Experience Cloud site users may experience a password reset loop in which, after clicking the password reset link received via email, they are redirected back to the password reset request page instead of the change password page.
This issue is typically caused by third-party email security software — such as Barracuda, Trend Micro, GreatHorn, or MimeCast — that automatically scans URLs in incoming emails to verify they are not malicious. When this scan occurs, the software follows the one-time password reset link, consuming the token before the actual user can click it. As a result, when the user clicks the link, the token has already been used and the reset cannot proceed.
The root cause of this issue is third-party email security software consuming the one-time password reset token before the user clicks the link. The resolution is to enable the Don't immediately expire links in forgot password emails permission on the affected user's profile. This allows the reset link to remain valid even after it has been accessed by security scanning software.
Work with your Salesforce Admin to enable this setting using the appropriate steps below.
Enhanced Profile User Interface
Disabled Enhanced Profile User Interface
000381402

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.