Editorial cricket intelligence · Independent reporting desk

Live editorial wire

Login help and account access

A security-first guide to signing in, recovering access and recognising imitation screens on fantasy cricket platforms.

Treat every update as provisional until the playing XI and match conditions agree.

Focus
match desks, score movement and late team news
For
readers who want a fast but measured briefing
Login help and account access — editorial cricket intelligence from COME Sports Guide
COME / DESK LOGIN Evidence before outcome

A measured walk through the login screen, the password reset flow, the OTP message and the imitation pages that occasionally mimic them.

Security baseline

What a safe login screen looks like

The legitimate login screen lives on the official domain, served over HTTPS, with a clear publisher name in the address bar. Before typing anything, look for two small details: a valid TLS certificate (a closed padlock or equivalent) and a publisher name that matches the brand you expect. If the address bar shows a long string of unrelated words or a slightly misspelt brand, stop.

Inside the page, the password field should mask what you type and the OTP field should accept only digits. If the screen asks for your full debit card number, your PIN or your Aadhaar number during a routine login, you are almost certainly on a phishing page. Close the tab and contact customer care through the official channel described further down this page.

Two-factor authentication, when offered, is worth enabling even if it adds a few seconds to the flow. A one-time code sent to your registered mobile is much harder to steal than a password alone. If the platform does not offer 2FA, treat that as a small but real downgrade in the security posture.

Recovery flow

Resetting a password without losing access

The legitimate reset flow begins on the official domain, asks for the registered mobile or email, sends a one-time link or code to the channel you registered, and prompts for a new password only after the code has been verified. Reset codes typically expire within ten minutes.

If you receive a reset code that you did not request, do not click the link. The fact that the code arrived means either someone typed your identifier by mistake or someone tried to access your account. Either way, change your password from a known good device and contact customer care to confirm whether any login was successful.

After a successful reset, the platform should automatically sign out other sessions. If you still see activity that you do not recognise, ask customer care to invalidate all sessions and rotate your session tokens. The customer care desk also documents the correct verification questions to confirm your identity.

Spotting imitations

Common signs of a phishing page

Phishing pages copy the brand colours, the typography and sometimes the URL pattern. They usually add a small twist: an extra hyphen, a country-code top-level domain that is unusual for the brand, or a subdomain that contains the brand name but does not end on it. None of these is conclusive on its own, but together they form a recognisable pattern.

Another sign is urgency. A real login screen does not threaten to delete your account if you do not sign in within the next ten minutes. A phishing page does, because fear reduces careful reading. If the page is asking for an unusual piece of information, treat the request itself as the warning sign.

When in doubt, open a fresh tab and type the official domain yourself. The login link you find in the address bar will take you to the real site even if the one you clicked on did not.

OTP hygiene

Keeping one-time codes safe

Never share the OTP with anyone, including customer care. A legitimate support agent can verify your identity with a few registration details; they never need the live code. If someone claiming to be support asks for the code, hang up.

If the same mobile number receives multiple unexpected OTPs within minutes, treat that as a sign of an attempted takeover. The right response is to change the password, lock the wallet temporarily if the option exists, and contact customer care with the timestamps.

Session safety

Devices, browsers and shared computers

If you sign in on a shared device, log out fully when you finish. Avoid the "remember me" option on a device you do not control. On your own device, keep the operating system and the browser up to date, since security patches often fix credential-stealing bugs.

Public Wi-Fi is convenient but not private. If you must sign in on a public network, prefer the operator's mobile app over the browser, because the app traffic is typically encrypted with certificate pinning. A VPN is another reasonable precaution for routine access.

Account recovery escalation

When self-service is not enough

If the standard reset flow does not work - for example, you no longer have access to the registered mobile - contact customer care with the original registration email, the approximate date of registration, the last successful login timestamp and a clear description of the issue. The agent will walk you through the additional verification required to recover the account safely.

Document every step of the conversation. Save the email confirmation, the ticket number and the agent identifier if one is provided. That record is essential if the recovery process is later reviewed or contested.

Security desk

A few habits that keep your account yours

Short, practical habits that prevent the most common account-takeover patterns on fantasy cricket platforms.

Confirm the domain

The first habit is to type the official domain yourself rather than following a link. The lock icon and the publisher name in the address bar are the cheapest verification you can do.

Use 2FA when offered

A one-time code sent to your registered mobile is harder to steal than a password alone. Two-factor authentication is worth the extra ten seconds at login.

Never share the OTP

A legitimate support agent will never ask for the live one-time code. If someone asks, hang up. The OTP is the second factor; sharing it bypasses the security entirely.

Log out on shared devices

A shared device is a shared session. The habit of logging out fully - not just closing the tab - prevents the next user from continuing your session.

1

Review active sessions

Most platforms list active sessions in the security settings. A quick monthly check catches any device you forgot about and lets you invalidate it remotely.

2

Set a withdrawal PIN

Where offered, a separate withdrawal PIN is a useful second factor that survives a stolen password.

3

Monitor the inbox

A separate email filter for security-related messages makes phishing easier to spot.

The COME Sports Guide desk treats login security as a basic skill, not a specialist topic. A reader who runs through the four habits above is already better protected than the average account holder, and the marginal effort required is small. Save the security contact details of your operator in your phone so you can reach customer care quickly if you ever need to lock an account in a hurry. The minutes saved often decide whether a takeover attempt is foiled or completed.

Continue the investigation

Carry the evidence into the next decision

Save the source, note the time and compare the result with the original reasoning. That small record is the foundation of better cricket judgement.

Second pass — account safety reference

A short reference card and reader FAQs for the login screen

A compact table of the most common login threats, the recommended defence for each and where to read more on this site.

TopicWhat it coversWhere it lives
Phishing pagesLook for the official domain and the TLS lock before typing. Decline the page if either is missing./login/
Credential stuffingUse a unique password and enable 2FA. Reused passwords are the largest single source of account takeover./wallet-kyc/
SIM swap fraudSet a withdrawal PIN and enable transaction alerts. Contact the operator immediately if mobile service is unexpectedly lost./customer-care/
Stolen deviceLog out all sessions from the security settings of a trusted device. Reset the password from the trusted device only./delete-account/
OTP interceptionNever share the OTP. A legitimate support agent will never ask for the live code./customer-care/
What is the fastest way to confirm a login page is real?

Type the official domain yourself rather than following a link. The lock icon and the publisher name in the address bar are the cheapest verification.

Should I use 2FA if it slows me down?

Yes. A one-time code sent to your registered mobile is much harder to steal than a password alone.

How do I recover an account I cannot access?

Contact customer care with the original registration email, the approximate date of registration and the last successful login timestamp.

The COME Sports Guide login desk treats security as a basic skill rather than a specialist topic. The reference table above is short on purpose. A reader who understands the five common threats and the recommended defence for each is already safer than the average account holder. The next step is the responsible-play controls, which keep money on the platform within bounds even when security fails.

Play now