Account security
Access to the account is the key to every domain under it. This page collects what secures it.
Where to find it
Section titled “Where to find it”Account → Security, direct address: dash.regfish.com/my/setting/security


Password
Section titled “Password”Under change password you need the current password and the new one twice. The complexity meter next to it is not a suggestion but the condition: at least eight characters, upper and lower case, a digit and a special character.
If you no longer have the current password, the way in is resetting it.
Sign in security
Section titled “Sign in security”Four methods sit side by side, and they do not exclude each other:
| Method | Purpose |
|---|---|
| Authenticator app | One time codes; several devices can be registered |
| Passkeys | Sign in with fingerprint, face or a security key |
| Recovery codes | One time codes for when no 2FA device is reachable |
| SMS as backup | Second factor to a verified mobile number |
The recovery codes are the part not to skip. Without them, a lost phone equals a locked account.
2FA is also the prerequisite for the protection rules of the domain guardian: their mechanism is the fresh 2FA confirmation, so without active 2FA they cannot be switched on.
Signed in devices
Section titled “Signed in devices”The list shows every active session with browser, operating system, IP address, sign in time and last activity. The current device is marked. You can sign out individual devices or every other device at once.
After changing the password on suspicion, this second step belongs to it: a changed password does not end existing sessions by itself.
API keys
Section titled “API keys”They live in the same area and have their own chapter: creating an API key.