Docs · Security

Security: 2FA & sessions

Your mailbox is the reset point for most of your other accounts, so SuperMailOS gives you the controls to keep it locked down: two-factor authentication, visibility over active sessions, and separate app passwords for mail clients.

Two-factor authentication (TOTP)

Two-factor authentication adds a second step to sign-in: even if your password leaks, an attacker still needs the rotating code from your authenticator app.

  1. Open Settings → Security.
  2. Start two-factor setup and scan the QR code with any TOTP authenticator app.
  3. Confirm by entering the current 6-digit code. Once it’s accepted, two-factor is active on your next sign-in.

If your provider offers recovery codes during setup, store them somewhere safe and offline — they’re how you get back in if you lose your authenticator.

App passwords for mail clients

Apple Mail, Outlook and other IMAP/SMTP apps sign in with a username and password directly, which doesn’t fit a two-factor prompt. The answer is an app password: a separate, revocable password scoped to one client. Generate one under Settings → Security → App passwords, use it in the mail app in place of your login password (see connect a mail app), and revoke it any time without touching your main login.

Sessions

Your security settings show where your account is currently signed in. If you see a session you don’t recognise — or you’ve signed in on a shared machine — sign it out there, and change your password if anything looks off.

Password resets

Password-reset and other system mail is sent from a dedicated system address on its own subdomain, kept separate from tenant sending so it never affects your domain’s reputation. If a reset email doesn’t arrive, check spam and confirm the address on your account.

Next: deliverability & inbox placement or migrate your existing mail.