WordPress Password Reset Link Not Working - Complete Fix

You forget your password. You click "Lost your password?" on the WordPress login page.

The email arrives within seconds. Good sign.

You click the reset link.

And then one of these happens:

  • Blank white page (no error, just nothing)
  • "Invalid" or "Expired" link error
  • Redirects back to login page without resetting anything
  • Shows "There is no user registered with that email address" (but you know you registered)
  • "Sorry, that key does not appear to be valid"

Your reset link is broken. You can't reset your password. You're stuck.

A client had this exact problem. Their password reset links worked for 6 months, then suddenly stopped. Users couldn't reset passwords. The client thought they were hacked.

Turned out their hosting provider changed their server IP that morning, and WordPress was trying to verify the reset link from the wrong domain. The entire password reset system was broken.

Password reset link failures are frustrating because WordPress doesn't tell you WHY it failed. It just silently breaks. But there are specific reasons this happens, and each one has a fix.


Why Password Reset Links Break

Understanding the cause helps you find the solution.

  • Site URL is misconfigured: WordPress thinks your site is at a different URL than where users are accessing it
  • Email isn't sending at all: The reset email never arrives, so the link doesn't exist
  • Link has expired: Reset links are only valid for 24 hours by default
  • Link was clicked twice: A reset link can only be used once
  • Email verification issue: The email server changed or requires authentication
  • Plugin conflict: A plugin is intercepting the reset process
  • Database issue: The user reset token isn't being stored correctly
  • Server IP changed: WordPress can't verify the link is from the same domain
  • HTTPS/HTTP mismatch: You're resetting on HTTPS but site runs on HTTP (or vice versa)
  • Server doesn't support remote requests: WordPress can't verify the reset link with itself

Step 1: Check if Email is Sending

If the reset email never arrives, the link obviously won't work.

Test email sending

  1. If you have access to another admin account, log into wp-admin
  2. Go to Tools > Site Health
  3. Look for "Email configuration" or "Mail"
  4. It will show either "Working" or "Not Configured"

If email shows "Not Configured"

Your hosting provider hasn't set up outgoing email. You need to either:

  • Use an SMTP plugin (Mailgun, SendGrid, WP Mail SMTP)
  • Enable mail server in hosting (contact your hosting provider)
  • Use SendGrid or Mailgun API (works on all hosting)

Install WP Mail SMTP

  1. Go to Plugins > Add New
  2. Search "WP Mail SMTP"
  3. Install and activate
  4. Go to WP Mail SMTP settings
  5. Select your email service (Gmail, Mailgun, SendGrid, etc.)
  6. Connect it with your API key
  7. Test send an email
  8. If successful, try password reset again

Step 2: Check Site URL Configuration

WordPress needs to know what URL your site is at. If it's wrong, reset links break.

Check your Site URL settings

  1. Log in to wp-admin (from another account, or via database)
  2. Go to Settings > General
  3. Look at two fields:
    • "WordPress Address (URL)"
    • "Site Address (URL)"
  4. Both should match your actual site domain (e.g., https://example.com)

Common Site URL mistakes

Site URL Setting Actual Domain Result
http://example.com https://example.com (with SSL) Reset link breaks (HTTP vs HTTPS mismatch)
example.com www.example.com Reset link breaks (www mismatch)
https://example.com:8080 https://example.com Reset link breaks (port mismatch)
https://staging.example.com After moving to https://example.com Reset link breaks (old URL still in settings)

Fix Site URL via wp-config.php

If you can't access wp-admin, you can set it in wp-config.php.

  1. Connect via FTP
  2. Open wp-config.php
  3. Add these lines BEFORE "That's all, stop editing!":
    define( 'WP_HOME', 'https://example.com' );
    define( 'WP_SITEURL', 'https://example.com' );
    (Replace example.com with your actual domain)
  4. Save and upload
  5. Try password reset again

Step 3: Check HTTPS/SSL Configuration

If your site uses HTTPS but WordPress doesn't know it, reset links break.

Verify SSL is working

  1. Open your site in a browser
  2. Look at the address bar
  3. Do you see a green lock icon?
  4. Is the URL https://yoursite.com or http://yoursite.com?

If you access via HTTPS but WordPress shows HTTP

  1. Log in to wp-admin
  2. Go to Settings > General
  3. Change both URLs to start with https:// instead of http://
  4. Click Save Changes
  5. Try password reset again

Force HTTPS via wp-config.php

Add this to wp-config.php:

define( 'FORCE_SSL_ADMIN', true );
define( 'FORCE_SSL_LOGIN', true );

This forces all login and password reset requests to use HTTPS.


Step 4: Check for Plugin Conflicts

A plugin might be intercepting the password reset process.

Disable plugins temporarily

  1. Connect via FTP
  2. Navigate to wp-content/plugins/
  3. Rename all plugin folders (add "-disabled" to the end of each)
  4. Try password reset again
  5. If it works, plugins were the issue
  6. Rename plugins back one at a time to identify the culprit

Common plugins that interfere with password reset

  • Security plugins: Wordfence, iThemes Security, All In One WP Security
  • Custom login plugins: Custom Login Page, Theme My Login
  • User management plugins: User Role Editor, UserPress
  • Membership plugins: MemberPress, Restrict Content Pro

Update these plugins first, or check their settings for "redirect password resets" or "custom login flow" options.


Step 5: Test the Actual Reset Link

The link might be formatted incorrectly or the token might not be valid.

What a reset link looks like

https://example.com/wp-login.php?action=rp&key=abc123key&login=username

Check each part

  • Domain: Should match your site URL exactly
  • /wp-login.php: Should be present
  • ?action=rp: Should be there (rp = reset password)
  • &key=: Should have a long token
  • &login=: Should have your username

If the link is missing any of these, the email is broken

Check Settings > General again for correct Site URL.

If the link looks correct but doesn't work

The token might have expired. Reset links are valid for 24 hours. If it's been more than a day, request a new one.


Step 6: Check Database Reset Token

WordPress stores reset tokens in the wp_users table. If they're not being stored, resets won't work.

Check if token is being generated

  1. Open phpMyAdmin
  2. Go to wp_users table
  3. Find your user row
  4. Look at the user_activation_key field
  5. It should be empty by default, but contain a key when a reset is requested

If user_activation_key is always empty

WordPress isn't generating reset tokens. This could mean:

  • wp_users table is corrupted
  • Database connection is failing
  • Database user doesn't have UPDATE permissions

Fix database permissions

  1. Contact your hosting provider
  2. Tell them: "My WordPress database user needs UPDATE permission on the wp_users table"
  3. They can grant this permission in minutes

Step 7: Check Loopback Request Support

WordPress verifies reset links by making a request to itself. If your server blocks these, verification fails.

Test loopback requests

  1. Log in to wp-admin
  2. Go to Tools > Site Health
  3. Look for "loopback request" or "cURL" tests
  4. If any show failures, your server can't make requests to itself

If loopback requests are failing

Contact your hosting provider. Tell them:

"My server can't make HTTP loopback requests to itself. Can you check if curl_exec is enabled, or if the firewall is blocking internal requests?"

This is a server configuration issue only hosting can fix.


Step 8: Check Server Time

Reset tokens expire based on server time. If server time is wrong, links expire instantly.

Check server time

  1. Log in to wp-admin
  2. Go to Settings > General
  3. Look at the timezone setting
  4. Make sure it matches your actual timezone
  5. Check if "UTC offset" is correct

Test server time

  1. Add this to a test page or plugin:
    <?php echo current_time('mysql'); ?>
  2. Compare it to the actual current time
  3. If they're significantly different (more than a few seconds), server time is wrong

Fix server time

Contact your hosting provider. Tell them your server time is off by X minutes/hours and needs to be synced with NTP.

They can fix this server-side.


Step 9: Enable Debug Logging to See the Error

WordPress can log password reset errors. This tells you exactly what's failing.

Enable debug logging

  1. Open wp-config.php via FTP
  2. Add these lines BEFORE "That's all, stop editing!":
    define( 'WP_DEBUG', true );
    define( 'WP_DEBUG_DISPLAY', false );
    define( 'WP_DEBUG_LOG', true );
  3. Save and upload
  4. Request a password reset
  5. Click the reset link
  6. Go to wp-content/debug.log
  7. Download it and look for errors mentioning "password" or "reset"

Common errors in debug log

Error Message Meaning Fix
"Key did not match user" Reset token doesn't match the user Database issue, token wasn't stored
"Expired key" Reset link is older than 24 hours Request a new reset link
"Could not retrieve user" User doesn't exist in database Check username/email spelling
"Loopback request failed" Server can't verify link with itself Contact hosting, enable curl_exec

Step 10: Check Email Provider Whitelist

Your email provider might be blocking reset emails as spam.

If reset emails are going to spam

  1. Check your email spam/junk folder
  2. Look for emails from your WordPress site domain
  3. Mark them as "Not Spam"
  4. Add your WordPress domain to your email provider's safe sender list
  5. Request a new reset email

Whitelist WordPress emails in Gmail

  1. Open Gmail
  2. Create a filter: From: noreply@yourdomain.com
  3. Choose "Never send to spam"
  4. Apply to all matching emails

Whitelist in Office 365/Outlook

  1. Go to Settings > Mail > Junk email
  2. Add noreply@yourdomain.com to Safe Senders list
  3. Also add your WordPress domain's mail server to Trusted Senders

Real-World Password Reset Failure

Scenario: A SaaS company hosted their WordPress site on a subdomain (blog.example.com). Everything worked fine. Then they moved to their main domain (example.com). Password resets stopped working.

What happened:

  1. The admin changed the Site URL in settings
  2. But they didn't update the database URL completely
  3. WordPress was generating reset links for example.com
  4. But the database still thought the site was at blog.example.com
  5. When users clicked the reset link, WordPress tried to verify the link at the wrong domain
  6. Verification failed
  7. Reset failed

Our fix:

  1. Checked Settings > General (showed correct URL)
  2. Checked wp-config.php (showed old blog subdomain)
  3. Updated wp-config.php with new domain
  4. Tested password reset
  5. Worked instantly

The lesson: WordPress stores the site URL in multiple places. If they don't match, resets break.


Password Reset Troubleshooting Checklist

Reset link not working?

  • āœ“ Verify email is being sent (check spam folder)
  • āœ“ Confirm Site URL matches your actual domain
  • āœ“ Check HTTPS vs HTTP settings (should be consistent)
  • āœ“ Disable plugins via FTP to check for conflicts
  • āœ“ Verify reset link format (has key and login params)
  • āœ“ Check database token is being generated (user_activation_key)
  • āœ“ Test loopback requests in Site Health
  • āœ“ Verify server time is correct
  • āœ“ Enable debug logging to see actual errors
  • āœ“ Check if reset email is going to spam
  • āœ“ Request a new reset link (old ones expire after 24 hours)
  • āœ“ Contact hosting if loopback requests fail

Prevention: Keep Password Resets Working

1. Use an SMTP plugin

Install WP Mail SMTP or similar. Proper email delivery is critical for resets.

2. Monitor Site Health

Check Tools > Site Health weekly. It catches URL mismatches and server issues early.

3. Test after migrations

If you move domains or change servers, test password reset immediately after.

4. Keep plugins updated

Security and login-related plugins should always be on the latest version.

5. Use staging for plugin testing

Test new plugins on staging before production. Some break password resets.


When to Contact Hosting Support

Contact them if:

  • You can't access wp-admin to check settings
  • Site Health shows "loopback request failed"
  • Debug log shows "curl_exec disabled"
  • Server time is significantly off
  • Email configuration shows "not configured" and you can't install SMTP plugin
  • You've tried all these steps and still have failures

What to tell them:

"WordPress password reset links are broken. I've checked the Site URL, HTTPS configuration, and plugins. Can you verify the database is working, curl_exec is enabled, and server time is synced?"

Most hosting providers fix this in 30 minutes.


The Real Talk

Password reset failures are one of the most frustrating WordPress issues because they happen silently. WordPress doesn't explain what's wrong. It just shows "link not working" with no details.

But password resets are deterministic. They always fail for specific reasons. There are no mysteries here. It's either:

  • Email isn't sending (network issue)
  • URL is wrong (configuration issue)
  • Plugin is interfering (conflict issue)
  • Server can't verify (server configuration issue)
  • Token expired (user clicked too late)

Work through these systematically. Check email first (easiest to fix). Then check URLs. Then disable plugins. Enable debug logging and read the actual error messages.

You will find the cause. And once you do, the fix is usually under 5 minutes.

Don't give up. Password resets can always be fixed.