Stop password reset spam. Enable 2FA. Add an Account PIN. Lock down your email and sessions.
In Settings → Security, enable 2-Step Verification. We recommend an authenticator app (TOTP) rather than only email codes. Popular options: Google Authenticator, Microsoft Authenticator, 1Password, or Authy.
If an attacker can control your email, they can reset your Roblox password.
Subject: Account Security — Password Reset Spam / Possible Unauthorized Access Hello Roblox Support, I’m receiving password reset emails that I did not request and I’m concerned about unauthorized access. Details: - Username: <username> - User ID (if known): <id> - Email on file: <email> - Approximate time of suspicious activity: <time> Actions taken: Changed password, enabled 2FA with authenticator, added Account PIN, and logged out of all other sessions. Please review my account security and let me know if you see unusual logins. Thank you, <name>
No. The PIN only protects settings changes (including security and trade settings). Keep the PIN private.
Yes. 2FA stops attackers even if your password leaks or is guessed.
Use recovery codes you saved during setup. If you don’t have them, contact Roblox Support with proof of ownership.