The Jeeto11 login path is the only place you should sign in. Phishing sites copy the official front page; they cannot copy the SSL certificate or the official login endpoint. the guide documents the verified path and the troubleshooting steps for common access issues.
The official login path
Sign in only through the official Jeeto11 app or the official website at jeeto11in.com. Confirm the URL in the address bar and the SSL certificate (lock icon) before entering your mobile number and OTP.
Phishing rule: if you arrived at the login page through a link in an SMS, email, or chat message, do not enter your OTP. Open the official app or type the operator's URL directly into the address bar instead.
Common issues
OTP not arriving
- Check your mobile network signal
- Confirm the registered mobile number is the one you are using
- Wait 60 seconds before requesting a resend
- If the issue persists across two attempts, switch from SMS OTP to email OTP if the option is available
Forgot password
The Jeeto11 login flow is usually mobile-number + OTP rather than username + password, so the "forgot password" path is rare. If you have set a separate password for the wallet section, use the in-app reset flow and never share the OTP with anyone.
Phishing patterns
The phishing patterns targeting fantasy cricket players in India are consistent:
- "Your account has been suspended; click here to verify" SMS
- "Congratulations, you have won a contest; share OTP to claim" call or WhatsApp
- "Customer care" links sent through Telegram or unofficial chat channels
- Look-alike domains (jeeto11in.co, jeeto11.app, jeeto-11.com) that copy the official design
Verify the domain: the only official domain is jeeto11in.com. Any other domain is unofficial, regardless of how convincing the page looks.
Account recovery
If you have lost access to your registered mobile number, account recovery requires:
- A registered email address on file
- Recent KYC documents (PAN, Aadhaar)
- A selfie holding the documents
- A support ticket through the official customer care channel
If your account is compromised
If you suspect your account has been accessed by someone else:
- Sign out of all sessions from the app's security settings
- Change your email password (a compromised email compromises every service that uses it)
- Enable two-factor authentication if the operator offers it
- Contact customer care to flag the account for monitoring
- Check your linked bank or UPI account for unexpected transactions
Two-factor authentication — what to enable
If the operator offers two-factor authentication (2FA), enable it on day one. 2FA adds a second verification step — typically a one-time password sent to your registered mobile or email — after the password entry. The second step makes it significantly harder for an attacker who has your password to log in.
The three common 2FA methods:
- SMS OTP: a code sent to your registered mobile number. The most common method; the least secure (SIM-swap attacks exist).
- Email OTP: a code sent to your registered email. Useful as a backup if SMS is unavailable.
- Authenticator app: a code generated by an app like Google Authenticator or Authy. The most secure method; the most setup cost.
If the operator offers an authenticator-app option, use it. The setup takes two minutes and protects you against the most common account-takeover attacks.
If the operator only offers SMS OTP, enable it. SMS OTP is not perfect but it is materially better than password-only login.
Two-factor authentication — what to enable
If the operator offers two-factor authentication (2FA), enable it on day one. 2FA adds a second verification step — typically a one-time password sent to your registered mobile or email — after the password entry. The second step makes it significantly harder for an attacker who has your password to log in.
The three common 2FA methods: SMS OTP (a code sent to your registered mobile; the most common, the least secure), Email OTP (a code sent to your registered email; useful as a backup), and Authenticator app (a code generated by an app like Google Authenticator or Authy; the most secure, the most setup cost).
If the operator offers an authenticator-app option, use it. The setup takes two minutes and protects you against the most common account-takeover attacks. If the operator only offers SMS OTP, enable it. SMS OTP is not perfect but it is materially better than password-only login.
Keep your registered mobile number active. If you change your mobile number, update the operator's account settings before the old number is deactivated. An inactive registered mobile number is the most common reason 2FA fails when you need it.
Session management on shared devices
If you ever sign in on a shared device — a friend's phone, a hotel business centre, a work device — the session management is your responsibility. Three habits: always sign out when you finish; clear the app's cache or the browser's history after the session; use the operator's "sign out of all sessions" feature from a trusted device after you finish.
The habits take thirty seconds each. The thirty seconds are the difference between a contained session and a compromised account. If you do not have a personal device and you play fantasy cricket, consider using a dedicated email address for the platform. The dedicated email is a layer of separation that protects your primary email from compromise.
The session management matters most when the shared device is in a public space (a hotel lobby, an internet cafe). The public-space session is the most likely to be observed; the public-space session is also the most likely to be forgotten. The "sign out of all sessions" feature is the catch-up that closes the risk.
Password hygiene for the platform
The platform password is the first line of defence for your account. Five habits: use a unique password (do not reuse your email or banking password); use a long password (12+ characters); use a password manager; change the password every six months; do not share the password with anyone, including customer care.
The platform's customer care team will never ask for your password. If anyone — even someone claiming to be from customer care — asks for your password, it is a scam. Report the contact to the operator's verified customer care channel.
The password hygiene does not require a security expert. It requires only the discipline to use a password manager and to follow the five habits. The discipline is the same as the discipline that keeps you within the fantasy cricket budget.
Public Wi-Fi and the login flow
Signing in on public Wi-Fi — a hotel network, an airport network, a cafe network — is a meaningful risk. The risk is not that the platform's login flow is insecure (it is HTTPS-encrypted) but that the network itself may be compromised.
A compromised public Wi-Fi network can intercept unencrypted traffic, redirect DNS requests to phishing sites, or perform man-in-the-middle attacks on HTTPS connections (if the network operator has installed a proxy certificate on your device without your knowledge).
Three habits for public Wi-Fi sessions: avoid signing in on public Wi-Fi if you can; use a personal hotspot if you need to sign in on the go; clear the app's cache and sign out of all sessions after any public Wi-Fi session.
The habits are conservative but the risk is real. Public Wi-Fi is one of the most common attack surfaces for account compromise.
Recovering a locked account
If the operator locks your account — usually because of too many failed login attempts or a flagged security event — the recovery flow is:
- Wait 24 hours; most temporary locks release automatically.
- If the lock persists, contact customer care with your registered mobile number and account ID.
- Customer care will run identity verification; the verification usually requires a fresh selfie and a KYC document re-upload.
- Once verified, the lock is released and you can sign in again.
The recovery flow is designed to be friction-heavy; the friction protects the account from an attacker who has your password. If the recovery feels slow, that is the design.
Related reads: App guide · Customer care · Responsible play