Glossary · Security

Two-factor authentication

Two-factor authentication requires a second proof, such as a code from an authenticator app, on top of a password to sign in.

A stolen password alone is then not enough. Time-based codes from an authenticator app (TOTP, RFC 6238) and hardware security keys are strong second factors; codes sent by SMS are weaker because phone numbers can be hijacked.

Mail apps that connect over IMAP and SMTP can't show a code prompt, so accounts with 2FA issue app passwords for them: long, random, per-app passwords you can revoke individually. A mailbox is the reset point for most other accounts, which makes it one of the most important places to turn 2FA on.

Business email that lands in the inbox.

Every domain you run in one inbox, from $3 a mailbox. 14 days free, no card.