Why it matters
A password can leak without you knowing: reused on another site that got breached, guessed, or captured by a convincing phishing email. The day that happens, it is not only your account at stake.
With the second factor on, a stolen password is not enough: without your phone, the login is refused.
How it works
At login, Mailpro asks for two things of a different nature:
That is the whole point: an attacker can steal the first remotely, but would also need your phone in hand. The code is computed offline by your app — it travels neither by SMS nor by email, two channels we now know can be intercepted.
Setup
There is nothing to install on the Mailpro side, and no in-house app to download.
Google Authenticator, Microsoft Authenticator, Authy, 1Password, Bitwarden… whichever you like. Mailpro uses the TOTP standard, so they are all compatible. If you already use one for another service, keep it.
Go to My account → Security and turn on the two-factor authentication switch. A QR code appears: scan it with your app, which will then add Mailpro to its list.
Enter the code shown by the app and validate. That is it: it will be asked at every login, right after your password.
This is the question that holds people back the most, and the answer is simple: an administrator on your account can turn off your two-factor authentication from My account → Users. You then log in with your password alone and re-enable 2FA on your new phone. If you are alone on the account and no longer have access to your app, contact our support from the account email address.
Yes, after your password. In practice it adds about ten seconds: you open the app, read six digits, type them in. That is the price of making a stolen password useless.
In almost every case, the phone clock is to blame. The code is derived from the time: if your phone is set manually and drifts by more than a few dozen seconds, the codes no longer match. Turn on automatic date and time on your device, then try again.
Yes, from My account → Security, with the same switch. We advise against it: it is the strongest protection for the smallest effort you can put on your account.
Each user enables 2FA on their own access. From My account → Users, an administrator sees at a glance who has it on and who does not — handy to chase the stragglers. If you manage several user accounts, that is the first screen to check.
Log in, open My account → Security, and follow the three steps. You only have to do it once.
Your data and your contacts’ data stay on our Swiss servers, under Swiss law, since 2001.
Every connection to Mailpro is protected by TLS 1.3, including the exchange of your authentication code.
Securing access to the personal data you process is part of your obligations. 2FA contributes directly.