State of M&A Data Rooms — Q2 2026 Read the report →

Can't Sign In: OTP Not Arriving

Common causes when a Peony email or SMS code isn't arriving, workarounds, and how to get a manual sign-in bypass.

Last updated July 22, 2026

Peony uses OTP (one-time passcode) as the default sign-in for admins. Password fallback is underway — in the meantime, the workarounds below are the fastest way back into your account.

First: Wait 60 Seconds

Codes usually arrive in seconds, but corporate mail providers can take 30-60 seconds. Don't spam Resend — rapid requests can trigger rate limiting.

Check Spam

Email OTPs are sent from verify@notification.peony.ink.

  • Search your inbox for "Peony" or "verify@notification.peony.ink".
  • Check Spam / Junk / Gmail Promotions.
  • Mark as "Not spam" and add to contacts.

If you admin your corporate email (Microsoft 365, Google Workspace), allowlist notification.peony.ink at the domain level.

Microsoft 365 / Defender Is Blocking the Code

This is the single most common cause. Aggressive Microsoft Defender tenants sometimes flag Peony's OTP emails as spam (SCL 9) or rewrite room links through Safe Links, which can quarantine the message before it reaches you. This is a Microsoft-side domain-reputation flag, not a Peony bug — the same block can also swallow expiry reminders and inbound replies to link emails.

What to do:

  • Get into the room without email OTP. Switch the link to Link access with an allow list and a passcode. That bypasses the email-verification step entirely. If you already have a working link, use Copy access link for a direct URL.
  • File a clean-email report with Microsoft at learn.microsoft.com/en-us/defender-office-365/submissions-admin. More clean reports from real recipients clear the flag faster.
  • Peony has escalated this to Microsoft and the peony.ink domain was marked safe globally in June 2026. Tenant-level allow entries expire on their own after roughly 45 days, so the global fix is the durable one. If codes still don't arrive, email support.

Still Not Arriving?

Email OTP

  • Corporate mail filter blocked it. Most common cause. Aggressive Exchange / Workspace tenants sometimes quarantine OTPs.
  • Typo in your account email (e.g. gmial.com). Every OTP goes to a nonexistent address.
  • Wrong email. If your email changed, your Peony account is still tied to the old one. See Contact Support for the manual email-migration path.

SMS OTP

Used during sign-up and when claiming a trial.

  • Twilio is overloaded. Peony sends SMS codes through Twilio, which occasionally drops or delays messages. Hit Resend code — it usually goes through within a few tries.
  • International carrier issues. SMS to some countries is unreliable.
  • VOIP numbers. Google Voice, Twilio, etc. are sometimes blocked. Use a regular mobile number.
  • Typo in the phone number — check the country code.

There is no email-verification fallback for SMS sign-up yet; the team is testing additional SMS providers. If the code never arrives, see the trial workaround below or email support to get set up manually.

Fixes

Try a Different Email or Phone

  • Corporate email blocking? Sign up with a personal Gmail as a temporary workaround, then email support to migrate rooms to your corporate email later.
  • SMS failing? Try a different mobile number (avoid VOIP), or ask support to enable your trial manually — see below. There is no voice-call OTP option today; it's on the roadmap.

Try Incognito

Stale session cookies can break OTP verification. Open an incognito window, go to app.peony.ink/signin, and try again.

Note the trade-off: incognito clears cookies, so you'll be asked for a code every time. For day-to-day access, sign in on a normal (non-incognito) window on the same device and browser. With streamlined access (on by default), Peony saves your auth for 7 days so you aren't re-entering codes each visit.

Manual Bypass (Email Support)

If nothing else works, Peony can whitelist an email or send a one-time sign-in link from the backend.

Email sean@peony.ink or deqian@peony.ink with:

  1. The email on your account
  2. Your company name
  3. A screenshot of the OTP screen or error
  4. Device and browser

Response time: a few hours on business days, faster via in-app Crisp chat.

See Contact Support.

Phone Verification When Claiming the Trial

Claiming the 7 day Data Room trial still requires phone verification. The claim modal asks for your company name, website, and phone number, then sends an SMS code you enter to confirm. There is no way to skip the phone step in the product.

If SMS is failing and you can't get the code, you don't have to fight it: pick a plan and email support with the email on your account and the country code of the phone that failed. Support can enable the 7-day Data Room trial for you manually.

Common Questions

Why is there a wait before I can request another code?

There's a short cooldown (about two minutes) between code requests by design, to protect the sign-in from abuse. If a viewer needs in sooner, having them use a different email address should sidestep the cooldown. Shortening or removing it is logged as a roadmap suggestion.

One external viewer gets an error via Email access, but it works for everyone else.

Usually one of three things: they're entering an outdated access code (it must match the latest email or link they were sent), the code landed in spam, or their company's IT firewall is blocking the message. Most often it's the recipient's own IT firewall — once their IT allowlists Peony, it works. Ask them to check spam first, then loop in their IT team.

A viewer wants to reset their password on a room they were invited to.

Viewers can't self-reset. Access to an invited room is controlled by the room owner or admin, not the viewer. Use the exact credentials the admin set, and confirm them with the owner if unsure.

Expiry reminders aren't reaching the link owner, and replies to link emails bounce.

This is the same Microsoft Defender issue described above — when Defender mislabels Peony as spam, it blocks both outbound expiry reminders and inbound replies. File a Defender clean-email report and, if you're on Microsoft 365, allowlist notification.peony.ink at the tenant level.

On the Roadmap

  • Password-login fallback (underway)
  • SMS retries across multiple providers
  • Voice-call OTP option
  • Shorter (or optional) resend cooldown