Login safety

The only login is the one the operator publishes.

Five checks before any login, password reset path and two-factor authentication. The reading desk does not run a login form. The login button points to the operator's verified entry.

Brass key resting on folded linen beside a softly glowing ceramic lamp

Login safety

The only login is the one the operator publishes.

The reading desk does not run a login form. The login button points to the operator's verified entry. A cloned login form is one of the most common phishing patterns. Check the URL bar, the certificate and the domain spelling before entering credentials.

Five checks before any login

The desk's pre-login checklist.

  1. URL bar: the domain spelling matches the operator's verified entry. A single character difference is a phishing signal.
  2. Certificate: the certificate issuer matches the operator's published certificate issuer.
  3. Domain age: the domain has been registered for more than one year. A new domain is a soft signal.
  4. Bookmark: the verified entry is bookmarked before any login attempt. Bookmarking prevents typo-squat phishing.
  5. Two-factor: two-factor authentication is enabled in account settings. SMS OTP is the published channel.

Password reset

The verified path, in four moves.

The password reset path is published in the help section. Use the verified entry to start a reset, not an email link. The email link may lead to a cloned form. The desk treats the verified entry as the only authoritative route.

Support guide

Phishing checklist

Six signals of a phishing login form.

  • Domain spelling: a single character difference is a phishing signal.
  • Certificate: a missing or self-signed certificate is a phishing signal.
  • OTP request: the login form does not request an OTP. A request is a phishing signal.
  • Password field autofill: a password field that does not autofill is a soft signal.
  • Unknown redirect: a redirect to an unknown domain after login is a phishing signal.
  • Urgency: a message that pressures the user into a fast login is a phishing signal.

Two-factor authentication

Why the desk recommends it.

Two-factor authentication adds an SMS OTP on top of the password. The OTP is delivered to the mobile number registered with the operator. A phishing form cannot receive the OTP because the OTP is delivered to the legitimate device, not to the form.

Source

Where the desk sourced each row.

Five checks, password reset path and two-factor authentication are taken from the operator's published help and account-security pages, captured 2026-08-17, marked subject to confirmation. The desk updates these rows when the operator publishes a change.

Related reading

Three routes the desk opens after the login guide.

Pre-login checklist

Five items the desk runs before any login attempt.

  1. URL bar: the domain spelling matches the operator's verified entry.
  2. Certificate: the certificate issuer matches the operator's published issuer.
  3. Domain age: the domain has been registered for more than one year.
  4. Bookmark: the verified entry is bookmarked before any login attempt.
  5. Two-factor: two-factor authentication is enabled in account settings.

Password reset

The verified path, in four moves.

The password reset path is published in the help section. Use the verified entry to start a reset, not an email link. The email link may lead to a cloned form. The desk treats the verified entry as the only authoritative route.

What the desk will not print

Two columns the desk refuses to print.

The desk does not run a login form. The desk cites the operator's verified entry. The desk also does not publish an OTP request form. OTPs are delivered to the legitimate device, not to the form.

How the desk reads login

Reading login as a security checklist, not a friction step.

Login is a security checklist, not a friction step. The verified entry, the certificate, the domain age, the bookmark and the two-factor authentication. Each item is a verification step.

Five checks the desk runs

  1. URL bar: the domain spelling matches the operator's verified entry. A single character difference is a phishing signal.
  2. Certificate: the certificate issuer matches the operator's published certificate issuer.
  3. Domain age: the domain has been registered for more than one year. A new domain is a soft signal.
  4. Bookmark: the verified entry is bookmarked before any login attempt. Bookmarking prevents typo-squat phishing.
  5. Two-factor: two-factor authentication is enabled in account settings. SMS OTP is the published channel.

Password reset path

The password reset path is published in the help section. Use the verified entry to start a reset, not an email link. The email link may lead to a cloned form. The desk treats the verified entry as the only authoritative route.

Two-factor authentication

Two-factor authentication adds an SMS OTP on top of the password. The OTP is delivered to the mobile number registered with the operator. A phishing form cannot receive the OTP because the OTP is delivered to the legitimate device, not to the form.

Six phishing signals

  • Domain spelling: a single character difference is a phishing signal.
  • Certificate: a missing or self-signed certificate is a phishing signal.
  • OTP request: the login form does not request an OTP inside the form. A request is a phishing signal.
  • Password field autofill: a password field that does not autofill is a soft signal.
  • Unknown redirect: a redirect to an unknown domain after login is a phishing signal.
  • Urgency: a message that pressures the user into a fast login is a phishing signal.

FAQ

Five questions about login safety.

Where is the verified login?
The verified login is the operator's published entry. Bookmark it before signing up. The reading desk does not run a login form.
How do I reset my password?
Use the verified entry to start a reset, not an email link. The email link may lead to a cloned form.
What is two-factor authentication?
Two-factor authentication adds an SMS OTP on top of the password. The OTP is delivered to the mobile number registered with the operator.
What if the login form requests an OTP?
A legitimate login form does not request an OTP inside the form. The OTP is delivered to the legitimate device, not to the form. A request is a phishing signal.
What if the password field does not autofill?
A password field that does not autofill is a soft signal. The desk treats it as a soft signal of a phishing form, not as a definite signal.

Reading-list appendix

Three articles from the news desk that deepen this route.

Dated, sourced explainers cover contest decisions, scoring rows, withdrawal cycles, state rules and captain math. Each article names myteam11in.com as the publisher and cites the operator's published page.

The 100-credit draft article covers the lobby label, the cap, the carry-over rule and the expiry window. The UPI withdrawal cycle article covers the cycle in nine steps, with a redacted screenshot checklist. The state-rules article covers the federal framework, the six restricted states and the MeitY PROG Act 2025 reporting requirements.

The captain-slot article covers two clocks: the captain slot lock and the toss time. The captain pick is a multiplier, not a reputation. The scoring-edge-cases article covers run-outs, stumpings, the duck rule and the maiden over. Each article is read in five minutes.

Glossary

Six terms the desk uses across all routes.

  • Captain multiplier: 2× the player's points. Locked at team creation. Cannot be edited after the contest closes for entries.
  • Vice-captain multiplier: 1.5× the player's points. Becomes captain if the captain is absent or did not bat or bowl.
  • Gullak-Cash variants: two bonus variants the operator publishes on the rewards page: 80/250/400 INR and 82/252/402 INR.
  • KYC: know-your-customer. The operator's verification step. PAN, identity proof, address proof and bank proof. Required before the first withdrawal.
  • Restricted states: Andhra Pradesh, Assam, Odisha, Telangana, Sikkim and Nagaland. Paid skill contests are restricted. Free contests may be available.
  • Self-exclusion: a published window during which the operator does not allow contest entry, deposit or withdrawal request.

Primary action

Use the verified entry only.

Bookmark the operator's verified entry before any login attempt. Enable two-factor authentication in account settings.

Play Now