Security · Email · Access
Secure a player account and its email access
Account security starts with a unique login, protected email and independent checks of incoming messages. It certifies neither the legality of the offer nor the operator’s safety.

Use a password unique to the account
The CNIL recommends separate passwords for sensitive accounts. A password manager can help create and store different credentials. Avoid personal facts that are easy to guess and do not keep passwords in a document shared with other people.
Enable a second factor where available
Two-factor authentication adds a login check when offered. Keep recovery codes protected and separate from your usual device. Never give a received SMS code to someone contacting you: it might authorise access or a transaction. Check the service’s own recovery process before changing devices.
Protect the email account too
Account recovery may rely on email. Review open sessions, recovery methods and forwarding rules in your mailbox. A strong gambling password helps little if another person can read the messages used to replace it. Treat the recovery channel as part of the same access chain.
Check a request before acting
Open the site using your usual saved address rather than an urgent message link. Confirm the domain, requested operation and case reference with official support. A familiar name, logo or HTTPS lock does not prove the message came from the right organisation.
Prepare for a lost device
Sign out on shared devices and avoid saving passwords there. If a phone is lost, use official procedures to end sessions and replace exposed credentials. Review unusual transactions and preserve references without copying all your secrets into an evidence folder.
Separate security from gambling restrictions
A secure account does not prevent excessive gambling. If access to stakes is the problem, consider limits, closure or an appropriate exclusion measure. Do not retain an active account solely because it has better technical protection. Access security and restricting gambling are different needs.
Practical reference
What each measure protects
No single measure covers every risk.
| Measure | Purpose | Limit |
|---|---|---|
| Unique password | Avoid reuse of compromised credentials | Does not verify the domain |
| Second factor | Add a login check | Codes must not be shared |
| End sessions | Reduce access from a device | May not close the account |
| Exclusion or closure | Restrict participation | Check the service’s scope |
Check the site before securing an account
Technical security does not replace checking the domain and applicable authorisation.
Official sources
Frequently asked questions
Should support know my password?
Do not send a password or login code to someone contacting you. Use the service’s official channel.
Does a second factor make a site lawful?
No. Authentication and regulatory authorisation are separate checks.