At /login, with the email address the account was opened under. If the password will not work, use "Forgot password" on that page — it emails a link that lets you set a new one, and the link expires. We cannot read your password and cannot tell you what it was.
They are all signed out. Changing a password ends every other session on the account, which is what makes changing it useful if you think somebody else has been in. The browser you changed it in stays signed in.
Yes — the Security page in your account lists the sessions that are currently open, with the last time each one was used. Anything you do not recognise is a reason to change your password, which ends all of them.
Not yet. The Security page says so plainly rather than showing a switch that does nothing. Until it arrives, the protections that matter are a password you use nowhere else and an email account that is itself secured — password resets go through your email.
From the Profile page. The new address has to be confirmed before it becomes the one we use, so the change is not complete until you have opened the message we send to it. Invoices and service notices follow the confirmed address.
Everything you hold with us and everything owed: services grouped by kind, invoices and payments, renewal dates, your addresses, and the notifications for anything that has happened recently. The sidebar is the whole of it — there is no second place things hide.
You, and the people who run Digipacket when they need to help you. Support staff can see your tickets, your services and your invoices; they cannot see your password, and any note they write to each other about a ticket is marked internal and is never shown to you or sent to you.
Not from a second login yet — an account has one set of credentials. Sharing them is the wrong answer, so if you need a colleague to deal with something specific, open a ticket and say so; we can work with them on that ticket without giving them your account.