Set Up Two-Factor Authentication for Your Email
Two-factor authentication (2FA) adds an important layer of protection to your email account. After you enter your password, you must also enter a temporary six-digit verification code generated by a trusted authenticator app.
This extra step helps protect your account if your password is exposed or stolen, because the password alone will not be enough to sign in.
We strongly recommend enabling two-factor authentication on every email account and keeping it enabled. Depending on your country, industry, organization, and the information handled through email, multi-factor authentication may be required by applicable laws, regulations, contractual obligations, or internal compliance policies.
Always confirm the requirements that apply to your organization and make sure two-factor authentication remains enabled when required.
Before you begin
You will need:
- Access to your ExtendyMail account through webmail.
- Your current email password.
- A TOTP authenticator app on your phone, such as Google Authenticator.
ExtendyMail uses a TOTP authenticator app for two-factor authentication. Most authenticator apps that support time-based one-time passwords (TOTP) can be used.
If you use an authenticator app, move the account to your new phone or disable and set up two-factor authentication again before resetting, replacing, or disposing of your current phone.
Enable two-factor authentication
Start by signing in to ExtendyMail webmail, then:
- Select Settings from the sidebar.
- From the settings menu, select Password.
- Select Two-factor authentication.
Enable 2FA with a TOTP authenticator app
- Choose the option to set up two-factor authentication with an authenticator.
- Select Enable with Google Authenticator.
- Enter your current email password when prompted.
- Open your authenticator app and scan the QR code shown in webmail.
- Enter the six-digit code generated by the authenticator app.
- Complete the setup.
After setup is complete, you will be signed out automatically. Sign in again using your email address and password, then enter the six-digit code from your authenticator app when requested.
Although the option may mention Google Authenticator, you can normally use another authenticator app that supports the TOTP standard.
Create an App Password after enabling 2FA
After enabling two-factor authentication, create an App Password for email applications such as Outlook, Apple Mail, and mobile mail apps.
Your normal email password will not work when adding a 2FA-protected account to these applications. Use the App Password instead. Using a separate App Password also lets you revoke access for an application without changing your main email password.
Follow Create and Manage App-specific Passwords to generate a separate password for each application or device.
Sign in with two-factor authentication
To sign in after enabling 2FA:
- Open the webmail login page.
- Enter your full email address and email password.
- Enter the six-digit verification code from your authenticator app.
While two-factor authentication is enabled, a password change may not take effect until 2FA is disabled. If you need to change your password, make sure you still have access to your verification method and follow your organization's security requirements before disabling 2FA.
Disable two-factor authentication
We do not recommend disabling two-factor authentication. Disabling it removes an important security layer and makes your account more vulnerable if your password is exposed.
It may also cause your account or organization to no longer meet applicable security or compliance requirements. Disable it only when necessary, and enable it again as soon as possible.
To disable two-factor authentication:
- Sign in to ExtendyMail webmail.
- Select Settings from the sidebar.
- Select Password, then Two-factor authentication.
- Select Disable.
- Enter your current email password, then select Submit.
- Enter the verification code from your authenticator app, then select Submit.
- Wait for the confirmation message.
After disabling 2FA, you can continue without it or set up a new authenticator device. We recommend setting it up again immediately.