms point beyond the password itself.

Our Emergency Fix is £249 per incident with a response within 2 working hours. Care plans start from £59 a month for ongoing WordPress maintenance and support.

Common questions

Answers to the questions we hear most about this.

How can I reset my WordPress password if the email never arrives?

Use another trusted administrator account if one exists. If you have authorised server access, WP-CLI is a strong recovery option. phpMyAdmin is a fallback when used carefully after a full files and database backup.

Is it safe to use MD5 to reset a WordPress password in phpMyAdmin?

WordPress supports MD5 as a recovery fallback for a manually reset password and will replace that value with its stronger current hash after a successful login. Use a strong temporary password, change it again after login, and prefer WP-CLI when available.

Can I disable a security plugin if it is blocking my WordPress login?

If you own and control the site, you can temporarily rename that specific plugin folder inside wp-content/plugins using SFTP or the host file manager. Do not delete it. Restore the folder name and review its settings once access is recovered.

Site down or showing an error?

Call us now. Emergency Fix is £149 with a response within 2 working hours, and no fix means no fee.

Get website support