Account recovery: what the reset flow does
Worth being precise about this, because recovery flows are where security assumptions usually go wrong.
What it needs: a verified email address on the account. Without one, there is no automated recovery path — and that is intentional, since any alternative would be a weaker way in.
What it sends: a single-use link, valid for 30 minutes, tied to a random token stored as a hash. The server never stores the token itself.
What it cannot do: recover an encrypted transfer secret, or decrypt anything you sent. Those keys are not derived from your password.
What you should do if you get a reset link you did not request: ignore it. The link alone cannot change a password; it opens a page that requires a new one. Nobody can use it without also having access to your mailbox.