Docs · Security
Security: 2FA & sessions
Your mailbox is the reset point for most of your other accounts, so SuperMailOS gives you the controls to keep it locked down: two-factor authentication, visibility over active sessions, and separate app passwords for mail clients.
Two-factor authentication (TOTP)
Two-factor authentication adds a second step to sign-in: even if your password leaks, an attacker still needs the rotating code from your authenticator app.
- Open Settings → Security.
- Start two-factor setup and scan the QR code with any TOTP authenticator app.
- Confirm by entering the current 6-digit code. Once it’s accepted, two-factor is active on your next sign-in.
If your provider offers recovery codes during setup, store them somewhere safe and offline — they’re how you get back in if you lose your authenticator.
App passwords for mail clients
Apple Mail, Outlook and other IMAP/SMTP apps sign in with a username and password directly, which doesn’t fit a two-factor prompt. The answer is an app password: a separate, revocable password scoped to one client. Generate one under Settings → Security → App passwords, use it in the mail app in place of your login password (see connect a mail app), and revoke it any time without touching your main login.
Sessions
Your security settings show where your account is currently signed in. If you see a session you don’t recognise — or you’ve signed in on a shared machine — sign it out there, and change your password if anything looks off.
Password resets
Password-reset and other system mail is sent from a dedicated system address on its own subdomain, kept separate from tenant sending so it never affects your domain’s reputation. If a reset email doesn’t arrive, check spam and confirm the address on your account.
Next: deliverability & inbox placement or migrate your existing mail.