Skip to content

Multi-factor authentication

Multi-factor authentication (MFA, called two-step verification in the dashboard) adds a second step to signing in to the dashboard. Frontmail supports TOTP authenticator apps (1Password, Google Authenticator, Microsoft Authenticator, Authy, Aegis, …) with backup codes.

  1. Verify your email address first – two-step verification can only be turned on for a verified address (so nobody can lock a mailbox owner out of an account registered with their email). Then open Settings → Security (Sign-in & security) and click Turn on next to Two-step verification.
  2. Confirm with your password.
  3. Scan the QR code with your authenticator app (or enter the key shown below it manually).
  4. Enter the 6-digit code the app shows.
  5. Save the 10 backup codes and confirm with I’ve saved them – each code signs you in once if you lose your phone. You won’t see them again.

You get an email whenever two-step verification is turned on or off. New backup codes replaces all your backup codes; Turn off disables two-step verification (both ask for your password).

After your email and password, enter the current code from your app – or choose Use a backup code instead. Tick Trust this device for 30 days to skip the code on that browser.

The code is asked for with every sign-in method: email and password, an emailed sign-in link (magic link) and Google / GitHub. After the link or the provider, the dashboard shows the two-step verification step before you’re signed in. A trusted device skips it for all methods.

An emailed sign-in link works right away in the browser where you asked for it. Opened in a different browser or device, it first shows Continue signing in? with the account’s email address – continue only if you just requested the link. Likewise, an email verification link opened elsewhere verifies the address but doesn’t sign that browser in. This stops a link sent by someone else from quietly signing you in to their account.

Sign in with one of your backup codes, then turn two-step verification off and on again to set up the new device – this also issues new backup codes. If you have no backup codes, contact support from the account email; for your security, account recovery requires identity verification and takes time.

Settings → Security → Change email asks for your current password (accounts without a password must have signed in within the last 15 minutes). Frontmail then emails your current address to approve the change; only after that the new address gets its confirmation link. The old address also gets a notice once the change is done. A stolen session alone therefore can’t move the account to another mailbox.

Frontmail staff accounts with superadmin access must have two-step verification turned on and must have signed in within the last hour to use the admin tools.

Settings → Sessions (Active sessions) lists every device where you’re signed in, with the browser, IP address and sign-in time. Sign out individual sessions or Sign out everywhere else. You also get an email when someone signs in from a new device.

MFA applies to dashboard access. API keys are not affected – protect them as described in Public and private keys.