Glossary · Security
Two-factor authentication requires a second proof, such as a code from an authenticator app, on top of a password to sign in.
A stolen password alone is then not enough. Time-based codes from an authenticator app (TOTP, RFC 6238) and hardware security keys are strong second factors; codes sent by SMS are weaker because phone numbers can be hijacked.
Mail apps that connect over IMAP and SMTP can't show a code prompt, so accounts with 2FA issue app passwords for them: long, random, per-app passwords you can revoke individually. A mailbox is the reset point for most other accounts, which makes it one of the most important places to turn 2FA on.
Every domain you run in one inbox, from $3 a mailbox. 14 days free, no card.