Hi Davy Obdam, >[...] > My question is what would be the best approach to achieve this? How is > this usualy done? Storing the password in encrypted form in a database. The confirmationmail you can write with the normal mailcommand using addslashes. The securest way if the password was randomly generated is to presend the resultpage via a ssl-connection and without sending a mail or the mail must be protected. So a hacker can't sniff the password. Regards, Ruprecht ---------------------------------- Ruprecht Helms IT-Service und Softwareentwicklung Tel/Fax.: +49[0]7621 16 99 16 Homepage: http://www.rheyn.de email: info@rheyn.de ---------------------------------- -- PHP Database Mailing List (http://www.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php