Mailbox Security: Password, Recovery Code, 2FA

Change a TrekMail mailbox password, issue a fresh recovery code, and check 2FA status — everything that hardens one mailbox now lives on the Security tab.

Article details

Type, difficulty, plans, and last updated info.

Type
Guide
Difficulty
Beginner
Plans
Starter · Pro · Agency
Last updated
Sep 9, 2026

Every regular TrekMail mailbox has a Security tab on its settings page. This is where you change the password, generate a fresh recovery code, and see whether two-factor authentication is on. Shared mailboxes have no direct login, so their settings show Access instead.

This page is for the account admin setting things up from the dashboard. If you own a mailbox and want to change your own password without bothering the admin, see Change Your Own Mailbox Password.

How to get there

  1. Open the Mailboxes page in your dashboard.
  2. Click Manage next to a regular mailbox.
  3. Click the Security tab. The other tabs vary by mailbox type, plan, and status.

The tab shows three sections, top to bottom: Two-factor authentication, Mailbox password, and Recovery code.

Two-factor authentication

This section shows whether 2FA is on for the mailbox. The status is also reflected in the page header, a green "2FA on" pill means it's enabled, a muted "2FA off" link means it's not.

2FA is configured by the mailbox owner from inside webmail, not from the dashboard. The owner scans and confirms their own authenticator-app secret. An authorized administrator can reset 2FA when the owner is locked out, but cannot turn it on for them. To enable or disable 2FA:

  1. The mailbox owner signs in at TrekMail webmail (or your tenant's branded URL).
  2. From the webmail settings, they enable 2FA and scan the QR code with an authenticator app (Google Authenticator, 1Password, Authy, etc.).
  3. Once confirmed, return to the Security tab or refresh it to see the new status.

After 2FA is on, new webmail sign-ins require the password and a TOTP or 2FA recovery code. IMAP and SMTP clients continue to use the mailbox password. Existing sessions are not affected; see the password notes below if you need to change credentials.

Mailbox password

The password section has a single form: enter a new password twice and click Save password. The form is the only way to set a mailbox password from the dashboard today, the old inline "key icon" shortcut in the mailbox list was removed in the May 2026 redesign.

Requirements (live-checked as you type):

  • At least 12 characters
  • At least one uppercase letter
  • At least one lowercase letter
  • At least one number

The Save button stays disabled until all four green checks are met.

If you'd rather not invent a password yourself, click Generate strong password under the input. We generate an 18-character mix of upper, lower, digits, and a small symbol set, no visually-confusing characters (i, l, 0, O, etc.). It's pasted into both fields automatically and revealed so you can copy it.

What changes after a successful save:

  • The previous password stops working for new webmail, IMAP, and SMTP sign-ins. Update Outlook, phones, scripts, and other clients before expecting them to reconnect.
  • Trusted-device access is revoked. Existing webmail sessions are not automatically closed by an administrator password change, so use a mailbox suspension or other incident response steps if an active session is a concern.
  • Mail in the mailbox is unaffected. No messages or folders are deleted.

If you're resetting because of a suspected compromise, this is the lock-out moment.

Recovery code

A recovery code is a one-time string that lets the mailbox owner reset their password when they cannot use the current one. It does not sign them in directly or replace their separate 2FA recovery codes.

The card shows:

  • When the current active code was issued (e.g. "Issued 3 hours ago"), or "Not issued yet" when no usable code remains.
  • A Generate new code button.

Clicking Generate opens a confirmation dialog and then displays the new code once in the dialog. Save it immediately. Once you close the dialog there is no way to retrieve it. The code expires after 24 hours; generating a new one invalidates all earlier mailbox-password recovery codes, including a legacy code saved during older mailbox setup.

Hand the code to the user through a secure channel (password manager Send link, Signal, in person). The user then uses it on the webmail "Forgot password?" page, Recovery code mode, to set a new password themselves.

If we stop a mailbox from sending

We watch the mail leaving every mailbox. If outgoing activity suggests that a mailbox password has been misused, we can stop that one mailbox from sending and leave everything else alone. Mail still arrives, the owner can still sign in and read, other mailboxes on the account are untouched, and your domain's reputation is protected.

It is a safety catch, not a punishment, and we will be in touch about it.

What to do:

  1. Change the mailbox password using the form above. This is the step that actually locks the other person out, stopping the sending only buys time.
  2. Put the new password into every place the mailbox is set up: phones, mail apps, and any script or tool that sends through it.
  3. Tell support you have done it, from the Support page. We switch sending back on; you cannot do that part yourself, by design.

While it is in force the mailbox behaves normally in every other respect, and anything written in webmail can be saved as a draft and sent once sending is back.

A few good habits

  • Use a different password than your TrekMail dashboard sign-in. A compromised mailbox should not let anyone into your billing or other mailboxes.
  • Keep the recovery code in a password manager. Not your inbox, not a sticky note, a manager that's separate from the mailbox you're protecting.
  • Turn on 2FA for high-value regular mailboxes. Shared mailboxes do not sign in directly, so protect them by keeping each member's own mailbox secure.

What's not on this tab

Some things you might expect here actually live elsewhere, by design:

  • Forwarding rules: Forwarding has its own tab. It is routing, not security.
  • Allowed senders / blocked senders: Filters tab. The Security tab is intentionally narrow to keep "who can sign in" separate from "what comes in."
  • Delete mailbox: the trash icon in the page header, top right. Sits next to Edit storage and is plan-side, not security-side.
  • Account-owner sign-in 2FA: that's a different setting on Account → Security, not on the mailbox itself. The two are independent: an account-owner can have 2FA on for the dashboard while individual mailboxes don't.

Related articles

Jump to nearby guides that continue the workflow.

We use necessary technologies to operate and secure TrekMail. Selecting Okay also allows limited analytics and advertising measurement described in our Cookie Policy.

Sign in to TrekMail

Access your dashboard, mailboxes and DNS.

or

12 characters passwords match

or

Reset email sent

If an account exists for this email, we've sent password reset instructions.

By continuing, you agree to TrekMail's Terms and Privacy Policy.