Hacker News new | ask | show | jobs
by Ozzie_osman 2087 days ago
Well email tracking isn't perfect, but it can help a lot. A legitimate pattern you'd see an email open event, email click event, then successful reset in that order. An illegitimate one might have no email open or click before the reset, or clicks from multiple places or something like that. That could narrow down the list significantly.

Of course, not all email clients allow send these events.