DMARCmetric

Two-factor authentication (2FA)

Updated 2026-09-06 · FAQ & Account

Two-factor authentication adds a second step to signing in: after your password, DMARCmetric asks for a short code that only you can produce. A stolen password alone is then not enough to get into your account. Like the rest of this section, this article describes the feature as it ships today.

A few facts up front:

Which method?

Authenticator appEmail codes
The codeSix digits from an app such as Google Authenticator, 1Password, Authy or Microsoft Authenticator (standard TOTP, changes every 30 seconds)Six digits emailed to your account address, valid for 5 minutes
Works offline?Yes — the app needs no networkNo — the mailbox must be reachable
If you lose accessTen single-use backup codes, shown once at setupThe mailbox itself
Protects againstA stolen password, and a compromised mailboxA stolen password

Our honest recommendation is the app. Your mailbox can already reset your password, so emailed codes protect you when someone knows your password but not when someone controls your mailbox. Email codes are still a real improvement over a password alone, and they are the right choice if you cannot install an app.

Turn on an authenticator app

  1. On your account page, press Set up an authenticator app and enter your current password. The password is asked for because this step creates a new secret for your account.
  2. Scan the QR code with your app, or type the key shown under it by hand.
  3. Save the ten backup codes. They are shown exactly once — use Copy codes or write them down and keep them somewhere safe. Each code signs you in one time if you cannot use the app.
  4. Enter the six-digit code your app shows and press Turn on.

Nothing is enforced until that first code is accepted. If you close the page halfway through, two-factor stays off and the backup codes you saw do not work; simply start again from Set up an authenticator app.

Turn on email codes

  1. Press Use email codes. A code is mailed to your account address straight away — the subject line is Your DMARCmetric sign-in code, and the message never contains a link. A message that looks like ours but asks you to click something is not from us.
  2. Enter the code and press Turn on. No password is asked for here: this method only adds a check of a mailbox you have already verified.

If the code does not arrive within a minute, check your spam folder and use Resend code (it becomes available after 30 seconds). If the page tells you We could not send the code to your address, our mail provider refused the message; try Resend code once, and if it keeps failing the support box at the bottom of this page is the way forward.

Signing in once it is on

Sign in with your email and password as usual. Instead of the dashboard you see a code step on the same page:

If the sign-in attempt expires or is discarded, the code form is replaced by the message and a Back to sign in button, which simply starts over.

Limits that protect you

These are the numbers behind the messages you might see:

Backup codes

Turning it off, or changing method

If you are locked out

What two-factor does not do today

The cookies involved — one that holds a sign-in that is waiting for its code, and one that remembers a device for 30 days — are described in our Privacy Policy. For the wider picture of how your account is protected, see Security and privacy at DMARCmetric.

Still stuck?

We answer every message — usually within one business day.

Email [email protected]