Skip to content

Can't access verify token sent to root email as the domain is in clientHold due to account suspension

0

Hi, exactly as the title suggests. I'm going around in circles here, I can authenticate with my root email address and password, but it then sends a token to my registered account email but as my account has been suspended the domain has been put in clientHold and therefore not resolving, so I can no longer access this. I have an IAM account I can log in to but can't assume any roles that I previously could.

I have raised this issue several times with AWS but I am constantly directed to "recover MFA" - this is not what I want, I have a TOTP token but can't choose to use this. So, I need one of the following things to happen...

  1. Temporarily restore the domain so I can receive the email - I can log in fine if the domain resolves - and then I can log in and pay any outstanding invoices.
  2. Allow me to log in with my TOTP code instead of relying on the one sent to a disabled email address.
  3. Send me a guest checkout link to pay my invoices, this needs to go to an alternative account or it can be sent as SMS to the registered number on my account.
  4. Anything else you can suggest...
  • For the FIFTH time now I have been advised to create a new account and raise a support ticket answering questions like "why do you need to access the account". This is beyond ridiculous, as it stands right now these are my "other" support requests, every single one of them is still UNASSIGNED.

    2026-07-05 20:28:30 - [CASE <not allowed apparently>] "Your AWS Inquiry" - Unassigned 2026-07-04 19:38:03 - Chat: Guest payment link required to pay an invoice - Unassigned 2026-06-25 10:58:53 - My AWS account has been closed, please can you provide a transfer code for my Route53 domains - Unassigned 2026-05-26 22:17:09 - Urgent production outage - Unassigned 2026-05-24 20:15:10 - Unable to access account to pay bill - Unassigned

    My business has been effectively down since the 24th May and AWS are quite literally holding my domains to ransom, but the sick thing is, is that I AM WILLING TO PAY THAT RANSOM!

    Right now I am going to have to look at buying alternative domains and rebuilding what I can scrape from an archive. You can be absolutely certain that I, nor my clients, will make this mistake again.

1 Answer
1

I assume, the automated system sees keywords like "token" or "login" and routes your ticket to the MFA/Identity team. They don't have access to billing or registrar tools, so they just send you the standard MFA recovery macro. To break this catch-22, you need to use the public, unauthenticated AWS support form -> https://support.aws.amazon.com/#/contacts/aws-account-support Do not select anything related to login or MFA. Choose Billing / Account Reinstatement. Tell them explicitly that this is a billing issue causing a domain resolution failure, and ask them for one of two specific actions:

  1. Provide a secure guest payment link via SMS or to an alternate email so you can settle the invoice without logging in.
  2. Temporarily lift the clientHold on your domain for 24 hours. This will allow your MX records to resolve so the verification email can arrive.

PS: AWS Support monitors this forum. There is a chance a representative might see your post and assist you directly ;) .

EXPERT

answered a month ago

EXPERT

reviewed a month ago

  • Thanks for this, and I really hope so. I've been through FOUR support tickets now and all have somehow ended up with the same advice. One of the replies even suggested that I needed to pay a notarist £120 to sign an affidavit to prove my identity... despite having provided a LOT of evidence up front already.

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.