<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security on WebNotes</title><link>https://v2.webnotes.in/categories/security/</link><description>Recent content in Security on WebNotes</description><generator>Hugo</generator><language>en-IN</language><lastBuildDate>Sat, 20 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://v2.webnotes.in/categories/security/index.xml" rel="self" type="application/rss+xml"/><item><title>Does Zerodha solicit fund transfers to personal accounts?</title><link>https://v2.webnotes.in/does-zerodha-solicit-fund-transfers/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/does-zerodha-solicit-fund-transfers/</guid><description>&lt;p&gt;&lt;strong&gt;Zerodha does not solicit fund transfers to personal or third-party accounts.&lt;/strong&gt; Client money moves in only one sanctioned path: from your own registered bank account or &lt;a href="https://v2.webnotes.in/how-to-add-funds-zerodha-upi/"&gt;UPI&lt;/a&gt;
 into Zerodha&amp;rsquo;s regulated client-funds pool account, never to an individual&amp;rsquo;s account, and Zerodha never asks you to transfer money to provide support, to unblock an account, or to release a payout. Any request to send money to a personal or third-party account in Zerodha&amp;rsquo;s name is fraud, not a Zerodha process, and the regulatory architecture of client funds is built precisely to make the legitimate path the only path money can take.&lt;/p&gt;</description></item><item><title>How to change your Zerodha user ID</title><link>https://v2.webnotes.in/how-to-change-user-id-zerodha/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-change-user-id-zerodha/</guid><description>&lt;p&gt;&lt;strong&gt;No, you cannot change your Zerodha user ID.&lt;/strong&gt; Zerodha&amp;rsquo;s own help desk states it plainly: you cannot change or customise your user ID, because it is registered on the exchange to track all your transactions, which makes it permanent and unchangeable. The 12-character &lt;a href="https://v2.webnotes.in/zerodha-12-character-user-id-format/"&gt;user ID&lt;/a&gt;
, the code such as AB1234 that identifies your account, is not an editable profile field like your email or mobile. It is an exchange-level identifier tied to every trade you have placed. This guide explains why it is fixed, what you can change instead, and how to recover a forgotten ID, which is the real need behind most searches to &amp;ldquo;change&amp;rdquo; one.&lt;/p&gt;</description></item><item><title>How to disable TOTP on Zerodha Kite</title><link>https://v2.webnotes.in/how-to-disable-totp-zerodha/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-disable-totp-zerodha/</guid><description>&lt;p&gt;&lt;strong&gt;To disable TOTP on &lt;a href="https://v2.webnotes.in/zerodha/"&gt;Zerodha&lt;/a&gt;
 &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
, log in, open My profile then Password &amp;amp; security, click Disable external TOTP, enter your Kite login password, and click Disable; the account then reverts to the &lt;a href="https://v2.webnotes.in/sms-otp/" rel="nofollow"&gt;SMS OTP&lt;/a&gt;
 as its second factor.&lt;/strong&gt; You cannot switch the second factor off entirely, because two-factor authentication on a trading login is mandated by the exchanges and SEBI.&lt;/p&gt;
&lt;p&gt;This is the point most people miss. &amp;ldquo;Disable TOTP&amp;rdquo; does not mean &amp;ldquo;log in with just a password.&amp;rdquo; It means swap the time-based app code back for the text-message code. One second factor always remains. Zerodha&amp;rsquo;s support pages are explicit that the OTP step at login cannot be eliminated, only changed in form.&lt;/p&gt;</description></item><item><title>How to enable biometric login on Kite (Touch ID, Face ID, fingerprint)</title><link>https://v2.webnotes.in/how-to-enable-biometric-kite/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-enable-biometric-kite/</guid><description>&lt;p&gt;Biometric login on &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
 uses your phone&amp;rsquo;s own fingerprint, Touch ID, or Face ID, registered in your operating-system settings, which Kite invokes as device lock at login. It is the second authentication factor for the Kite app, mandatory since 23 September 2022, and the biometric never leaves your phone: Zerodha does not store your fingerprint or face data, it asks the OS to confirm an unlock and receives only a pass or fail. If the scan fails, your phone&amp;rsquo;s PIN, pattern, or passcode is the fallback.&lt;/p&gt;</description></item><item><title>How to enable device lock on the Kite app</title><link>https://v2.webnotes.in/how-to-enable-device-lock-kite/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-enable-device-lock-kite/</guid><description>&lt;p&gt;Device lock on the &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
 app is your phone&amp;rsquo;s own screen lock, a PIN, pattern, fingerprint, or Face ID, that Kite uses as the second authentication factor when you log in. It is not a separate code you type into the app and it is not optional: device lock for Kite app login has been mandatory since 23 September 2022, because it satisfies the requirement set by the Securities and Exchange Board of India (&lt;a href="https://v2.webnotes.in/sebi/"&gt;SEBI&lt;/a&gt;
) for two-factor authentication (2FA) on trading-app login. Your lock data stays on your phone; Zerodha does not store it.&lt;/p&gt;</description></item><item><title>How to fix Kite logging out when switching apps</title><link>https://v2.webnotes.in/how-to-fix-kite-logout-switching-apps/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-fix-kite-logout-switching-apps/</guid><description>&lt;p&gt;The &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
 app logs you out when you switch to another app, such as an authenticator app to copy a time-based one-time password (TOTP), because your device is in power-saving mode or is preventing Kite from running in the background; the operating system kills the backgrounded app and drops your session. Per Zerodha&amp;rsquo;s own support article, this is a power-management behaviour, not a deliberate security lock that triggers on app switch. The fix is to stop the OS from suspending Kite: turn off power saving, exempt Kite from battery optimisation, or sidestep the switch entirely by using device-lock biometric login instead of TOTP.&lt;/p&gt;</description></item><item><title>How to fix not receiving emails from Zerodha</title><link>https://v2.webnotes.in/how-to-fix-not-receiving-zerodha-emails/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-fix-not-receiving-zerodha-emails/</guid><description>&lt;p&gt;If you are not receiving emails from Zerodha, the cause is almost always on the delivery side, not Zerodha&amp;rsquo;s: the mail is in a spam, junk, promotions or archived folder; your email domain (often an office domain) is blocking it; your inbox is full; a forwarding rule is diverting it; or your registered email is wrong or outdated. Zerodha sends few emails by design, so a quiet inbox is sometimes normal, but a genuinely missing statement or alert is usually one of these fixable causes.&lt;/p&gt;</description></item><item><title>How to fix the Invalid TOTP error on Zerodha Kite</title><link>https://v2.webnotes.in/how-to-fix-invalid-totp-zerodha/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-fix-invalid-totp-zerodha/</guid><description>&lt;p&gt;&lt;strong&gt;The Invalid TOTP error on &lt;a href="https://v2.webnotes.in/zerodha/"&gt;Zerodha&lt;/a&gt;
 &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
 is a clock problem, not a wrong code: Kite rejects the &lt;a href="https://v2.webnotes.in/how-to-set-up-totp-zerodha/"&gt;TOTP&lt;/a&gt;
 when the clock on the device running your authenticator does not match network time, so set that phone to automatic or network-provided time and enter a fresh six-digit code.&lt;/strong&gt; TOTP is time-based; a drift of even a minute makes the app compute the code for the wrong 30-second window, and Kite refuses it.&lt;/p&gt;
&lt;p&gt;This is the single most common cause, and it is also the least obvious one, because the code on screen looks perfectly valid. It is valid, for a moment that has already passed or not yet arrived. The fix is to correct the clock on the device that generates the code, which is the phone holding Google Authenticator or Authy, not the computer you are logging in from.&lt;/p&gt;</description></item><item><title>How to freeze and unfreeze your Zerodha demat account</title><link>https://v2.webnotes.in/how-to-freeze-unfreeze-demat-zerodha/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-freeze-unfreeze-demat-zerodha/</guid><description>&lt;p&gt;You can voluntarily freeze your own &lt;a href="https://v2.webnotes.in/zerodha/"&gt;Zerodha&lt;/a&gt;
 &lt;a href="https://v2.webnotes.in/demat-account/"&gt;demat account&lt;/a&gt;
, or specific securities within it, against debit, credit, or both, using the &lt;a href="https://v2.webnotes.in/cdsl/"&gt;CDSL&lt;/a&gt;
 freeze facility. A debit freeze stops the holdings being sold or transferred out, which makes it a direct defence against an unauthorised sale if your login is ever compromised. You execute the freeze by submitting the CDSL freeze/unfreeze request form to Zerodha, eSigned and raised through a &lt;a href="https://v2.webnotes.in/how-to-create-ticket-zerodha/"&gt;support ticket&lt;/a&gt;
; CDSL processes it within 72 working hours and charges nothing.&lt;/p&gt;</description></item><item><title>How to log in to Zerodha Console</title><link>https://v2.webnotes.in/how-to-login-zerodha-console/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-login-zerodha-console/</guid><description>&lt;p&gt;&lt;strong&gt;Zerodha Console is the broker&amp;rsquo;s reporting and back-office platform at console.zerodha.com, and you log in to it with your Kite credentials by clicking Login with Kite.&lt;/strong&gt; Console has no username or password of its own. It authenticates every client through the same &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
 login system, using the same 12-character &lt;a href="https://v2.webnotes.in/zerodha-12-character-user-id-format/"&gt;user ID&lt;/a&gt;
, the same password, and the same second factor. This guide covers the exact login flow, why Console and Kite share one credential set, and the access problems that send people looking for help.&lt;/p&gt;</description></item><item><title>How to log in to Zerodha when your mobile is lost</title><link>https://v2.webnotes.in/how-to-login-mobile-lost-zerodha/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-login-mobile-lost-zerodha/</guid><description>&lt;p&gt;&lt;strong&gt;If your registered mobile is lost, you regain Kite access by switching your second factor from SMS OTP to a TOTP authenticator app, which generates the 6-digit login code on any device without an SMS.&lt;/strong&gt; SMS-based two-factor authentication depends on the SIM in your hand; a lost phone breaks it. The fix is a &lt;a href="https://v2.webnotes.in/kite-app-code/"&gt;TOTP authenticator&lt;/a&gt;
, set up during a password reset that you verify by email rather than SMS. This guide walks that reset-and-switch flow, the change-of-mobile route to restore your number, and the harder case where both your mobile and email are gone.&lt;/p&gt;</description></item><item><title>How to recover a forgotten Kite PIN</title><link>https://v2.webnotes.in/how-to-recover-kite-pin/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-recover-kite-pin/</guid><description>&lt;p&gt;&lt;strong&gt;The Kite PIN is the 6-digit second factor you enter after your password, and you reset a forgotten one through the Forgot user ID or password flow on kite.zerodha.com.&lt;/strong&gt; There is no separate Forgot PIN button, because the PIN is part of your login credentials, not a standalone code. Resetting it routes through the same screen that resets the password: user ID, PAN, an OTP on email or SMS, then a new password and a new PIN set together. This guide walks that reset, explains how the PIN relates to the full login, and covers the switch to a &lt;a href="https://v2.webnotes.in/kite-app-code/"&gt;TOTP authenticator&lt;/a&gt;
 if you would rather not memorise a PIN at all.&lt;/p&gt;</description></item><item><title>How to recover a lost TOTP on Zerodha Kite</title><link>https://v2.webnotes.in/how-to-recover-lost-totp-zerodha/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-recover-lost-totp-zerodha/</guid><description>&lt;p&gt;&lt;strong&gt;If you lost the phone holding your authenticator, deleted the app, or wiped the device, recover access on &lt;a href="https://v2.webnotes.in/zerodha/"&gt;Zerodha&lt;/a&gt;
 &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
 by clicking Forgot user ID or password? on the login page; verify with your user ID, PAN, and an OTP to your registered email or mobile, set a new password, then re-enrol TOTP under Method 2: External authenticator and scan a fresh QR code.&lt;/strong&gt; The standard reset is self-service and free; no support ticket is needed unless you have also lost access to both your registered email and mobile.&lt;/p&gt;</description></item><item><title>How to remove the temporary OTP on Kite</title><link>https://v2.webnotes.in/how-to-remove-temporary-otp-kite/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-remove-temporary-otp-kite/</guid><description>&lt;p&gt;&lt;strong&gt;You cannot remove the temporary OTP step on &lt;a href="https://v2.webnotes.in/zerodha/"&gt;Zerodha&lt;/a&gt;
 &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
, because NSE and &lt;a href="https://v2.webnotes.in/sebi/"&gt;SEBI&lt;/a&gt;
 require a second authentication factor on every trading login; what you can do is switch the temporary OTP from an SMS-delivered code to an authenticator-generated &lt;a href="https://v2.webnotes.in/how-to-set-up-totp-zerodha/"&gt;TOTP&lt;/a&gt;
, under My profile then Password &amp;amp; security.&lt;/strong&gt; The OTP step itself is mandatory and stays; only its form is yours to choose.&lt;/p&gt;
&lt;p&gt;The phrase &amp;ldquo;temporary OTP&amp;rdquo; describes the time-limited one-time password Kite asks for after your password at each login. It is temporary in the literal sense: each code is valid for a short window, about 30 seconds for an authenticator code, then expires. People searching to &amp;ldquo;remove&amp;rdquo; it usually mean one of two things: they want to stop the SMS-delivered OTP and use something smoother, or Zerodha issued them a one-off temporary access after a lockout and they want to know how to get back to a normal login. This guide covers both.&lt;/p&gt;</description></item><item><title>How to reset the Zerodha support code (ZPin)</title><link>https://v2.webnotes.in/how-to-reset-zpin-zerodha/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-reset-zpin-zerodha/</guid><description>&lt;p&gt;The Zerodha support code, which Zerodha also labels the &lt;strong&gt;ZPin&lt;/strong&gt; or telephone code, is a four-digit identifier that the interactive voice response (IVR) system asks for to authenticate you before it connects your call to a &lt;a href="https://v2.webnotes.in/zerodha/"&gt;Zerodha&lt;/a&gt;
 support agent. You did not choose it and it is not a login credential. It does one job: it proves the caller is the account holder when the call comes from a number that is not registered on the account. You reset it through &lt;a href="https://v2.webnotes.in/zerodha-console/"&gt;Console&lt;/a&gt;
 after a one-time-password (OTP) check, and you can view it any time in the &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
 app, Kite web, or Console.&lt;/p&gt;</description></item><item><title>How to respond to a Zerodha email asking you to authorise your holdings</title><link>https://v2.webnotes.in/how-to-authorise-holdings-email-zerodha/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-authorise-holdings-email-zerodha/</guid><description>&lt;p&gt;A Zerodha email asking you to authorise your holdings means you sold securities from your &lt;a href="https://v2.webnotes.in/demat-account/"&gt;demat account&lt;/a&gt;
 without a standing &lt;a href="https://v2.webnotes.in/how-to-sign-ddpi-zerodha/"&gt;DDPI&lt;/a&gt;
 or POA, so the sale needs your explicit &lt;a href="https://v2.webnotes.in/cdsl/"&gt;CDSL&lt;/a&gt;
 authorisation before it can settle; you complete it with your CDSL TPIN through the link in the email, before 7:00 PM the same day. This is not a security alert or a problem with your account. It is the depository asking you to approve a specific debit of your own shares, which is required precisely because you have not given the broker a standing instruction to do it for you.&lt;/p&gt;</description></item><item><title>How to respond to an additional-documents email from Zerodha</title><link>https://v2.webnotes.in/how-to-respond-additional-documents-email-zerodha/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-respond-additional-documents-email-zerodha/</guid><description>&lt;p&gt;If Zerodha emails you asking for additional documents during onboarding or &lt;a href="https://v2.webnotes.in/how-to-re-kyc-zerodha/"&gt;re-KYC&lt;/a&gt;
, the safe response is to verify the email is genuine first, then upload the document only through your own Zerodha login at support.zerodha.com or signup.zerodha.com/rekyc, never through a link in the email, an SMS or a WhatsApp message. A genuine request always corresponds to a pending item visible inside your own logged-in account; if the demand exists only in the email, treat it as phishing.&lt;/p&gt;</description></item><item><title>How to revoke connected apps on Kite</title><link>https://v2.webnotes.in/how-to-revoke-kite-connected-apps/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-revoke-kite-connected-apps/</guid><description>&lt;p&gt;Revoking a &lt;strong&gt;connected app on Kite&lt;/strong&gt; removes a third-party platform&amp;rsquo;s standing permission to access your &lt;a href="https://v2.webnotes.in/zerodha/"&gt;Zerodha&lt;/a&gt;
 account. On &lt;a href="https://v2.webnotes.in/kite-web/"&gt;Kite web&lt;/a&gt;
 you click your client ID, then My Profile, then Apps, then Revoke against the app; on the &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite app&lt;/a&gt;
 you tap your client ID, then Connected Apps, then the app, then Revoke. The action removes that app&amp;rsquo;s permission to access your trading data and account information, so a platform like &lt;a href="https://v2.webnotes.in/sensibull/"&gt;Sensibull&lt;/a&gt;
, &lt;a href="https://v2.webnotes.in/smallcase/"&gt;smallcase&lt;/a&gt;
 or &lt;a href="https://v2.webnotes.in/streak/" rel="nofollow"&gt;Streak&lt;/a&gt;
 can no longer read your holdings or place orders until you authorise it again.&lt;/p&gt;</description></item><item><title>How to secure an Indian trading and demat account: best practices</title><link>https://v2.webnotes.in/how-to-secure-trading-account/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-secure-trading-account/</guid><description>&lt;p&gt;Securing an Indian trading and demat account comes down to a few controls that block the routes attackers actually use: a strong, offline second login factor, clean device habits, a refusal to enter credentials on pages or calls you did not initiate, a scope-limited &lt;a href="https://v2.webnotes.in/poa-to-ddpi-transition/"&gt;DDPI&lt;/a&gt;
 rather than an open-ended power of attorney, and regular monitoring through &lt;a href="https://v2.webnotes.in/zerodha-console/"&gt;Zerodha Console&lt;/a&gt;
 so an unauthorised move shows up early. None of these is exotic; the gap is that most accounts run on the weakest available option for each.&lt;/p&gt;</description></item><item><title>How to set up TOTP on Zerodha Kite</title><link>https://v2.webnotes.in/how-to-set-up-totp-zerodha/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-set-up-totp-zerodha/</guid><description>&lt;p&gt;&lt;strong&gt;TOTP, or time-based one-time password, is a six-digit code that an authenticator app on your phone generates offline and refreshes every 30 seconds; on &lt;a href="https://v2.webnotes.in/zerodha/"&gt;Zerodha&lt;/a&gt;
 &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
 you enable it under My profile, Password &amp;amp; security, Enable external TOTP, then scan a QR code with &lt;a href="https://v2.webnotes.in/google-authenticator/" rel="nofollow"&gt;Google Authenticator&lt;/a&gt;
 or &lt;a href="https://v2.webnotes.in/authy/" rel="nofollow"&gt;Authy&lt;/a&gt;
 so the rolling app code becomes your second login factor in place of the SMS OTP.&lt;/strong&gt; Setting it up takes about five minutes and costs nothing.&lt;/p&gt;</description></item><item><title>How to set up your password on Zerodha</title><link>https://v2.webnotes.in/how-to-set-up-password-zerodha/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-set-up-password-zerodha/</guid><description>&lt;p&gt;&lt;strong&gt;Zerodha never sends you a ready-made password.&lt;/strong&gt; When your account opens, the welcome email from &lt;a href="mailto:welcome@zerodha.com"&gt;welcome@zerodha.com&lt;/a&gt;
 carries your 12-character &lt;a href="https://v2.webnotes.in/zerodha-12-character-user-id-format/"&gt;user ID&lt;/a&gt;
 and a link to set the password yourself, nothing more. The absence of a password in that email is the design, not a delivery failure. This guide walks the first-login setup: opening the welcome email, creating the password, and configuring the 6-digit PIN or TOTP authenticator that the SEBI two-factor rule makes compulsory on every &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
 login.&lt;/p&gt;</description></item><item><title>How to stop unsolicited stock-tip SMS and report them</title><link>https://v2.webnotes.in/how-to-stop-stock-tip-sms-zerodha/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-stop-stock-tip-sms-zerodha/</guid><description>&lt;p&gt;Unsolicited stock-tip and guaranteed-return SMS are stopped through TRAI&amp;rsquo;s Do Not Disturb framework, reported to TRAI on 1909, and, where they offer investment advice, complained about to SEBI on &lt;a href="https://v2.webnotes.in/zerodha-scores/"&gt;SCORES&lt;/a&gt;
. The first thing to be clear on: &lt;a href="https://v2.webnotes.in/zerodha/"&gt;Zerodha&lt;/a&gt;
 does not send stock tips. It provides no advisory service, so a tip SMS or a guaranteed-return message that uses Zerodha&amp;rsquo;s name is impersonation or unrelated spam, never a genuine Zerodha communication, and acting on it is the start of a scam, not a trade.&lt;/p&gt;</description></item><item><title>How to unblock a blocked Kite account</title><link>https://v2.webnotes.in/how-to-unblock-kite-account/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-unblock-kite-account/</guid><description>&lt;p&gt;&lt;strong&gt;Kite blocks your account after five incorrect password attempts, and the block clears only when you reset your login credentials; there is no separate unblock button.&lt;/strong&gt; Completing the Forgot user ID or password flow sets a new password and unblocks the account automatically. The same applies to a block from repeated incorrect &lt;a href="https://v2.webnotes.in/why-risk-disclosure-every-login-kite/"&gt;two-factor authentication&lt;/a&gt;
 entries. This guide walks the reset-to-unblock flow, and separates it from two states people confuse with a login block: account dormancy, and a risk-management or suspicious-activity freeze, each of which has a different fix.&lt;/p&gt;</description></item><item><title>How to verify a call or SMS claiming to be from Zerodha</title><link>https://v2.webnotes.in/how-to-verify-zerodha-call/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-verify-zerodha-call/</guid><description>&lt;p&gt;To verify whether a call, SMS, or person claiming to be from &lt;a href="https://v2.webnotes.in/zerodha/"&gt;Zerodha&lt;/a&gt;
 is genuine, match the calling number against Zerodha&amp;rsquo;s official published contact list on support.zerodha.com; Zerodha&amp;rsquo;s genuine calls come only from that list of registered numbers, and a number outside it is not Zerodha. Layer on a behavioural test that does not depend on the number at all: Zerodha staff never ask for your OTP, password, PIN, or KYC documents, never ask you to transfer funds, and never give stock tips over the phone. A caller doing any of these is an impostor regardless of the number on your screen.&lt;/p&gt;</description></item><item><title>How to verify whether an email is genuinely from Zerodha</title><link>https://v2.webnotes.in/how-to-verify-zerodha-email/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/how-to-verify-zerodha-email/</guid><description>&lt;p&gt;An email is genuinely from Zerodha only if its sender domain is &lt;strong&gt;zerodha.com&lt;/strong&gt; or one of the ten mailer subdomains Zerodha publishes on its verify-genuine-email support page, and even a genuine email never asks for your password, OTP or PIN. The sender domain, the part of the address after the @ sign, is the one signal a fraudster cannot fake past your email provider&amp;rsquo;s authentication checks. The logo, the formatting, the tone, the client ID in the body: all of these are copied from real emails and prove nothing.&lt;/p&gt;</description></item><item><title>Kite app code vs external TOTP vs SMS OTP: which second factor to use</title><link>https://v2.webnotes.in/kite-app-code-totp-vs-sms-otp/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/kite-app-code-totp-vs-sms-otp/</guid><description>&lt;p&gt;Kite offers three ways to satisfy the second factor of a two-factor login: the in-app &lt;strong&gt;app code&lt;/strong&gt;, an external authenticator &lt;strong&gt;TOTP&lt;/strong&gt;, and &lt;strong&gt;SMS OTP&lt;/strong&gt;. An external authenticator TOTP is the most secure and most reliable of the three, because it computes codes offline, removes the SIM and the telecom network from the attack surface, and lets you log in to &lt;a href="https://v2.webnotes.in/kite-web/"&gt;Kite web&lt;/a&gt;
 without opening the &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
 mobile app. The in-app app code is a solid default; SMS OTP is the weakest link and is best treated as a fallback only.&lt;/p&gt;</description></item><item><title>Kite app code: what it is and how it works as a login factor</title><link>https://v2.webnotes.in/kite-app-code/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/kite-app-code/</guid><description>&lt;p&gt;The &lt;strong&gt;Kite app code&lt;/strong&gt; is a six-digit time-based one-time password (TOTP) generated inside Zerodha&amp;rsquo;s &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
 mobile app that you type into &lt;a href="https://v2.webnotes.in/kite-web/"&gt;Kite web&lt;/a&gt;
 as the second factor of a two-factor login. After you enter your user ID and password on Kite web, the app shows a code that is valid for 30 seconds; entering it completes the login. Zerodha documents this as the default second factor for clients who have the Kite mobile app and have not switched to an external authenticator.&lt;/p&gt;</description></item><item><title>Why Zerodha blocks Rediffmail email IDs</title><link>https://v2.webnotes.in/zerodha-rediffmail-blocked/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/zerodha-rediffmail-blocked/</guid><description>&lt;p&gt;Zerodha restricts Rediffmail email IDs for two documented reasons: it has observed an increase in cyberattacks targeting Rediffmail accounts, and emails it sends are frequently not delivered to Rediffmail addresses. Because every contract note, statement, OTP and alert reaches you by email, a provider that drops or bounces those messages is a compliance and security problem, not a minor inconvenience. New registrations on Rediffmail are not accepted, and existing Rediffmail accounts are blocked from resetting the &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
 password by email.&lt;/p&gt;</description></item><item><title>Zerodha client password and credential policy</title><link>https://v2.webnotes.in/zerodha-client-password-policy/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/zerodha-client-password-policy/</guid><description>&lt;p&gt;&lt;strong&gt;Zerodha&amp;rsquo;s client password and credential policy&lt;/strong&gt; sets no password in the account-opening welcome email; the client creates the password at first login, and a mandatory second factor, the Kite App Code or an external time-based one-time password (TOTP), sits on top of it under the cyber-security framework SEBI mandated in its circular of 3 December 2018, enforced across brokers from 30 September 2022. The login is therefore two factors deep by design, and the account holder, not the broker, carries the loss from any credential misuse.&lt;/p&gt;</description></item><item><title>Zerodha email: your registered mobile number is blocked</title><link>https://v2.webnotes.in/zerodha-mobile-number-blocked-email/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/zerodha-mobile-number-blocked-email/</guid><description>&lt;p&gt;A Zerodha email stating that your registered mobile number is blocked means the number appears on the Telecom Regulatory Authority of India (TRAI) list of inactive or disconnected numbers. SEBI requires every &lt;a href="https://v2.webnotes.in/demat-account/"&gt;demat account&lt;/a&gt;
 to carry an active mobile number so that one-time passwords and trade alerts reach only the account holder, and Zerodha sends this notice so you update the number before communications start failing. It is a security and compliance message, not a marketing email.&lt;/p&gt;</description></item><item><title>Zerodha IP address shared alert</title><link>https://v2.webnotes.in/zerodha-ip-shared-alert/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/zerodha-ip-shared-alert/</guid><description>&lt;p&gt;The &lt;strong&gt;Zerodha IP address shared alert&lt;/strong&gt; is an email Zerodha sends when two or more Zerodha accounts log in from the same device or network and therefore share a single public IP address. Zerodha sends it because, under an &lt;a href="https://v2.webnotes.in/national-stock-exchange/"&gt;NSE&lt;/a&gt;
 compliance rule, brokers capture and report client IP addresses for security and surveillance, and a common IP across accounts is something the broker has to explain to the exchange. The alert asks you to clarify why the accounts share the address; it is a question, not a verdict.&lt;/p&gt;</description></item><item><title>Zerodha login from a different city alert</title><link>https://v2.webnotes.in/zerodha-login-different-city-alert/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/zerodha-login-different-city-alert/</guid><description>&lt;p&gt;The &lt;strong&gt;Zerodha login from a different city alert&lt;/strong&gt; is an email, accompanied by a Kite app notification, that Zerodha sends when you log in to &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
 from a city or IP address it has not seen on your account before. Zerodha judges location from the IP address of the login request, not from your physical position, so the alert is a prompt to confirm the login was yours, not a statement that someone has broken in. The decision you have to make on receiving it is binary: do you recognise this login, or not?&lt;/p&gt;</description></item><item><title>Zerodha multiple incorrect 2FA notification</title><link>https://v2.webnotes.in/zerodha-multiple-incorrect-2fa-notification/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/zerodha-multiple-incorrect-2fa-notification/</guid><description>&lt;p&gt;The &lt;strong&gt;Zerodha multiple incorrect 2FA notification&lt;/strong&gt; is an alert sent to your registered email and current device when several wrong two-factor authentication entries are made on your &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
 login, and the account is blocked after 5 incorrect 2FA entries. The notification warns that the 2FA was entered incorrectly and that your password may be compromised, because whoever was entering the 2FA had already cleared the password stage to reach it. If you made the failed attempts yourself, a credential reset restores access; if you did not, the alert is telling you someone else got as far as your second factor.&lt;/p&gt;</description></item><item><title>Zerodha new device login notification</title><link>https://v2.webnotes.in/zerodha-new-device-login-notification/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/zerodha-new-device-login-notification/</guid><description>&lt;p&gt;The &lt;strong&gt;Zerodha new device login notification&lt;/strong&gt; is an alert sent to your registered email and your current device the moment your correct &lt;a href="https://v2.webnotes.in/kite-zerodha/"&gt;Kite&lt;/a&gt;
 password is entered on a device Zerodha has not seen before, sent before two-factor authentication is completed. It tells you that your login credentials have been entered on a new device, so you can confirm the login was yours or act quickly if it was not. The notification keys on the device, which is what separates it from the &lt;a href="https://v2.webnotes.in/zerodha-login-different-city-alert/"&gt;login-from-a-different-city alert&lt;/a&gt;
 that keys on IP location.&lt;/p&gt;</description></item><item><title>Zerodha official social media handles and how to spot fakes</title><link>https://v2.webnotes.in/zerodha-official-social-media-handles/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/zerodha-official-social-media-handles/</guid><description>&lt;p&gt;&lt;strong&gt;Zerodha&lt;/strong&gt; maintains a published set of official social media handles and domains, fronted by the support handle &lt;a href="https://twitter.com/zerodhaonline"&gt;@zerodhaonline&lt;/a&gt;
 on X and the website &lt;a href="https://v2.webnotes.in/zerodha/"&gt;zerodha.com&lt;/a&gt;
, against which any account, message, or link claiming to be from Zerodha can be checked. Zerodha Broking Limited is a SEBI-registered stock broker (SEBI registration INZ000031633), and any handle, group, or app outside its published list, especially one offering tips, guaranteed returns, advisory, or asking for money, is not Zerodha.&lt;/p&gt;</description></item><item><title>Zerodha trade SMS and email alerts from the exchanges</title><link>https://v2.webnotes.in/zerodha-trade-sms-alerts/</link><pubDate>Sat, 20 Jun 2026 00:00:00 +0000</pubDate><guid>https://v2.webnotes.in/zerodha-trade-sms-alerts/</guid><description>&lt;p&gt;&lt;strong&gt;Zerodha trade SMS and email alerts&lt;/strong&gt; are messages that the stock exchanges, &lt;a href="https://v2.webnotes.in/national-stock-exchange/"&gt;National Stock Exchange&lt;/a&gt;
, &lt;a href="https://v2.webnotes.in/bombay-stock-exchange/"&gt;Bombay Stock Exchange&lt;/a&gt;
 and MCX, send directly to a retail client on every day that client trades, as a &lt;a href="https://v2.webnotes.in/sebi/"&gt;SEBI&lt;/a&gt;
 investor-protection measure to flag unauthorised trades in the account. The broker does not send them; the exchange does, using the mobile number and email that &lt;a href="https://v2.webnotes.in/zerodha/"&gt;Zerodha&lt;/a&gt;
 reported to it at account opening. The point of the alert is that you read the SMS, recognise every trade in it, and raise an alarm the same day if a trade appears that you never placed.&lt;/p&gt;</description></item></channel></rss>