Skip to content

optimize email text for totp#789

Merged
kasparsd merged 8 commits intoWordPress:masterfrom
masteradhoc:patch-1
Feb 13, 2026
Merged

optimize email text for totp#789
kasparsd merged 8 commits intoWordPress:masterfrom
masteradhoc:patch-1

Conversation

@masteradhoc
Copy link
Contributor

What?

Improve the 2FA email message structure, wording, and clarity to better align with WordPress core email standards and improve security communication.

Why?

This change improves accuracy, consistency with WordPress core email tone (e.g., password reset emails), and overall user experience while preserving existing behavior.

How?

No functional behavior of token generation or validation was changed. Just clarification of the content itself

Testing Instructions

  1. Enable Email Two-Factor authentication.
  2. Attempt to log in with a user account requiring email 2FA.
  3. Verify the received email contains the new changes

Screenshots or screencast

image

Changelog Entry

Changed - Improved 2FA email wording, structure, and accuracy to align with WordPress core standards and enhance security clarity.

@github-actions
Copy link

github-actions bot commented Feb 13, 2026

The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the props-bot label.

If you're merging code through a pull request on GitHub, copy and paste the following into the bottom of the merge commit message.

Co-authored-by: masteradhoc <masteradhoc@git.wordpress.org>
Co-authored-by: kasparsd <kasparsd@git.wordpress.org>

To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook.

Copy link
Collaborator

@kasparsd kasparsd left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I feel like A login attempt was made for account ... sounds cautious or a bit dangerous.

Here are examples of email code login we can use for reference:

  • They all have the code in a dedicated line.
  • Some use scary language because they send the email verification only if things don't look like usual.

X (Twitter)

Image

OpenAI

Image

Microsoft

Image

Ryanair

Image

@kasparsd
Copy link
Collaborator

@masteradhoc Here is the email after updates:

email

Does it look good to you? Any changes you would suggest?

@masteradhoc
Copy link
Contributor Author

@kasparsd looks good to me!

@kasparsd kasparsd merged commit 66bc1ef into WordPress:master Feb 13, 2026
28 checks passed
@masteradhoc masteradhoc deleted the patch-1 branch February 13, 2026 13:38
@jeffpaul jeffpaul added this to the 0.15.0 milestone Feb 13, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants