You may want to look into using HMAC Urls (with a timed expiration date), see
http://en.wikipedia.org/wiki/HMAC for a quick explanation.
This lets you send a link like www.mysite.com/resetpassword?userid=123×tamp=...&hmac=.... without having to keep a database backed copy of 'reset password' emails and tracking sent links.
You can make it so the link only works for say a few hours or any other combination of factors, the HMAC lets you 'sign' the URL you issue the user so it cannot be changed/forged, and you append a 'timestamp' argument to then let you determine if you consider the URL too old to take action on.