Turn on two-factor protection
A second step at sign-in: a six-digit code from an app on your phone. It takes five minutes to set up. The important part of this guide is not the setting up, though — it is the backup codes. Without them, a lost phone means a lost mailbox.
Why bother
A password can be read over your shoulder, guessed from a leak on another site, or coaxed out of you by a message that looks like ours. All of this happens to careful, attentive people too — just less often.
A code from the app lives for thirty seconds and never travels: the app and the server each work it out on their own from a shared secret. Knowing your password stops being enough — someone also needs your phone in their hand.
Which app to install
Any app that follows the TOTP standard will do; there are dozens and they are interchangeable. Ones we have tried:
- Google Authenticator — simple, on both platforms.
- Microsoft Authenticator — can back itself up to the cloud.
- Aegis (Android) and Raivo (iOS) — open source, codes kept encrypted.
- 2FAS — open source, with backup and a browser companion.
- Bitwarden and 1Password — if you already keep your passwords in one of these, you need nothing extra.
How to turn it on
- Sign in to your account and open the Security section.
- Press "Turn on two-factor protection" — a square code appears.
- In the app, choose to add an account and point the camera at the code. No camera? Type the sixteen-character key by hand.
- The app shows a six-digit number — enter it in the field on the page. It changes every half minute; if you miss it, wait for the next one.
- Save the backup codes the page then shows you. This is the only time they are visible.
Backup codes: where to put them
Eight one-time codes. Each works exactly once and stands in for a code from the app. They are the only way back in if the phone drowns, breaks, or stays behind in a taxi.
Good places: printed and kept with your documents; written in a paper notebook; stored in a password manager — but not on the same phone that holds the app.
Bad places: a screenshot in the phone gallery, a note inside this same mailbox, a file called "codes" on the desktop.
What changes afterwards
Signing in to the site and to webmail will ask for a code. Your mail app on the phone or computer, however, will stop connecting with the ordinary password: IMAP and SMTP have no way to ask for a second step.
For those you create a separate app password — a short guide of its own, and without it the mail on your phone goes quiet.
If both the phone and the codes are gone
What remains is account recovery through the contact form. It is not quick: we have to satisfy ourselves that the mailbox is yours, and we ask things only the owner would know. While the check runs, the mailbox keeps working but you cannot get into it.
Which is why backup codes are worth saving before you need them, not after.