Skip to main content

How to use Spikerz's recovery contacts (recovery email & phone)?

Written by Nathan

What Are Login Contacts?

Login contacts are the email addresses and phone numbers that can sign in to a social media account, saved directly on that account's protection page in Spikerz. They sit alongside the secured email and secured phone number Spikerz generates, so every address attached to an account is visible in one place.

Each channel now has its own card. The Email card lists every email on the account - the one the team logs in with and the Spikerz secured address - and the Phone number card does the same for phone numbers. There is no separate recovery section to open.

Saving a login contact changes nothing on the social platform. Spikerz stores the address so the team can find it later, instead of hunting through spreadsheets, chat threads, and personal notes at the exact moment access is at risk.

With login contacts, you can:

  • See every email and phone number attached to an account on a single page

  • Save the address or number the account actually signs in with, with an optional label

  • Check login emails against your company's domains automatically

  • Spot accounts that sign in with a personal or agency address

  • Remove a contact the moment it's no longer valid

  • Track which accounts have a login email, a login phone, and a saved password


Where to Find Login Contacts

Open Account Protection from the left-hand sidebar of your Spikerz dashboard and select the account you want to work on. The Email and Phone number cards appear in the Inbox step.

Each card header shows the channel name and the number of contacts saved on it, followed by the actions available to you. Below the header, every contact on the account is listed as its own row:

  • Login contacts – Marked with a Login chip, plus the label you gave them and a domain chip where one applies.

  • The Spikerz secured address – Marked with a Spikerz chip.
    ​

If a channel has nothing saved yet, the card shows "No emails added yet" or "No phone numbers added yet".


Setting Allowed Login Domains

Allowed login domains are the domains your organization's social accounts are expected to sign in with. Once they are set, Spikerz checks every login email against the list and marks it accordingly.
​

This list is set once for the whole workspace. Only admins can edit it, and managers and above can view it.

Step 1

Go to Settings and open the Workspace tab.

Step 2

Find the Allowed login domains section.


​

Step 3

Under Add a domain, enter a bare domain such as yourcompany.com — no https://, no @, and no path.
​

Step 4

Click Add domain. The domain appears in the list immediately and applies to every account in the workspace.

To remove a domain, click the remove icon next to it.

A domain matches its own subdomains too, so yourcompany.com also covers mail.yourcompany.com. Lookalike domains do not match — notyourcompany.com is not treated as yourcompany.com. Matching ignores capitalization, and you can save up to 50 domains.
​

While the list is empty, the section reads "No domains yet. Login emails are not checked." and the Inbox step shows a notice: "Login emails are not being checked". Admins get a Set allowed login domains shortcut straight from that notice.
​

⚠️ Setting the list is optional. With no domains configured, login contacts still work exactly as described — Spikerz simply doesn't mark any address as on- or off-domain.


How to Add a Login Email or Phone Number

Step 1

Go to Account Protection from the left-hand sidebar and select the account you want to protect.


​

Step 2

In the Inbox step, click Add login email on the Email card, or Add login phone number on the Phone number card.

Step 3

Enter the address or number in the Email address or Phone number field. This field is required. Phone numbers should include the country code, for example +1 202 555 0148.


​

Step 4

While you type an email address, Spikerz checks it against your allowed login domains and shows the result under the field:

  • A green chip with your organization's name, and the note "Matches an allowed login domain."

  • A warning chip reading "Not a [your organization] address", and the note "It will be saved and flagged on the account.

An off-domain address is never blocked. It is saved like any other contact and carries the warning chip so the team can see it at a glance.


​

Step 5

Add a Label (optional) to record who or what the contact belongs to, such as "Marketing lead" or "Agency inbox". This is optional but recommended when several people manage the same account.


​

Step 6

Click Save. The contact appears on the card with its Login chip, its label, and its domain chip.

The password for the address is not entered here. It is added in the next step, Password, together with the rest of the login credentials.


What the Chips Mean

Each row on a card is marked with chips that describe the contact at a glance:

  • Login – This is an address or number the account signs in with, saved by your team.

  • Spikerz – This is the secured address Spikerz generated for the account.

  • Your organization's name, in green – The login email is on one of your allowed login domains.

  • "Not a [your organization] address", in amber – The login email is not on any allowed domain. It is saved, and flagged.

  • Your label – The optional note you added when saving the contact.

Domain chips apply to email only. Phone numbers are never domain-checked, and no chip appears while the workspace has no allowed login domains configured.


Managing Saved Login Contacts

To remove a contact, click the menu icon at the end of its row and select Remove login email or Remove login phone number. The contact is deleted immediately for everyone with access to the account.

Spikerz validates every contact before saving it. You may see one of the following messages:

  • Enter a valid email address. – The email address is incomplete or incorrectly formatted.

  • Enter a valid phone number. – The phone number is incomplete or missing a country code.

  • This contact is already saved. – The same email or phone number is already stored for this account.

⚠️ Viewers can see every contact on an account but cannot add or remove them.


Login Contacts and Account Auto Lockout

Login contacts are saved by you, so Spikerz has no inbox of its own to receive the account's password notices. On an account with login contacts but no secured inbox, the Account lockout section stays visible but Activate protection is disabled, and hovering over it explains why: account auto-lockout needs a secured inbox to receive rotation notices.

Everything else in the section keeps working. You can still:

  • Save current password – Store the account's current password securely in Spikerz.

  • Edit password – Update the stored password whenever it changes on the platform.

  • Rotate password – Trigger a password rotation manually from the menu on the Current password panel.


Tracking Coverage Across Your Accounts

Login contact coverage is reported alongside your other protection metrics, so you can see at a glance which accounts still need attention.

On the Overview Dashboard

When viewing all accounts, the Overview dashboard displays three coverage tiles as a ratio of protected accounts to eligible accounts:

  • Recovery email – Number of accounts with an email saved for account recovery.

  • Recovery phone – Number of accounts with a phone number saved for account recovery.

  • Saved password – Number of accounts with the current password saved in the vault.

When viewing a single account, the same metrics appear as Protected or Not protected, each with a shortcut to complete the setup, such as Add a recovery email or Save the current password.

In the Account Protection Table

In the all-accounts Account Protection view, four columns appear after Account lockout:

  • Login email

  • Login phone

  • Login domain

  • Password

Login email, Login phone, and Password each carry a status indicator:

Active – A login email, login phone, or saved password exists for the account.

Inactive – Nothing has been saved yet for that account.

Login domain summarizes the domain check for the whole account:

- Your organization's name, in green – Every login email on the account is on an allowed domain.

- "Not a [your organization] address" – At least one login email on the account is off-domain. A single off-domain address is enough to flag the row.

- Not checked – The account has no login email saved, or the workspace has no allowed login domains configured.

Each of the status columns also has its own filter, so you can list every account that is still missing a login email, a login phone, or a saved password.


​


​

Did this answer your question?