Deliverability

Securing your email with a strong password and 2FA

You secure your email best with two layers: a strong, unique password and two-step verification (2FA). Together they ensure that someone who guesses or steals your password still can't get in. Don't worry: you need no technical knowledge for this, and it's sorted in a few minutes.

By the Mailflux team Published on

Anti-spam settings with a whitelist and blacklist

What is securing your email with 2FA?

Securing your email with 2FA means that logging in requires two proofs: something you know (your password) and something you have (usually a code on your phone). That second step is the core of two-step verification. Even if someone knows your password, they lack that code and your mailbox stays shut.

Your mailbox is often the key to the rest of your digital life: through "forgot password", whoever is in your mail can also take over your other accounts. That's why this is precisely the account to protect extra well. A more detailed explanation of the concept can be found at what 2FA for email is.

Why securing your email with 2FA matters

A password alone is a flimsy latch. Passwords leak in data breaches, get reused across multiple services, or are wheedled out of you through phishing. As soon as one of them is out in the open, your mailbox is wide open, unless there's a second lock on it.

For a doctor, lawyer or accountant, that's no abstract risk. Your mailbox holds sensitive data about clients and patients; a hijacked mailbox can mean a data breach, with reporting obligations and loss of trust. 2FA drastically reduces that chance, because a stolen password on its own is no longer enough to get in.

Think too of the domino effect. Whoever gains access to your mailbox can click "forgot password" at any number of other services and intercept the recovery mail. That way a whole row of accounts falls with one account: your webshop, your accounting package, your social media channels. This is exactly why your email is the account that deserves the most attention, and why that second step is so much more than a formality.

How it works

Security in two layers is simpler than it sounds. Here's how to go about it.

  1. Choose a strong, unique password. Long beats complicated: a string of four or five random words is strong and memorable. Don't use it anywhere else.
  2. Use a password manager. It remembers and generates unique passwords for you, so you only have to know one yourself.
  3. Turn on two-step verification. At the login screen you enter an extra code after your password. That code comes from an authenticator app on your phone, which is safer than a code by text message.
  4. Keep your recovery codes. When enabling it you get emergency codes; keep them in a safe place in case you lose your phone.

Want to see step by step how to activate that second step? Then follow the guide on setting up two-step verification.

Notice how small the effort is? Enabling it costs a few minutes once, and after that you only enter an extra code at a new login or on a new device. For that tiny hurdle you get an enormous leap in protection in return: it's one of the few security measures where the effort is so low and the gain so high.

What to watch out for

Run through these points to secure your mailbox properly:

  • Your email password is long, unique and used nowhere else.
  • You keep your passwords in a password manager, not on a note or in your browser without protection.
  • Two-step verification is on, preferably via an authenticator app.
  • Your recovery or emergency codes are in a safe, separate place.
  • You don't fall for fake mails asking for your login details or codes.
  • At any suspicion of misuse, you change your password immediately and check your active sessions.

Pay particular attention to that second-to-last one: no security helps if you hand over your code yourself. Attackers try to lure you through phishing into typing your 2FA code on a fake site. So never share codes, with anyone.

A few common mistakes to avoid. Never reuse the same password across multiple services: if one leaks, they all lie open. Don't store your recovery codes in the same mailbox you want to protect with them, because then a hijack also costs you your emergency exit. And don't store passwords unprotected in your browser on a shared computer. Small habits one by one, but together they make the difference between solid and apparent security.

Finally: 2FA is not a one-off job. If you get a new device, set up the authenticator app again and occasionally check which devices and sessions have access to your mailbox. That way you keep sight of exactly who can get in.

And at Mailflux

At Mailflux, two-step verification is optionally available in every plan, so you can secure your mailbox with a second lock. In addition, every plan filters with machine learning against spam, phishing and malware, with standard antivirus, anti-spam and anti-malware, and automatic backups. That way the threats that want to steal your password already face a closed door earlier.

You get professional email on your own domain, hosted in Europe and GDPR-compliant. One clear price per mailbox, billed annually, without superfluous extras, with the security basics neatly in order.

Ready to get started?

Professional email on your own domain, hosted in Europe and GDPR-compliant. Request your mailbox with no obligation.

Get started

FAQ

Frequently asked questions

Why isn't a strong password alone enough?

Passwords leak in data breaches, get reused or are stolen via phishing. As soon as one is out in the open, your account is exposed. Two-step verification adds a second proof (a code you have), so that a stolen password on its own is no longer enough to get in.

Which form of 2FA is safest?

A code from an authenticator app is generally safer than a code by text message, because text messages can be intercepted or redirected. Stronger still are physical security keys. For most users, an authenticator app is the best balance between security and convenience.

What if I lose the phone with the 2FA app?

That's what the recovery codes you received during setup are for: keep them in a safe, separate place. If you lose both your phone and your codes, you go through your provider's recovery procedure. Set up 2FA again on your new device straight away afterwards.