Multi-factor authentication
Multi-factor authentication (MFA, called two-step verification in the dashboard) adds a second step to signing in to the dashboard. Frontmail supports TOTP authenticator apps (1Password, Google Authenticator, Microsoft Authenticator, Authy, Aegis, …) with backup codes.
Turn it on
Section titled “Turn it on”- Verify your email address first – two-step verification can only be turned on for a verified address (so nobody can lock a mailbox owner out of an account registered with their email). Then open Settings → Security (Sign-in & security) and click Turn on next to Two-step verification.
- Confirm with your password.
- Scan the QR code with your authenticator app (or enter the key shown below it manually).
- Enter the 6-digit code the app shows.
- Save the 10 backup codes and confirm with I’ve saved them – each code signs you in once if you lose your phone. You won’t see them again.
You get an email whenever two-step verification is turned on or off. New backup codes replaces all your backup codes; Turn off disables two-step verification (both ask for your password).
Signing in
Section titled “Signing in”After your email and password, enter the current code from your app – or choose Use a backup code instead. Tick Trust this device for 30 days to skip the code on that browser.
The code is asked for with every sign-in method: email and password, an emailed sign-in link (magic link) and Google / GitHub. After the link or the provider, the dashboard shows the two-step verification step before you’re signed in. A trusted device skips it for all methods.
Sign-in links opened on another device
Section titled “Sign-in links opened on another device”An emailed sign-in link works right away in the browser where you asked for it. Opened in a different browser or device, it first shows Continue signing in? with the account’s email address – continue only if you just requested the link. Likewise, an email verification link opened elsewhere verifies the address but doesn’t sign that browser in. This stops a link sent by someone else from quietly signing you in to their account.
Lost your device?
Section titled “Lost your device?”Sign in with one of your backup codes, then turn two-step verification off and on again to set up the new device – this also issues new backup codes. If you have no backup codes, contact support from the account email; for your security, account recovery requires identity verification and takes time.
Changing your sign-in email
Section titled “Changing your sign-in email”Settings → Security → Change email asks for your current password (accounts without a password must have signed in within the last 15 minutes). Frontmail then emails your current address to approve the change; only after that the new address gets its confirmation link. The old address also gets a notice once the change is done. A stolen session alone therefore can’t move the account to another mailbox.
Superadmins
Section titled “Superadmins”Frontmail staff accounts with superadmin access must have two-step verification turned on and must have signed in within the last hour to use the admin tools.
Sessions
Section titled “Sessions”Settings → Sessions (Active sessions) lists every device where you’re signed in, with the browser, IP address and sign-in time. Sign out individual sessions or Sign out everywhere else. You also get an email when someone signs in from a new device.
MFA applies to dashboard access. API keys are not affected – protect them as described in Public and private keys.