Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

To stop WordPress from sending the password-reset message generated by the “Lost your password?” form, add this filter in a site-specific plugin or a must-use plugin:

add_filter( 'send_retrieve_password_email', '__return_false' );

This hook is available in WordPress 6.0.0 and later. It prevents the retrieve-password email from being sent, but the reset request can still appear successful to the user.

What this filter disables

send_retrieve_password_email controls whether WordPress sends the retrieve-password email after someone submits the lost-password form. WordPress documents that returning false disables sending.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The rule applies before WordPress generates a password-reset key or composes the message. With the filter active, the normal email-based recovery link is unavailable, even though the form handler may report that the request succeeded.

Install the filter safely

Option 1: Add it to a site-specific plugin

Create a small plugin that is independent of your active theme:

  1. Open wp-content/plugins/ on the site.
  2. Create a PHP file such as disable-lost-password-email.php.
  3. Add this code, including the plugin header:
<?php
/**
 * Plugin Name: Disable Lost Password Emails
 */

add_filter( 'send_retrieve_password_email', '__return_false' );
  1. Upload the file and activate Disable Lost Password Emails under Plugins > Installed Plugins.

Option 2: Use a must-use plugin

For a rule that should always load and not be switchable from the normal Plugins screen, place the same PHP file in wp-content/mu-plugins/. Create that directory if it does not exist. Must-use plugins load automatically, so remove or rename the file to undo the rule.

Why not put it in the theme?

A theme’s functions.php can register the filter, but the behavior disappears when the theme changes or is replaced. A site-specific or must-use plugin keeps this site-level setting separate from presentation code.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What users will experience

  • The lost-password form can still tell the requester that the operation was successful.
  • No password-reset email or reset link is delivered.
  • Users cannot complete the ordinary email-based recovery process while the filter returns false.

Before enabling it on a live site, provide another verified recovery route for administrators and users who may become locked out.

Disable the email only for selected users

The hook accepts the submitted username and a WP_User object. A conditional callback can therefore suppress mail for specific accounts or conditions instead of every reset request.

function my_disable_selected_reset_emails( $send, $user_login, $user ) {
    if ( $user instanceof WP_User && in_array( 'subscriber', (array) $user->roles, true ) ) {
        return false;
    }

    return $send;
}
add_filter( 'send_retrieve_password_email', 'my_disable_selected_reset_emails', 10, 3 );

Test conditional logic against the site’s roles, multisite setup, authentication plugins and account-recovery procedure before deploying it. A global __return_false callback is simpler, but it affects every user.

Rank #4
Teacher Record Book
  • Keep track of everything from attendance to test scores
  • Spiral bound
  • Measures 8-1/2" x 11"
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Do not confuse the reset email with other WordPress emails

The user’s reset-link email

This is the message sent to the person who submits the lost-password form. Use send_retrieve_password_email to decide whether WordPress sends it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Changing the reset email’s contents

retrieve_password_notification_email changes the email arguments, including the recipient, subject, message and headers. It is intended for customizing the message, not as the clearest documented switch for suppressing delivery.

The administrator password-change notification

WordPress also has a separate administrator notification associated with a user’s password being reset. The wp_password_change_notification() path notifies the site administrator and is distinct from the reset link sent to the user. Disabling the user email does not, by itself, disable that administrator notification.

Check your WordPress version

The send_retrieve_password_email hook was introduced in WordPress 6.0.0. On an older installation, do not assume this filter exists; verify the version and the installed core code before relying on it. Updating WordPress may also require compatibility checks with the site’s plugins and theme.

Quick Recap

SaleBestseller No. 1
SaleBestseller No. 3
Bestseller No. 4
Teacher Record Book
Teacher Record Book
Keep track of everything from attendance to test scores; Spiral bound; Measures 8-1/2" x 11"
$4.89

Choose the right approach

Goal Use Result
Stop the reset email for everyone add_filter( 'send_retrieve_password_email', '__return_false' ); Prevents the user-facing retrieve-password email from being sent.
Stop it only for certain users or conditions A callback receiving the filter’s username and WP_User arguments Returns false selectively and preserves the default result otherwise.
Edit recipient, subject, body or headers retrieve_password_notification_email Changes message arguments; it is not the primary documented send/no-send switch.
Control the administrator’s password-change notice The separate administrator-notification path Requires addressing that notification independently; the user-email filter does not cover it.

Test and recover if the setting causes problems

  1. Use a non-administrator test account and submit the site’s Lost your password? form.
  2. Confirm that the request reaches the expected success screen but no reset message arrives.
  3. Verify that your documented alternative recovery method works.
  4. If users need normal recovery again, deactivate the plugin or remove the filter from the must-use plugin.
  5. If only the administrator notice is unwanted, remove this global filter and address that separate notification path instead.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.