Password Reset Requests Not Blocked after Suspicious IP Banned

Last Updated: Sep 3, 2024

Overview

This article explains why Auth0 does not block password reset requests from a specific IP, although login requests are blocked when Suspicious IP Throttle is triggered for that IP.

Applies To

  • Password Reset Requests
  • Suspicious IP

Solution

The suspicious IP throttling feature is not available for password reset flows.

To see this functionality considered in a future release, please submit a feature request using this form.

Meanwhile, if needed, a specific IP could be blocked by opening a support ticket.