• Our team is looking to connect with folks who use email services provided by Plesk, or a premium service. If you'd like to be part of the discovery process and share your experiences, we invite you to complete this short screening survey. If your responses match the persona we are looking for, you'll receive a link to schedule a call at your convenience. We look forward to hearing from you!
  • We are looking for U.S.-based freelancer or agency working with SEO or WordPress for a quick 30-min interviews to gather feedback on XOVI, a successful German SEO tool we’re looking to launch in the U.S.
    If you qualify and participate, you’ll receive a $30 Amazon gift card as a thank-you. Please apply here. Thanks for helping shape a better SEO product for agencies!
  • The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.

Resolved Password reset request was denied

pleskfiber

New Pleskian
Server operating system version
Ubuntu 20.04.6
Plesk version and microupdate number
18.0.56 #4
Hello everyone!

I'm experiencing a recurring issue with Plesk when trying to send password reset emails to my users. Every time I attempt this, I encounter the following error message, and I'm puzzled about its cause:

Code:
Password reset request for email ‘john.doe@example.’com (user ‘john.doe’) was denied: domain ‘example.com can be managed by a different user.

This issue seems to affect nearly all users, whose email accounts are typically in the format <firstname>.<lastname>@example.com. Our Plesk server is hosted under a subdomain (e.g., plesk.example.com), and the main domain example.com is registered to a user within Plesk since it's our company's primary domain.

I have discovered that the password reset function works for the user who have management rights for the example.com domain.

I'm reaching out for insights or suggestions on what might be causing this issue and how to resolve it. Any advice or guidance would be greatly appreciated!

Thank you in advance!
 
This is an expected behavior. When you as a customer use forgot password option while having your email on a domain that has an SMB user that can manage mail on that domain, we explicitly deny your request, because said SMB user can modify the target mail address password and get access to the server as a client/reseller. Solution: Use a valid customer's account o reset a password or ask the Plesk "admin" to do that.
 
Hello Peter,

Thank you for your prompt response.

I've decided to proceed with manually resetting the passwords for the users. I appreciate your assistance in this matter.
 
This is an expected behavior. When you as a customer use forgot password option while having your email on a domain that has an SMB user that can manage mail on that domain, we explicitly deny your request, because said SMB user can modify the target mail address password and get access to the server as a client/reseller.
Is this the case for any email that is not in the respective customer's domain itself?
 
I don't get the question. Please re-phrase.
Any external email provider is able to read your mail if they choose to, whether they use plesk or not. Why do you think it improves security to just block accounts on the same server in a different subscription? (And blocking all external emails would make the feature rather useless.)
 
Back
Top