Rate limiting and excessive account emails

@Imaduffus Welcome to the forum! I want to start by making it clear that I do not work for Bitwarden — I am just a Bitwarden customer, like you (although I volunteer as a moderator on this forum). FYI, Bitwarden staff can be identified by the blue-white shield logo overlaid in the lower right corner of their avatar image (see @dwbit’s profile image for an example).

That does seem “insane”, and may be due to a server-side misconfiguration, if that is what you are seeing. It would suggest that the rate-limit for incorrect login attempts that fail at the 2FA stage is only a 30-second delay, and that the delay is not increased as the number of failed attempts increases.

Could you clarify whether your account is hosted by Bitwarden, or self-hosted? Would you be willing to share a redacted screenshot that shows the time-stamps of at least a handful of consecutive notification emails? Also, can you confirm that your email notices do end with the instruction “If this was not you, you should change your master password immediately”?

1 Like