Two-factor authentication (2FA)
Two-factor authentication adds a second step to signing in: after your password, DMARCmetric asks for a short code that only you can produce. A stolen password alone is then not enough to get into your account. Like the rest of this section, this article describes the feature as it ships today.
A few facts up front:
- It is optional and off by default. Nothing changes for you until you turn it on.
- It belongs to your user, not to your workspace. Each member decides for their own account; turning it on does not affect anyone else in the workspace.
- You pick one of two methods — an authenticator app or emailed codes — and you can switch later.
- Where it lives: your account page, in the Two-factor authentication card just below Change password.
Which method?
| Authenticator app | Email codes | |
|---|---|---|
| The code | Six digits from an app such as Google Authenticator, 1Password, Authy or Microsoft Authenticator (standard TOTP, changes every 30 seconds) | Six digits emailed to your account address, valid for 5 minutes |
| Works offline? | Yes — the app needs no network | No — the mailbox must be reachable |
| If you lose access | Ten single-use backup codes, shown once at setup | The mailbox itself |
| Protects against | A stolen password, and a compromised mailbox | A stolen password |
Our honest recommendation is the app. Your mailbox can already reset your password, so emailed codes protect you when someone knows your password but not when someone controls your mailbox. Email codes are still a real improvement over a password alone, and they are the right choice if you cannot install an app.
Turn on an authenticator app
- On your account page, press Set up an authenticator app and enter your current password. The password is asked for because this step creates a new secret for your account.
- Scan the QR code with your app, or type the key shown under it by hand.
- Save the ten backup codes. They are shown exactly once — use Copy codes or write them down and keep them somewhere safe. Each code signs you in one time if you cannot use the app.
- Enter the six-digit code your app shows and press Turn on.
Nothing is enforced until that first code is accepted. If you close the page halfway through, two-factor stays off and the backup codes you saw do not work; simply start again from Set up an authenticator app.
Turn on email codes
- Press Use email codes. A code is mailed to your account address straight away — the subject line is Your DMARCmetric sign-in code, and the message never contains a link. A message that looks like ours but asks you to click something is not from us.
- Enter the code and press Turn on. No password is asked for here: this method only adds a check of a mailbox you have already verified.
If the code does not arrive within a minute, check your spam folder and use Resend code (it becomes available after 30 seconds). If the page tells you We could not send the code to your address, our mail provider refused the message; try Resend code once, and if it keeps failing the support box at the bottom of this page is the way forward.
Signing in once it is on
Sign in with your email and password as usual. Instead of the dashboard you see a code step on the same page:
- App users type the six digits from the app. If the phone is not at hand, Use a backup code instead accepts one of your saved codes.
- Email users get a code mailed automatically the moment the step appears, with Resend code available after 30 seconds. Each mailed code is valid for 5 minutes.
- Remember this device for 30 days skips the code step on that browser for 30 days, counted from your most recent sign-in there — each sign-in that skips the code renews the 30 days. It never skips the password. The choice is per browser — a different browser, device or private window is asked for a code again.
If the sign-in attempt expires or is discarded, the code form is replaced by the message and a Back to sign in button, which simply starts over.
Limits that protect you
These are the numbers behind the messages you might see:
- Ten wrong codes are the limit for one sign-in attempt. The next try is refused with Too many wrong codes. Please sign in again. — the pending sign-in is discarded and you start from the password. Nothing happens to your account itself.
- A sign-in attempt lasts ten minutes. Enter a code (or press Resend) after that and the page answers Your sign-in expired. Please sign in again. — you start from the password.
- At most five codes are mailed per sign-in attempt — the automatic first one counts, and so does a send our provider refuses. The last code you received still works; if you need more, sign in again.
- Each emailed code allows five guesses before the page asks you to request a new one.
- Every code endpoint is also rate-limited per IP address, so a script cannot hammer the code step.
Backup codes
- Only the authenticator-app method has backup codes; email users recover through the mailbox.
- Each of the ten codes works once. Using one at sign-in consumes it.
- New backup codes on the account page (with your password) replaces the whole set — every old code stops working the moment the new list appears. Save the new list; it is also shown only once.
Turning it off, or changing method
- Disable two-factor asks for your password and turns the feature off completely. It also forgets every remembered device, not only the browser you are using — any sign-in that was waiting for a code elsewhere is cancelled too.
- Changing method, or moving to a new phone: disable two-factor first, then set it up again with the method you want. The setup buttons only appear while two-factor is off. We never show an existing QR code or secret a second time; a fresh setup always creates a fresh secret and fresh backup codes. That is deliberate — an account should never hold a key that nobody has scanned.
If you are locked out
- App user who has lost the phone but has backup codes: sign in with a backup code, then disable two-factor and set it up again on the new phone.
- App user who has lost both the phone and the backup codes: there is no self-service way back in — that is what makes the method strong. Email support from the address on your account; after we have confirmed it is you, we turn two-factor off so you can sign in and set it up again. We will never mail you a backup code or read one out.
- Email user whose codes do not arrive: check spam first, then contact support if the page reports that the address was refused.
What two-factor does not do today
- Turning it on or off does not sign you out of other browsers where you are already signed in.
- Changing your password does not forget remembered devices — use Disable two-factor and set it up again if you want every device forgotten.
- There is no workspace-wide requirement: an owner cannot make two-factor mandatory for other members.
- There are no passkeys and no SMS codes.
The cookies involved — one that holds a sign-in that is waiting for its code, and one that remembers a device for 30 days — are described in our Privacy Policy. For the wider picture of how your account is protected, see Security and privacy at DMARCmetric.