Can't Sign In: OTP Not Arriving
Common causes when a Peony email or SMS code isn't arriving, workarounds, and how to get a manual sign-in bypass.
Last updated September 27, 2026
Peony uses OTP (one-time passcode) as the default sign-in for admins. Password fallback is underway — in the meantime, the workarounds below are the fastest way back into your account.
- I'm an admin and can't sign inwait, check spam and Microsoft Defender, then ask for a manual bypass
- A visitor didn't get the invite or codeallow lists, expired codes and mail filters holding Peony's emails
First: Wait 60 Seconds
Codes usually arrive in seconds, but corporate mail providers can take 30-60 seconds. Don't spam Resend — rapid requests can trigger rate limiting.
Check Spam
Email OTPs are sent from verify@notification.peony.ink.
- Search your inbox for "Peony" or "verify@notification.peony.ink".
- Check Spam / Junk / Gmail Promotions.
- Mark as "Not spam" and add to contacts.
If you admin your corporate email (Microsoft 365, Google Workspace), allowlist notification.peony.ink at the domain level.
Microsoft 365 / Defender Is Blocking the Code
This is the single most common cause. Aggressive Microsoft Defender tenants sometimes flag Peony's OTP emails as spam (SCL 9) or rewrite room links through Safe Links, which can quarantine the message before it reaches you. This is a Microsoft-side domain-reputation flag, not a Peony bug — the same block can also swallow expiry reminders and inbound replies to link emails.
What to do:
- Get into the room without email OTP. Switch the link to Link access with an allow list and a passcode. That bypasses the email-verification step entirely. If you already have a working link, use Copy access link for a direct URL.
- File a clean-email report with Microsoft at learn.microsoft.com/en-us/defender-office-365/submissions-admin. More clean reports from real recipients clear the flag faster.
- Peony has escalated this to Microsoft and the
peony.inkdomain was marked safe globally in June 2026. Tenant-level allow entries expire on their own after roughly 45 days, so the global fix is the durable one. If codes still don't arrive, email support.
Still Not Arriving?
Email OTP
- Corporate mail filter blocked it. Most common cause. Aggressive Exchange / Workspace tenants sometimes quarantine OTPs.
- Typo in your account email (e.g.
gmial.com). Every OTP goes to a nonexistent address. - Wrong email. If your email changed, your Peony account is still tied to the old one. See Contact Support for the manual email-migration path.
SMS OTP
Used during sign-up and when claiming a trial.
- Twilio is overloaded. Peony sends SMS codes through Twilio, which occasionally drops or delays messages. Hit Resend code — it usually goes through within a few tries.
- International carrier issues. SMS to some countries is unreliable.
- VOIP numbers. Google Voice, Twilio, etc. are sometimes blocked. Use a regular mobile number.
- Typo in the phone number — check the country code.
There is no email-verification fallback for SMS sign-up yet; the team is testing additional SMS providers. If the code never arrives, see the trial workaround below or email support to get set up manually.
Fixes
Try a Different Email or Phone
- Corporate email blocking? Sign up with a personal Gmail as a temporary workaround, then email support to migrate rooms to your corporate email later.
- SMS failing? Try a different mobile number (avoid VOIP), or ask support to enable your trial manually — see below. There is no voice-call OTP option today; it's on the roadmap.
Try Incognito
Stale session cookies can break OTP verification. Open an incognito window, go to app.peony.ink/signin, and try again.
Incognito keeps no cookies, so it asks for a code every time; for day-to-day access use a normal window, and see Streamlined access for how the 7-day skip works.
Manual Bypass (Email Support)
If nothing else works, Peony can whitelist an email or send a one-time sign-in link from the backend.
Email sean@peony.ink or deqian@peony.ink with:
- The email on your account
- Your company name
- A screenshot of the OTP screen or error
- Device and browser
Response time: a few hours on business days, faster via in-app Crisp chat.
See Contact Support.
Phone Verification When Claiming the Trial
Claiming the 7 day Data Room trial always requires an SMS code, and if it never arrives support can enable the trial for you manually; see The claim form.
A Visitor Didn't Get the Invite or Code
Check the three usual causes in the questions below: the visitor's email isn't on the allow list, they're using an older code, or their company's mail gateway is holding the email. On Microsoft 365, start here:
Invite & Notification Emails Are Being Quarantined
If viewers on a Microsoft 365 tenant never receive invite emails, expiry reminders, or new-file notifications, Microsoft Defender is likely quarantining them as spam before they reach the inbox. This is a Microsoft-side domain-reputation flag, not a Peony bug.
Ask the recipient's IT / mail admin to add both peony.ink and notification.peony.ink (the subdomain Peony sends invite, reminder, and new-file notification emails from) to the tenant safe-sender allow list. The same block can also swallow sign-in codes — see Microsoft 365 / Defender Is Blocking the Code above for the full Defender walkthrough and the clean-email report link.
Common Questions
Why is there a wait before I can request another code?
There's a short cooldown (about two minutes) between code requests by design, to protect the sign-in from abuse. If a viewer needs in sooner, having them use a different email address should sidestep the cooldown. Shortening or removing it is logged as a roadmap suggestion.
One external viewer gets an error via Email access, but it works for everyone else.
Usually one of three things: they're entering an outdated access code (it must match the latest email or link they were sent), the code landed in spam, or their company's IT firewall is blocking the message. Most often it's the recipient's own IT firewall — once their IT allowlists Peony, it works. Ask them to check spam first, then loop in their IT team.
A viewer wants to reset their password on a room they were invited to.
Viewers can't self-reset. Access to an invited room is controlled by the room owner or admin, not the viewer. Use the exact credentials the admin set, and confirm them with the owner if unsure.
Expiry reminders aren't reaching the link owner, and replies to link emails bounce.
This is the same Microsoft Defender issue described above — when Defender mislabels Peony as spam, it blocks both outbound expiry reminders and inbound replies. File a Defender clean-email report and, if you're on Microsoft 365, allowlist notification.peony.ink at the tenant level.
Visitors have to enter a new code every time they open my link.
Streamlined access is probably off; see how to turn it on.
A visitor enters their email but never gets a code.
Check that their email (or their company domain) is on the link's allow list. If it isn't, Peony doesn't send a code — and, for security, it doesn't tell them they lack access, so nobody can test addresses against your link. Add them in the room's Permissions and ask them to try again.
The code says it's invalid.
Each time someone requests a new code, the previous one stops working. If an older email arrives late, its code is already expired — use the code from the most recent email.
A recipient's company uses Mimecast or Proofpoint and the invite never arrives.
Any email gateway can hold Peony's emails, not only Microsoft Defender. Ask the recipient's IT team to allow notification.peony.ink, then have the person who shared the room click Resend invite in Permissions. Peony support can't resend an invite on the sharer's behalf, but can confirm when the recipient's mail server accepted the email.
Which addresses do Peony's emails come from?
Invites, updates and verification codes are sent from invite@notification.peony.ink, updates@notification.peony.ink and verify@notification.peony.ink. That doesn't change when you add a custom domain or a custom invite email, so ask recipients' IT teams to allow notification.peony.ink.
On the Roadmap
- Password-login fallback (underway)
- SMS retries across multiple providers
- Voice-call OTP option
- Shorter (or optional) resend cooldown
