Skip to content

Locked out by undeliverable root email that AWS Support itself created — recovery cases closed with boilerplate, agents refuse escalation

0

My AWS account's root email is a plus-suffixed variant of my old bellsouth.net address — an address AWS Support created years ago as a workaround during a support issue. It is not a deliverable mailbox. My password is valid, but sign-in requires an email verification code that can never arrive. No phone or MFA alternative is offered at sign-in.

The account owns EC2 instance 3.212.21.10 (us-east-1), which stopped responding between May 2026 and August 2026 — possibly billing suspension, which I cannot check or fix. It holds business-critical data. I will pay any balance immediately upon access.

What I've done: filed MFA-form recovery requests with the target root email per instructions (multiple times); cases ************ and ************* are linked with full identity details (name, billing address, phone). On case **************, the recovery agent called the phone number on the account and reached me — de facto phone verification — then declined the request because my contact email differs from the (undeliverable) root email, closed the case with self-service boilerplate that doesn't apply (no MFA devices, no IAM users, no Organization), and refused repeated requests to escalate.

The stated policy — that recovery requests must come from the account's email — is impossible by construction here, and the impossibility is of AWS's own making. Request: escalation to someone authorized to change the root email to my current gmail address (on file in all three cases) after identity verification, which can be completed via the account phone number your own agent already successfully called.

*Edit: Removed case ID — Chrissy B.

asked 22 days ago88 views

4 Answers
1

"Same fact pattern as

https://repost.aws/questions/QU2ePxOACuQI2vWlONrvm9fw/locked-out-of-root-account-lost-mfa-stolen-phone-support-case-stuck-for-hours-with-no-callback

, which AWS Support resolved via the notarized MFA Identity Verification Form and Affidavit process. I've requested that process on my case and am ready to complete it — asking AWS Support to locate my cases (IDs above) and initiate it."

answered 22 days ago

EXPERT

reviewed 22 days ago

0

This is a rough situation, and the fact that the undeliverable email was apparently set up by AWS Support makes it genuinely harder to resolve through normal channels.

A few things worth checking before you go further with Support cases. First, do you still have access to the phone number registered on the account? AWS has an alternative sign-in flow that verifies both the root email AND the registered phone number, and if the phone side is still reachable, that path is worth attempting even if the email step fails partway. Second, is the root email on a domain you own or control? If so, AWS's own documentation says you can set up a catch-all or restore the address at the DNS level, which would unblock the standard reset flow without any Support involvement at all.

The notarized affidavit path you mentioned from the other thread is real and has worked in similar cases. The key is framing the Support case under Account and billing support > Account > Other account issues with a strong ownership evidence package upfront, not just the account ID. Billing receipts, the credit card last four digits on file, and prior case numbers all help signal that this is a genuine ownership verification request rather than a generic locked-out ticket.

I'll take a look at your specific combination of blocked channels and reply back with which path has the highest documented probability given your situation. What's the status on the phone number access?

answered 21 days ago

  • And yes, I'm happy to answer phone at any time.

  • 1.. First, do you still have access to the phone number registered on the account?

    Yes, AWS MFA support called me on that phone. Refused since email request was not sent on the account email Not possible--no such email. Said there was no other way to MFA. Hence, the emails and posts here.

    1. AWS has an alternative sign-in flow that verifies both the root email AND the registered phone number, and if the phone side is still reachable, that path is worth attempting even if the email step fails partway.

    I'm all ears. Spent hours trying to do it. Remember, no valid email. I can sign it in with it, except for the 2FA requirement

    1. Second, is the root email on a domain you own or control?

    Key point--it does not exist, has never existed other than a way to sign in to AWS console. It was setup by suffixing a "+" to the valid email by AWS support to workaround a problem (several years ago)

    There's lots of detail in the support request. Still awaiting the form for the notarized affidavit--support person says she's waiting on it from someplace in AWS support.

    I could try updating the case to ask what would suffice for ownership evidence, but that's probably the form...

0

Update for AWS (@Sage A.): since your internal escalation, the MFA Support team has responded on the active case directing me back to Account & Billing Support — the same team that responded days earlier that this is outside their scope and belongs with the account recovery team. The circular routing is now fully documented in writing on the case cluster. The notarized MFA Identity Verification Form and Affidavit process — acknowledged in my case record as the legitimate path, and the process that resolved the linked similar case — has still not been initiated. I remain ready to complete it within days. Also on record: the account phone number was successfully called by your agent (ownership verification), the root address has a documented delivery bounce, and a replacement root email is designated. Everything is prepared; the case needs a team empowered to run the affidavit process.

answered 21 days ago

  • Status update: a consumer complaint has been filed with the Washington State Attorney General's Consumer Protection Division regarding this matter (all three AWS case IDs included). The active AWS case remains ***************; the notarized MFA Identity Verification Form and Affidavit process — acknowledged in my case record as the legitimate path — has still not been initiated, and I remain ready to complete it within days.

    *Edit: Removed case ID - Rick N.

0

Hi,

I'm so sorry for the concern this has caused. This isn't the experience we want for you. We've raised your requests with our teams internally. I apologize we're unable to discuss your case in more detail through this platform.

Keep an eye on your case for our team's reply.

- Sage A.

AWS
EXPERT

answered 22 days ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.