Two-factor authentication for email: what it is and how to turn it on
How 2FA stops stolen passwords from becoming stolen accounts, which method to choose, and what to do about apps that cannot handle a code prompt.
A password can be guessed, phished or found in a breach dump. Two-factor authentication adds a second, independent check, so that knowing the password is not enough to get in. For an email account — the address that can reset every other password you own — it is the single highest-value security setting available.
Turning on 2FA
- Open your account's security settings in webmail.
- Choose a second factor: an authenticator app, an SMS code, or a hardware key if supported.
- If you chose an authenticator app, scan the QR code with it and enter the six-digit code it shows to confirm.
- Save the recovery codes somewhere offline — a password manager or a printed copy in a safe place. These are what get you back in if you lose the phone.
- Mark the devices you use daily as trusted, so you are not prompted on every sign-in.
- Generate app passwords for any mail client that cannot show a code prompt (older desktop clients, some phone mail apps).
- Sign out and back in once to confirm the whole flow works before you rely on it.
Choosing a method
Authenticator app — codes generated on your device, working offline, immune to SIM swapping. The right default for most people.
SMS — convenient and better than nothing, but vulnerable if someone can take over your phone number. Fine as a fallback.
Hardware key — a physical device you tap or plug in. The strongest option, and effectively phishing-proof, because the key checks the site's identity for you.
Email to another address — weakest, since it merely moves the problem to another mailbox.
App passwords, and why you need them
IMAP and SMTP have no way to prompt for a code. When 2FA is on, mail clients therefore authenticate with an app password: a long, random, single-purpose credential you generate in account settings. Create one per application, and revoke it if the device is lost — the account password stays untouched.
If you lose your second factor
This is what recovery codes are for. Without them, recovery depends on the provider's identity-verification process, which is deliberately slow. Store the codes when you set up 2FA, not later, and keep a second factor registered where possible — for example an authenticator app on a tablet as well as a phone.
Frequently asked questions
Does 2FA slow down daily use? Barely. Trusted devices mean you enter a code occasionally, not every time.
Is SMS 2FA worth using? Yes, if the alternative is nothing. An authenticator app is better where it is offered.
What if I change phones? Move your authenticator entries before wiping the old phone; most apps support an encrypted transfer or cloud backup.
Can 2FA be bypassed? Sophisticated phishing can proxy a code in real time. A hardware key defends against that; so does never entering a code on a page you reached from a link.
2FA at imail.com.tr
imail webmail supports two-factor authentication with trusted devices, and app passwords for mail clients. If you have just created an account, turning 2FA on is the first thing worth doing — see the features page, or start with our guide to creating an account.
Free, ad-free email
15 GB of storage, KVKK compliant, your own @imail.com.tr address.
Create a free account