Account security
Six digits after the password.

Two-factor from any authenticator app, ten recovery codes for the day the phone is gone, and a switch that requires it across a workspace.

In short

What is two-factor authentication?

Two-factor authentication asks for a second proof after the password, usually a short code from an app on your phone. Because the code keeps changing, a leaked password is not enough on its own.

6

digits in every code

30s

before the app shows the next one

10

recovery codes, shown once

How it works

Nothing switches on until it works

Setup takes your password, shows a QR code and waits for six digits from the app. A bad scan is caught while you can still sign in.

Ten recovery codes, shown once

They appear at the end of setup and cannot be read back later. Each one signs you in once if the phone is gone.

Required across a whole workspace

One switch under Privacy in your workspace settings applies at once, even to people already signed in. Anyone without an app meets a lockout screen until they enrol.

What you get

In the product today

Any authenticator app

Google Authenticator, 1Password, Authy, or anything else that reads a QR code.

Risky changes ask again

Removing a domain or creating an API key asks for a code, good for an hour.

Off needs the password

Turning two-factor off asks for your password, as turning it on did.

Good practice

Getting the most out of it

  1. 01

    Codes off the phone

    Keep the recovery codes in a password manager or on paper, not on the phone.

  2. 02

    Enrol before requiring

    The rule covers you too, so set up your own app before switching it on.

  3. 03

    Warn the team first

    Members without an app are locked out the moment it goes on, so tell them first.

Where it stands

Good to know

Text messages and security keys
Not offered. The second step is an authenticator app or a recovery code.
Seeing recovery codes again
Not possible. Turning two-factor off and on again issues a new set.

Questions

Asked often

Keep going

Works well with

Choose which emails we send you

Per-category switches in Account → Notifications, and the ones that matter are honestly marked as unswitchable.

Roles & permissions levels

A role says what somebody may do; an address grant says what they may do it to.

End-to-end encryption

OpenPGP keys made in your browser. Mail you send to another OpenEmail address can be sealed before it leaves the tab, and sealed mail addressed to you opens in the reading pane, decrypted on your machine. The keys are never ours to hand over.

Start

Your domain,
your mail.

Point a domain at OpenEmail and read it in a mailbox built around it. The free plan covers one domain.

Your inbox,
on your own terms.

Email infrastructure for businesses, AI, agents and personal email. Built for scale, privacy and control. Everything email should have had from day one.

OpenEmail

Email infrastructure for businesses, AI, agents and personal email. Built for scale, privacy and control. Everything email should have had from day one.

© 2026 OpenEmail. All rights reserved.