Starting a Password Reset
Navigate to the eviltoto login page. Below the password field, you'll see a "Forgot Password?" link. Click it. eviltoto displays a form asking for your registered email address. Type the email you used during registration, then click "Send Reset Link". eviltoto checks its records for an account matching that email, generates a unique reset token, and sends an email to that address within seconds.
The email includes a link labeled "Reset Your Password". This link contains the reset token and is valid for one hour. If the link expires, you can request a new one by repeating the "Forgot Password?" process. eviltoto does not limit the number of reset requests, so you can generate fresh links as needed.
The reset email comes from [email protected] (or a similar eviltoto domain). Check your spam folder if the email doesn't appear in your inbox within two minutes. If you never receive an email, verify that your registered email address is correct. If you are unsure of your registered email, contact eviltoto support with your account details (phone number, name, date of birth). Our support team can confirm your registered email without accessing your password.
Never share the reset link with anyone. It contains a token that grants temporary password-change access. If someone else clicks your reset link before you do, they can set a new password and lock you out of your account. eviltoto recommends deleting or ignoring any unsolicited password-reset emails.
Completing the Reset
Click the reset link from your email. eviltoto opens a password-reset form on your browser. The form asks for a new password, confirmation of that password, and a verification code sent via SMS to your phone number. The SMS arrives within 30 seconds of you opening the reset page.
Type your new password twice (once in each field) to ensure they match. Password requirements are at least 8 characters, including at least one uppercase letter, one lowercase letter, and one number. Once you enter the SMS code from your phone, click "Reset Password". eviltoto validates the code, confirms the match between the two password entries, and updates your account.
- Receive reset link via email (valid for 1 hour).
- Click the link to open the password-reset form.
- Enter your new password twice.
- Receive SMS verification code to your registered phone number.
- Type the SMS code into the reset form.
- Click "Reset Password" to confirm.
After reset completes, eviltoto displays a confirmation message. You can now log in using your email address and new password. Your session on other devices (if any) remains active until you manually log out. If you want to log out all sessions, use the "Log out everywhere" option in your account settings after you've reset your password.
Two-Factor Authentication and Account Recovery
If you enable two-factor authentication (2FA) on your eviltoto account, password reset becomes slightly more complex. During the password-reset flow, after you submit your new password and SMS code, eviltoto asks for a second authentication factor: a code from an authenticator app like Google Authenticator, Microsoft Authenticator, or Authy.
This protects against attackers who may have access to your email and phone number but not your authenticator app. Keep your authenticator app backed up securely—if you lose your phone and cannot access your authenticator codes, password reset becomes difficult. eviltoto support can help restore access through identity verification (government ID and date of birth), but the process takes longer than a standard reset.

Account Verification and Identity Confirmation
If you cannot access your registered email or phone number, eviltoto requires identity verification before allowing a password reset. This protects your account from unauthorized takeover. Contact eviltoto support with the following details:
- Your full name (as registered on the account).
- Your date of birth.
- Your registered phone number (even if you no longer have access to it, provide the number you registered with).
- A government ID photo (passport, national ID, or driver's license).
- The email address associated with the account.
eviltoto's support team verifies this information against your account details. If everything matches, they send a temporary reset link to a new email address you specify, or they perform the password reset on your behalf. This process typically takes 24–48 hours. During high-volume periods (Idul Fitri, Idul Adha, or major Champions League fixture weeks), it may take longer.
- Password requirements
- At least 8 characters, including uppercase, lowercase, and a number. No dictionary words or predictable sequences.
- Reset link expiry
- Reset links from eviltoto expire after 1 hour. If you miss the window, request a new link through the "Forgot Password?" page.
- SMS verification
- eviltoto sends SMS codes to your registered phone number during password reset. Standard message rates apply if you're on a limited SMS plan.
- Account access post-reset
- Your new password takes effect immediately. All previous sessions on other devices remain logged in until you manually log out.
Preventing Password Loss
Regularly update your eviltoto password, especially before major football seasons (Liga 1, Piala AFF, Champions League) or after you use a shared device. Use a password manager like Bitwarden, 1Password, or LastPass to generate and store complex passwords so you don't need to remember them. Never reuse your eviltoto password across other sites—if another service gets breached, attackers may try your eviltoto email and old password combinations.
Enable two-factor authentication in your account settings. This adds a security layer beyond your password. Store your backup codes (provided during 2FA setup) in a safe location separate from your phone and password manager. If you ever lose access to your authenticator app or phone number, backup codes allow recovery without contacting eviltoto support.

