Keeping your Vexloot account safe
Your Vexloot account holds your purchase history and, temporarily, the credentials you buy — treat it with the same care as a bank login.
Sign in strong
- Use a unique password — do not reuse the one you use elsewhere. A password manager is the easiest way to keep them separate.
- Enable passkey — once available, enrolling a passkey on your primary device makes phishing attacks practically impossible against your account.
- Add a recovery email — the recovery email is used only for account recovery and is never shown to anyone else.
Session hygiene
- Vexloot sessions expire after 30 days by default. You can review and revoke any active session from the security tab in your settings.
- Sign out from shared devices. The account chip in the header always shows which account is signed in.
Purchase safety
- All order communication happens through the inbox on your order page. Vexloot will never ask you to move to Discord, WhatsApp or Telegram — treat any such request as a scam and report it from the order timeline.
- The one-time reveal panel shows purchased credentials only once. Copy or screenshot immediately; we do not keep a copy after the reveal window closes.
- When you buy an account, change every credential you can as soon as you receive it: email, password, recovery email, MFA. This is the standard practice for account transfers.
Report a compromise
If you see logins from unfamiliar devices, or your buyer inbox shows messages you did not send, revoke sessions from settings and email support from the affected account. We keep an audit log of every account action and can rebuild the timeline while investigating.