Mailbox Security: Password, Recovery Code, 2FA

Change a TrekMail mailbox password, issue a fresh recovery code, and check 2FA status — everything that hardens one mailbox now lives on the Security tab.

Article details

Type, difficulty, plans, and last updated info.

Type
Guide
Difficulty
Beginner
Plans
Starter · Pro · Agency
Last updated
Aug 16, 2026

Every TrekMail mailbox has a Security tab on its settings page. This is where you change the password, generate a fresh recovery code, and see whether two-factor authentication is on. Anything that protects who can sign in to that one mailbox is on this tab.

This page is for the account admin setting things up from the dashboard. If you own a mailbox and want to change your own password without bothering the admin, see Change Your Own Mailbox Password.

How to get there

  1. Open the Mailboxes page in your dashboard.
  2. Click a mailbox row to open its settings.
  3. Click the Security tab — it's the last one in the row, after Aliases, Forwarding, Filters, Auto-Reply, and Sieve.

The tab shows three sections, top to bottom: Two-factor authentication, Mailbox password, and Recovery code.

Two-factor authentication

This section shows whether 2FA is on for the mailbox. The status is also reflected in the page header — a green "2FA on" pill means it's enabled, a muted "2FA off" link means it's not.

2FA is configured by the mailbox owner from inside webmail, not from the dashboard. We do this on purpose — the TOTP secret only ever lives between the owner's authenticator app and our server, so even an account admin can't lift it. To enable or disable 2FA:

  1. The mailbox owner signs in at TrekMail webmail (or your tenant's branded URL).
  2. From the webmail settings, they enable 2FA and scan the QR code with an authenticator app (Google Authenticator, 1Password, Authy, etc.).
  3. Once confirmed, the Security tab in the dashboard immediately reflects the new state — no refresh needed.

After 2FA is on, every new sign-in for that mailbox — webmail, IMAP, SMTP — requires both the password and a fresh TOTP code. Existing sessions are not affected; if you want to invalidate them too, change the password (see below).

Mailbox password

The password section has a single form: enter a new password twice and click Save password. The form is the only way to set a mailbox password from the dashboard today — the old inline "key icon" shortcut in the mailbox list was removed in the May 2026 redesign.

Requirements (live-checked as you type):

  • At least 12 characters
  • At least one uppercase letter
  • At least one lowercase letter
  • At least one number

The Save button stays disabled until all four green checks are met.

If you'd rather not invent a password yourself, click Generate strong password under the input. We generate an 18-character mix of upper, lower, digits, and a small symbol set — no visually-confusing characters (i, l, 0, O, etc.). It's pasted into both fields automatically and revealed so you can copy it.

What changes the moment you click Save:

  • Every active IMAP, SMTP, and webmail session for this mailbox is terminated immediately. The user has to re-authenticate with the new password.
  • The previous password stops working everywhere — Outlook, iPhone Mail, scripts using SMTP, all of it.
  • Mail in the mailbox is unaffected — no messages are deleted, no folders rearranged.

If you're resetting because of a suspected compromise, this is the lock-out moment.

Recovery code

A recovery code is a one-time string that lets the mailbox owner sign in without their password or 2FA app — useful when the user has lost their phone or forgotten everything.

The card shows:

  • When the current code was issued (e.g. "Issued 3 days ago"), or "Not issued yet" if there's never been one.
  • A Generate new code button.

Clicking Generate opens a confirmation dialog and then displays the new code once in the dialog. Save it immediately — once you close the dialog there's no way to retrieve it. If you lose it, just generate another (the previous one is invalidated automatically — there's only ever one active code per mailbox).

Hand the code to the user through a secure channel (password manager Send link, Signal, in person). The user then uses it on the webmail "Forgot password?" page, Recovery code mode, to set a new password themselves.

If we stop a mailbox from sending

We watch the mail leaving every mailbox. When what is going out stops looking like the person who owns the mailbox — the pattern that a taken password produces — we stop that one mailbox from sending and leave everything else alone. Mail still arrives, the owner can still sign in and read, other mailboxes on the account are untouched, and your domain's reputation does not take the hit that a few hours of someone else's mail would cause.

It is a safety catch, not a punishment, and we will be in touch about it.

What to do:

  1. Change the mailbox password using the form above. This is the step that actually locks the other person out — stopping the sending only buys time.
  2. Put the new password into every place the mailbox is set up — phones, mail apps, and any script or tool that sends through it.
  3. Tell support you have done it, from the Support page. We switch sending back on; you cannot do that part yourself, by design.

While it is in force the mailbox behaves normally in every other respect, and anything written in webmail can be saved as a draft and sent once sending is back.

A few good habits

  • Use a different password than your TrekMail dashboard sign-in. A compromised mailbox should not let anyone into your billing or other mailboxes.
  • Keep the recovery code in a password manager. Not your inbox, not a sticky note — a manager that's separate from the mailbox you're protecting.
  • Turn on 2FA for high-value mailboxes (support@, billing@, shared team boxes). It's the single biggest password-theft defense you can add.

What's not on this tab

Some things you might expect here actually live elsewhere — by design:

  • Forwarding rules — Forwarding tab (next to Security in the tab strip). Forwarding rules are routing, not security.
  • Allowed senders / blocked senders — Filters tab. The Security tab is intentionally narrow to keep "who can sign in" separate from "what comes in."
  • Delete mailbox — the trash icon in the page header, top right. Sits next to Edit storage and is plan-side, not security-side.
  • Account-owner sign-in 2FA — that's a different setting on Account → Security, not on the mailbox itself. The two are independent: an account-owner can have 2FA on for the dashboard while individual mailboxes don't.

Related articles

Jump to nearby guides that continue the workflow.

We use cookies for essential functionality. No ads, no ad tracking.

Sign in to TrekMail

Access your dashboard, mailboxes and DNS.

or

12+ characters, and not one from a known data breach.

or

Reset email sent

If an account exists for this email, we've sent password reset instructions.

By continuing, you agree to TrekMail's Terms and Privacy Policy.