Why Does StoreYug Use Dual-OTP Verification?
Your account email address is the master key to your store—it receives password reset links, billing tax invoices, and sensitive operational alerts. Conventional websites often allow email updates with a single code, leaving stores vulnerable if an unattended laptop or session is compromised.
To eliminate account takeover risks, StoreYug employs a strict Dual-OTP Security Protocol: whenever you request an email change, verification codes are dispatched simultaneously to both your existing registered email and your proposed new email address. Both codes must be validated together before the change is approved.
🛡️ Complete Takeover Protection: Even if someone gains momentary access to an unlocked dashboard, they cannot transfer your store away because authorization from your current inbox is strictly required.
Step-by-Step: Changing Your Registered Email
- Navigate to My Profile from the top-right account menu.
- In the Personal Information card, delete your current email and type your new email address in the Email Address field.
- Click Save Changes.
- The Verify Email Change security modal will automatically open on your screen.
- Open your email accounts to collect both verification codes:
- Code 1 (Current Email): Sent to your existing email inbox with the subject "Security Alert: Verify email change - StoreYug".
- Code 2 (New Email): Sent to your new email inbox with the subject "Verify your new email - StoreYug".
- Enter both 6-digit codes into their respective input fields in the modal:
- Code sent to current email
- Code sent to new email
- Click Verify & Update Profile.
Safety Timers and Protection Rules
- 5-Minute Expiry: Both OTP codes remain valid for 5 minutes from the time of generation.
- 2-Minute Resend Cooldown: If either code fails to arrive, an on-screen timer displays a 2-minute countdown before allowing you to click Click here to resend (up to 3 resends per session).
- Rate Limiting: For store security, you can initiate an email change request a maximum of 3 times within a 24-hour period.
- Attempt Lockout: Submitting incorrect OTP codes 5 times immediately clears the pending request to prevent brute-force guessing.
💡 Post-Change Login: Once verified, your new email address takes effect immediately. You must use this new email address for future dashboard sign-ins and password recovery requests.