I've seen this done two ways.
- Return an error saying the email doesn't exist
- Return a message that password reset instructions were sent. Personally, I don't like this method because the user can enter an invalid email address and think they're getting the reset instructions.
>Hi,
>
>Speaking about security aspect of Password recovery. Regardless of the approach of resetting password (email password in plain text, or sending a link to reset a password), what if user enters an email that does not exist in the database? Is it ok to return to the user a message such as "Email not found"? In theory someone can check if this or that person has access to the site (by entering an email address) but do you think this may create a security breach?
Craig Berntson
MCSD, Microsoft .Net MVP, Grape City Community Influencer