Interfaces
The typography of expiring passwords
The password reset email is a genre. It has fonts, tones, a rhythm. Almost nobody designs it on purpose.
There is a specific font, used by a specific default email template, that I now associate more with panic than with any other single thing on the internet. It is the plain sans-serif that comes standard with a certain kind of transactional email service. When I see it in my inbox, I know, before I read anything, that something has expired.
Password reset emails are a genre in the strictest sense: they have conventions, expectations, a set of moves. They open with a version of 'we noticed a login attempt', they contain a button that is always the same colour, they end with a version of 'if this wasn't you, please contact support'. They are written by templates written by templates, and almost nobody in the chain has read the whole thing.
This is not usually a problem, because most people don't read these emails either. They click the button, or they don't. The words are decoration around a single action. But when a password reset email is the first email a person receives from a company — as it often is — it becomes, whether the company meant it to or not, an introduction. What kind of company you seem to be is decided, quietly, by a template.
There is a particular tension in the genre that most templates fumble. A reset email has to be reassuring and alarming at once: reassuring, because you probably did ask for it; alarming, because if you didn't, this is the moment you need to act. The default templates resolve the tension by feeling like nothing at all — a flat, affectless grey that is neither warm enough to trust nor urgent enough to heed. They split the difference and land on beige.
You can tell how much a company respects its own security posture by how it writes the sentence that begins 'if this wasn't you.' The lazy version buries it at the bottom in the same weight as everything else. The thoughtful version treats it as the most important line in the email, because for the small fraction of readers it applies to, it is. That single editorial decision — what to emphasise — is worth more than any amount of visual polish.
The best password reset emails I've seen are the ones that lightly break the genre. They use the company's actual typography. They speak in a version of the company's actual voice. They admit, without pretending otherwise, that this email is a security-related interruption in the person's day. This is a small amount of design work. It costs almost nothing. Almost nobody does it.
The reason almost nobody does it is structural. Transactional email lives in a seam between teams: too technical for marketing, too unglamorous for product, too rare to show up in anyone's dashboard. It is sent by a system, configured once, and then forgotten, which is exactly how you end up with a company's first impression being authored by a default nobody chose.
I have come to think of these forgotten surfaces — the reset email, the receipt, the account-deletion confirmation — as a kind of honesty test. Anyone can make the marketing site warm. The question is whether the warmth survives into the moments when nobody is watching the funnel, when the only person on the other end is someone with a problem. That is where a company's actual manners live.
I bring this up because password resets are not going away, and because they are one of the small honest moments when a company can behave like a company that thinks about the person on the other end. It is a low bar. It is worth clearing.