Editorial guide · Login and access

Login, account access, and the verification steps that protect your account.

The desk does not host a login form. The login page explains the verification steps you should run before you enter credentials on any login form, the signals that distinguish a legitimate login from a phishing page, and the recovery steps if you cannot access your account.

Home · Login Last review 22 July 2026 Source: editorial methodology v 2026.07
Wicketkeeper in focused position behind the stumps

Check the URL before you type a password

Finger scrolling a fantasy sports app on a smartphone
The URL is the first signal. The certificate is the second.

The URL is the first signal that a login form is legitimate. The domain should match the platform's official domain, and the connection should use HTTPS with a valid certificate. The desk's verification rule is conservative: if the URL does not match the platform's official domain, do not enter credentials. The certificate check is the second signal: a valid certificate confirms the connection is encrypted and the server is who it claims to be.

Two-factor authentication, if available

Two-factor authentication adds a second verification step on top of the password. The second step is usually a code sent to your phone or generated by an authenticator app. The desk's position is that two-factor authentication is a strong signal that a platform takes account security seriously, and a platform that offers two-factor authentication is more likely to be a reputable one. The desk recommends enabling two-factor authentication on every platform that offers it.

Password reset: the official channel only

Laptop showing a fantasy research dashboard
The reset link should arrive from the platform's official domain.

The password reset link should arrive from the platform's official domain, and the link should resolve to the platform's official domain. A reset link that arrives from a third-party domain, or that resolves to a third-party domain, is a phishing signal. The desk's recommendation is to never click a reset link in an email; navigate to the platform's official domain manually and use the in-product reset flow.

Account recovery: what to send the support team

If you cannot access your account, the customer-care page is the place to start. The support team will ask for the email address on the account, the last successful login, the device you usually log in from, and any recent transactions. The desk's recommendation is to gather these inputs before you contact support, and to send them through the platform's official support channel, not through a third-party contact form.

Phishing: the signals to watch for

Smartphone showing a fantasy sports app on a grass field
Phishing is the most common account-takeover vector. The signals are consistent.

Phishing is the most common account-takeover vector. The signals are consistent: a sender domain that does not match the platform's official domain, a reset link that resolves to a third-party domain, a request for credentials through a channel the platform does not use, and a sense of urgency that is not consistent with the platform's normal communication. The desk's recommendation is to treat any of these signals as a phishing signal, and to verify through the platform's official channel before you act.

Check the URL. Check the certificate. Check the channel. Three checks, one habit.
Recovery next

If you cannot access your account, start with the customer-care page

The customer-care page lists the support channels the desk has verified, and the inputs the support team will ask for.

Read the customer-care page See the wallet and KYC page

Affiliate disclosure: the button above routes through a first-party redirect. The desk may earn a small commission if you sign up.

How to read a login URL you have never seen before

A new login URL is a URL the desk has not covered. The desk's reading of a new login URL is conservative: read the domain, read the certificate, and read the publisher name. The three reads are the inputs the desk recommends, and the inputs are the difference between a guess and a bet. The desk does not publish a hot take on a new login URL, and the desk does not recommend a specific platform without the three reads. The reason is the same: a hot take is a guess, and a guess is not the product.

How the desk handles a login URL that does not match the official domain

A login URL that does not match the official domain is a phishing signal, not a legitimate login flow. The desk's reading of a mismatched login URL is conservative: read the domain, read the certificate, and read the publisher name. The three reads are the inputs the desk recommends, and the inputs are the difference between a guess and a bet. The desk publishes a correction when a phishing login URL is verified, and the correction is the input the desk recommends reading.

How to read a login form that asks for unusual inputs

A login form that asks for unusual inputs is a phishing signal, not a legitimate login flow. The desk's reading of an unusual-input login form is conservative: read the form, read the privacy policy, and read the publisher name. The three reads are the inputs the desk recommends, and the inputs are the difference between a guess and a bet. The desk publishes a correction when a phishing login form is verified, and the correction is the input the desk recommends reading.

How the desk handles a login form that does not use HTTPS

A login form that does not use HTTPS is a phishing signal, not a legitimate login flow. The desk's reading of a non-HTTPS login form is conservative: read the URL, read the certificate, and read the publisher name. The three reads are the inputs the desk recommends, and the inputs are the difference between a guess and a bet. The desk publishes a correction when a non-HTTPS login form is verified, and the correction is the input the desk recommends reading.

How to read a password reset link you have never seen before

A new password reset link is a link the desk has not covered. The desk's reading of a new password reset link is conservative: read the sender domain, read the destination URL, and read the certificate. The three reads are the inputs the desk recommends, and the inputs are the difference between a guess and a bet. The desk does not publish a hot take on a new password reset link, and the desk does not recommend a specific platform without the three reads. The reason is the same: a hot take is a guess, and a guess is not the product.

How the desk handles a login flow on a day with no matches

The desk does not publish a login update on a day with no matches. The desk's reading of a no-match day is conservative: read the corrections log, read the editorial policy, and read the responsible-play page. The three reads are the inputs the desk recommends, and the inputs are the difference between a guess and a bet. The desk does not publish a hot take on a no-match day, and the desk does not recommend a specific login flow. The reason is the same: a hot take is a guess, and a guess is not the product.

How to read a login form that loads slowly

A login form that loads slowly is a signal to slow down, not a signal to dismiss. The desk's reading of a slow-loading login form is conservative: read the URL, read the certificate, and read the publisher name. The three reads are the inputs the desk recommends, and the inputs are the difference between a guess and a bet. The desk publishes a correction when a slow-loading login form is verified, and the correction is the input the desk recommends reading.

How the desk handles a login form that requires JavaScript

A login form that requires JavaScript is a public document, and the public document is the source of truth. The desk's reading of a JavaScript-required login form is conservative: read the form, read the publisher name, and read the privacy policy. The three reads are the inputs the desk recommends, and the inputs are the difference between a guess and a bet. The desk does not publish a hot take on a JavaScript-required login form, and the desk does not recommend a specific platform without the three reads. The reason is the same: a hot take is a guess, and a guess is not the product.

How to read a login form that uses a third-party identity provider

A login form that uses a third-party identity provider is a public document, and the public document is the source of truth. The desk's reading of a third-party-login form is conservative: read the provider name, read the publisher name, and read the privacy policy. The three reads are the inputs the desk recommends, and the inputs are the difference between a guess and a bet. The desk does not publish a hot take on a third-party-login form, and the desk does not recommend a specific platform without the three reads. The reason is the same: a hot take is a guess, and a guess is not the product.

How the desk handles a login form that does not support two-factor authentication

A login form that does not support two-factor authentication is a signal to slow down, not a signal to dismiss. The desk's reading of a no-2FA login form is conservative: read the form, compare the form to the inputs the desk recommends, and read the corrections log. The three reads are the inputs the desk recommends, and the inputs are the difference between a guess and a bet. The desk publishes a correction when a no-2FA login form is verified, and the correction is the input the desk recommends reading.

How to read a login form that asks for a phone number

A login form that asks for a phone number is a signal to slow down, not a signal to dismiss. The desk's reading of a phone-requesting login form is conservative: read the form, read the privacy policy, and read the publisher name. The three reads are the inputs the desk recommends, and the inputs are the difference between a guess and a bet. The desk publishes a correction when a phone-requesting login form is verified, and the correction is the input the desk recommends reading.

How the desk handles a login flow on a day with no matches

The desk does not publish a login update on a day with no matches. The desk's reading of a no-match day is conservative: read the corrections log, read the editorial policy, and read the responsible-play page. The three reads are the inputs the desk recommends, and the inputs are the difference between a guess and a bet. The desk does not publish a hot take on a no-match day, and the desk does not recommend a specific login flow. The reason is the same: a hot take is a guess, and a guess is not the product.

Ready to start your first lineup?Open the checklist on a verified partner page.