Mail.com 2FA: How to Set Up an Authenticator App
Two-factor authentication gives your mail.com mailbox extra protection on top of your password. mail.com requires an authentication app for it, which generates a unique, temporarily valid security code each time you log in, so Authenticator App - Novaz can supply your codes.
Your Mail.com inbox is the master key to your other accounts — attackers use it to reset passwords everywhere. Mail.com secures sign-ins with an authenticator app — set it up once and you're protected on every login.
2FA methods Mail.com supports
- Authenticator app (TOTP)
Before you start
- Your mail.com email address and password (the setup assistant asks for the password before it starts)
- A mobile phone that can receive SMS: the setup verifies your number, and mail.com needs a verified number to reset your password if you're ever locked out
- Authenticator App - Novaz installed on your iPhone or iPad
- mail.com open on a computer, so you can scan the QR code with your phone
- A safe place for the secret key PDF you download during setup; mail.com recommends printing it
- The latest version of the mail.com Mail app, if you use it: mail.com says you need it for two-factor authentication
Part 1: Turn on 2FA in Mail.com
- 1
Open Security Options
Log in on the mail.com website, click "Account" at the top right, then click "Security Options" on the left.
- 2
Start the setup assistant
Under "Two-factor authentication", click "Activate two-factor authentication". The setup assistant opens and lists what you'll need; click "Start setup now".
- 3
Enter your password
Enter the password for your email address and click "Start now".
- 4
Verify your mobile phone number
Enter a mobile phone number, or check the one mail.com shows and click "Change" if it's out of date. Click "Request SMS", enter the confirmation code from the text message and click "Continue". No SMS? Click "Resend SMS".
Part 2: Add Mail.com to Authenticator App - Novaz
- 5
Add mail.com in Authenticator App - Novaz
mail.com now shows a QR code. Open Authenticator App - Novaz, tap the + button and scan it. If it won't scan, use "Copy code" (see the tips below). Name the account "mail.com" and tap "Save".
- 6
Note the 6-digit code
Authenticator App - Novaz now shows a 6-digit code for mail.com. It changes every 30 seconds, so have it ready for the next step.
Part 3: Confirm and finish
- 7
Enter the code
Back on mail.com, enter the 6-digit authentication code from the app and click "Continue".
- 8
Save your secret key
For emergency access, click "Save your secret key" to download a PDF with your secret key. Keep it somewhere secure; mail.com recommends printing it.
- 9
Click Activate now
Check your personal information, click "Next", then "Activate now". Two-factor authentication is on, and from now on mail.com asks for your password and a code from Authenticator App - Novaz each time you log in.
- 10
Save a way to recover your account
If Mail.com offers backup or recovery codes, download them or write them down and store them somewhere safe. They are how you get back into your account if you ever lose your phone. If it doesn't, check how Mail.com recovers accounts before you need it.
If something goes wrong
- The code doesn't work: it may have expired, so enter the next one. Also make sure your iPhone sets its date and time automatically (Settings > General > Date & Time).
- The QR code won't scan, or it's on your iPhone's own screen: click or tap "Copy code" under the QR code and paste the code into Authenticator App - Novaz as a setup key. From a computer, mail.com suggests sending the code to yourself in a message first.
- Your email program stopped working: if it uses POP3/IMAP, reactivate access in your mail.com email settings and give the program an application-specific password (see the FAQ below) instead of your mail.com password.
Checked against Mail.com's own help pages on September 25, 2026. Menu names can change, so these pages have the current path:
- Setting up two-factor authentication – mail.com Help ↗
- Two-factor authentication – mail.com Help ↗
- What should I do if I’ve activated 2FA, but lost access to the authentication app or it is not working? – mail.com Help ↗
- Problems with scanning the QR code – mail.com Help ↗
- How do I set up application-specific-passwords? – mail.com Help ↗
How to recover your Mail.com account
mail.com's help doesn't describe backup codes. Your way back in is the secret key you saved during setup. If you lose your phone or can't use Authenticator App - Novaz, start the password recovery process at password.mail.com and enter the secret key when asked. That turns off two-factor authentication so you can log in without the 6-digit code; you can turn it on again afterwards. The same applies if you forget your password. Lost the secret key? Search your computer for the PDF, starting with the download folder; if it's gone, contact mail.com customer support. mail.com warns that 2FA can't be switched off instantly: a stringent verification process is required, and it isn't always successful.
Frequently asked questions
- What is the secret key for?
- It's your emergency access. During password recovery, mail.com asks for the secret key and then turns off two-factor authentication, so you can get back in if your authentication app is lost.
- Will my email program still work with 2FA on?
- External programs that use POP3/IMAP, or CalDAV and CardDAV for your calendar and address book, need an application-specific password. Create one under "Security Options" > "Manage application-specific passwords" > "Create new application-specific password". It's shown only once, so write it down.
- Do I need to log in again in the mail.com Mail app?
- Yes, once: after you turn on two-factor authentication, log in again in the mail.com Mail app, mail.com MailCheck and any program that uses POP3/IMAP.
Generate your Mail.com codes in Authenticator App - Novaz
Free, offline, and encrypted. One tap for every 6-digit code.
Get the appMore Email guides
Novaz is not affiliated with, endorsed by, or sponsored by Mail.com. Mail.com and its logo are trademarks of their respective owner and are used here for identification only.



