Temporary lock outs
If you enter the wrong password too many times, Mallow temporarily locks your login for 30 minutes to protect your account. This is different from an account ban or billing suspension.
What triggers a lockout
After 10 failed login attempts, Mallow blocks further sign-in attempts for your username and IP address. The lockout lasts 30 minutes and then lifts automatically. If you enter the correct password successfully, the failed-attempt counter resets.
How to tell you're locked out instead of using the wrong password
When you're locked out, the login page displays:
Too many login attempts. Please wait a few minutes and try again.
A normal failed login because of a wrong password displays:
Invalid email or password. Please try again.
API integrations will receive an HTTP 429 response during a lockout instead of the usual 401 or 403.
How to regain access
The lockout clears automatically after 30 minutes. You do not need to reset your password. If you still cannot log in after waiting, or if you believe someone is trying to access your account, contact Mallow support at [email protected].
How lockouts differ from account bans or suspension
Login lockout is temporary (30 minutes), automatic, and triggered only by repeated failed sign-in attempts from the same username and IP address.
Billing suspension happens when your subscription payment fails and is resolved by updating your payment method.
Permanent account bans occur for prohibited industries or compliance violations, and you cannot resolve them by waiting.
See Account bans and restrictions for details on suspensions and closures.