Two-Factor Authentication (2FA / TOTP)
Enable or disable TOTP-based 2FA for your account.
Article details
Type, difficulty, plans, and last updated info.
▼
Article details
Type, difficulty, plans, and last updated info.
- Type
- Guide
- Difficulty
- Beginner
- Plans
- Nano · Starter · Pro · Agency
- Last updated
- Sep 9, 2026
Your TrekMail account controls all your domains, mailboxes, and billing. If someone gains access to it through a leaked password, phishing, or credential stuffing, they could change important settings or lock you out.
Two-factor authentication (2FA) reduces this risk by requiring a second proof of identity when you log in. A stolen password alone is not enough to complete the normal sign-in flow.
How 2FA works in TrekMail
TrekMail uses TOTP (time-based one-time passwords). An authenticator app generates a short code that changes regularly. After your password, TrekMail asks for the current code.
Setting up 2FA
You will need a TOTP-compatible authenticator app or password manager. Check that it can back up or transfer your TOTP entries in the way you expect, then install and test it before starting the steps below.
Before enabling 2FA, decide where the recovery codes will live. A password manager secure note is usually more reliable than a screenshot or an unprotected download folder. Do not share the QR code, the manual secret, or a recovery code with support or another person.
To enable 2FA:
Before starting, verify your dashboard sign-in email. TrekMail does not allow 2FA to be enabled on an unverified account.
- Log in to the TrekMail dashboard.
- Click your avatar or name and choose Account.
- Find the Two-factor authentication section and click Enable.
- Open your authenticator app and scan the QR code shown on screen
- Your app displays a current code. Enter it in the confirmation field.
- Confirm that you saved the recovery codes, then click Verify.
Save your recovery codes now. TrekMail shows eight one-time recovery codes while you set up 2FA. Store them in a password manager or another safe place. They are not shown again after setup.
Logging in with 2FA enabled
After entering your email and password, you see a second screen asking for a code:
- Open your authenticator app
- Find the TrekMail entry and copy its current code.
- Enter the code.
- Click Verify.
You are then logged in normally. The current session remains active until you sign out, it expires, or TrekMail revokes it after a security-sensitive account change.
Disabling 2FA
If you need to remove 2FA, for example to switch to a new authenticator app:
- Go to Account → Two-factor authentication.
- Click Disable Two-Factor Authentication
- Enter the current 6-digit code from your authenticator app to confirm
- 2FA is removed immediately
After disabling, log in with just your password until you re-enable it.
Recovery codes
Recovery codes are single-use. A used code cannot be used again. TrekMail shows them only during enrollment and does not provide a separate “view” or “regenerate” screen. If you still have access to your account but no recovery codes, save new ones by disabling 2FA with your authenticator code and then enabling it again.
Troubleshooting
Code is always rejected even though it looks correct The most common cause is that your phone's clock is out of sync. TOTP codes are time-based, so even a small clock difference can cause repeated failures.
- On iPhone: Settings → General → Date & Time → Set Automatically (enable)
- On Android: Settings → System → Date & Time → Use network-provided time (enable)
Lost your phone or deleted the authenticator app Use one of your recovery codes on the login screen. Choose the recovery-code option, then enter one saved code. Once signed in, disable 2FA and enable it again with the new authenticator.
You do not have recovery codes and cannot log in Contact TrekMail support and explain that you lost both the authenticator and recovery codes. Support will tell you what account-ownership information is needed; do not send a password or a recovery code in a ticket.
Related articles
Jump to nearby guides that continue the workflow.