Security
Lost Access to Your Account Email
Your account email is your sign-in identity and the destination for every password reset and security code, so losing access to it is the one lockout you cannot solve inside the panel.
What you can do depends on whether you can still sign in. Work out which situation you are in first.
Situation One: You Can Still Sign In
This is the good case, and it is much more common than people expect. Your session is still valid, or your password and second factor still work, and only the mailbox has gone.
Fix it immediately, before anything logs you out:
- Go to Settings, then Profile.
- On the Email row, click Change.
- Enter an address you genuinely control and click Send verification link.
- Open the link at the new address.
That promotes the new address to be your sign-in identity. The full process, including what happens to the old address, is in Changing the Email Address on Your Account.
Do this now, not later. Sessions expire, browsers get cleared, and a new device triggers an email verification code you will not be able to receive. Every hour you wait makes this harder.
While you are there, add a factor that does not depend on email: a passkey or SMS two-factor on Settings, then Security. See Lost Your Two-Factor Device.
Situation Two: You Cannot Sign In
Password resets go to the address you have lost, so the reset flow cannot help you. There is no self-service recovery for this and there deliberately never will be: an account you could take over by claiming to have lost the email would not be secure.
Before contacting support, check whether one of these applies, because each is faster than an identity check:
Do you sign in with Google, GitHub, or Apple? Then your password is irrelevant and the mailbox may be too. Try the social sign-in button on the login page. If the provider account still works, you are in.
Is the mailbox merely full or filtered rather than gone? Clear space, check spam and quarantine, and try a password reset again. See Not Receiving Email if the mailbox is hosted with us.
Is it a work address at a domain you still control? Ask whoever administers that domain to restore the address, or to forward it to you temporarily. That is usually a five minute job for them.
Did the domain expire? If the address was on a domain that lapsed, renewing or recovering the domain restores the mailbox. This is often the real problem.
Contacting Support
If none of those apply, email support@kapsulehost.com from any address you control, and say clearly that you have lost access to the email address on your Kapsule account.
Support will need to establish that you are the account holder, and cannot take your word for it. The strongest evidence is something only the real owner would have:
- Your Support Key, if you noted it down. It looks like
KSK-followed by six characters and appears on the Support page and on Settings, then Account.

- Invoice or order numbers. Orders begin
KC-and invoices beginKCI-. - The last four digits and expiry of the card on file. Never send a full card number.
- Details of domains, sites, or mailboxes on the account.
- Control of a domain registered on the account, which you can demonstrate on request.
Nobody at Kapsule will ever ask you for your KPanel password, and you should never send it. If a message claiming to be from Kapsule asks for it, it is not from us. See Phishing and Impersonation.
Expect this to take longer than a password reset. An identity check that could be rushed would not be an identity check.
Why There Is No Self-Service Route
It is worth understanding the reasoning, because it is the same reasoning that protects you.
Every recovery mechanism is also an attack path. A "lost my email" button that moved an account to a new address on request would be the easiest way to steal a hosting account, along with the domains, the mailboxes, and the card on file that come with it. So the recovery route is deliberately manual and deliberately slow.
The corollary is that the prevention is entirely in your hands, and takes two minutes.
Preventing This
Use an email address you do not host with us. If your account email is on a domain hosted at Kapsule, then a suspended account, a lapsed domain, or a mail outage takes away the address you need in order to fix it. Use an independent provider.
Do not use an address on a domain you might let expire. Domains lapse quietly. The mailbox goes with them.
Do not use a shared or role address. An info@ mailbox read by three people is a poor destination for security codes, and a departing colleague can take the access with them.
Add a second sign-in method. A passkey on Settings, then Security, works without any email at all.
Note your Support Key. Copy it from Settings, then Account, and keep it with your other business records. It is the fastest way for support to find your account.
Keep one invoice PDF. It has your order and invoice numbers on it, which are strong evidence of ownership. See Reading Your Invoice.
If It Was Not You Who Changed It
There is one variation of this problem that is not a lockout at all, and it needs urgent action rather than patient recovery: someone else changed your account email.
The clue is an email you did receive, headed "Email change requested", naming an address you have never seen. That alert is sent to your existing address specifically so you find out while you still have control.
If that happened:
- Sign in immediately, while your address is still the active one.
- Change your password.
- Sign out everywhere from Settings, then Security.
- Revoke any API keys you do not recognise. See API Keys and Developer Access.
- Check the audit log for anything else that changed.
- Enable two-factor authentication if it is not already on.
Then contact support and tell them what happened. Account Security has the full compromise checklist.
Troubleshooting
The reset email is not arriving. Check spam and quarantine, and confirm the address is the one on the account. If the mailbox is on a domain hosted with us and the account is suspended, mail will not be delivered. See Why Your Account Was Suspended.
"Please verify your email before signing in." Your address is unverified rather than lost. Sign in and use Resend link on the Email row.
A code was emailed to me for a new browser and I cannot receive it. That is an email problem, not a two-factor problem, and the same recovery route applies.
I have two accounts and am not sure which email belongs to which. Say so in your support request and list both addresses.
My colleague's address is on the account and they have left. You do not need their address. Remove their membership from Settings, then Team, and invite the replacement. See Inviting Team Members and Setting Roles.