---
title: "Two-factor authentication for email"
description: "Six-digit codes from any authenticator app, ten single-use recovery codes, and one switch that requires two-factor for everyone in a workspace."
url: "https://openemail.uk/features/account-security"
---

[Privacy & ownership](https://openemail.uk/features.md#trust)

# Account security Six digits after the password.

Two-factor from any authenticator app, ten recovery codes for the day the phone is gone, and a switch that requires it across a workspace.

[Open mail](https://openemail.uk/mail/inbox) [Get Started](https://openemail.uk/signup.md)[All features](https://openemail.uk/features.md)

In short

## What is two-factor authentication?

Two-factor authentication asks for a second proof after the password, usually a short code from an app on your phone. Because the code keeps changing, a leaked password is not enough on its own.

6

digits in every code

30 s

before the app shows the next one

10

recovery codes, shown once

How it works

## Nothing switches on until it works

Setup takes your password, shows a QR code and waits for six digits from the app. A bad scan is caught while you can still sign in.

## Ten recovery codes, shown once

They appear at the end of setup and cannot be read back later. Each one signs you in once if the phone is gone.

## Required across a whole workspace

One switch under Privacy in your workspace settings applies at once, even to people already signed in. Anyone without an app meets a lockout screen until they enrol.

What you get

## In the product today

Any authenticator app

Google Authenticator, 1Password, Authy, or anything else that reads a QR code.

Risky changes ask again

Removing a domain or creating an API key asks for a code, good for an hour.

Off needs the password

Turning two-factor off asks for your password, as turning it on did.

Good practice

## Getting the most out of it

1. 01
   
   Codes off the phone
   
   Keep the recovery codes in a password manager or on paper, not on the phone.
2. 02
   
   Enrol before requiring
   
   The rule covers you too, so set up your own app before switching it on.
3. 03
   
   Warn the team first
   
   Members without an app are locked out the moment it goes on, so tell them first.

Where it stands

## Good to know

Questions

## Asked often

Keep going

## Works well with

Choose which emails we send you

Per-category switches in Account → Notifications, and the ones that matter are honestly marked as unswitchable.

Roles & permissions levels

A role says what somebody may do; an address grant says what they may do it to.

End-to-end encryption

OpenPGP keys made in your browser. Mail you send to another OpenEmail address can be sealed before it leaves the tab, and sealed mail addressed to you opens in the reading pane, decrypted on your machine. The keys are never ours to hand over.

Start

## Your domain, your mail.

Point a domain at OpenEmail and read it in a mailbox built around it. The free plan covers one domain.

[Open mail](https://openemail.uk/mail/inbox) [Get Started](https://openemail.uk/signup.md)[Read the reference](https://openemail.uk/docs/knowledge/trust/account-security.md)
