Tools · runs in your browser
Sign-in code guess odds
Five tries at a six-digit code sounds safe. Whether it is depends on how many new codes someone can ask for. Put in your limits and see the chance that a guesser gets in.
Against the usual marks
| Mark | Yours |
|---|
What would change it most
| Change | 30 days | One year |
|---|
The link in your address bar keeps these settings, so you can paste it into a review or a ticket.
How it's worked out
- One code: a guesser with t tries at a code picked from N possibilities gets it with chance t / N. Six digits is N = 1,000,000.
- Many codes: each new code is a fresh draw, so over k codes the chance is 1 − (1 − t/N)k. This is why "codes per hour" matters more than it looks: it multiplies everything.
- A lockout caps the total number of guesses, whatever the calendar says. It's the only setting that makes the one-year number stop growing. It also lets a stranger lock someone out on purpose, so pair it with a way back in.
- Code lifetime doesn't change the arithmetic here; the tries limit does that. A short life matters for a different reason: an old code sitting in an inbox shouldn't still work.
- The model is one target address and a guesser who never gets tired. Real attackers spread over many accounts: with 10,000 accounts, multiply the chance of getting into some account accordingly.
The marks come from NIST's digital identity guidelines (SP 800-63B): codes of at least six decimal digits, a sign-in finished within 10 minutes, and no more than 100 failed attempts in a row on one account. The same document says email shouldn't be sold as a second factor; an emailed code proves someone can read that inbox, which is what a sign-up or a passwordless sign-in needs.
What the email itself should look like, and the server side in twenty lines: Six digits, ten minutes: what a sign-in code email needs to get typed in.
Send the code in one HTTPS call
email59 is an email router with a small API for sign-in codes, alerts and notices. No domain setup, no subscriptions.