Skip to main content

Sign-in codes by e-mail

Applies to: identity after 0.32, mail after 0.30.1 · Checked: 27.09.2026

A second factor for people without an authenticator app: after the password identity sends an eight-digit code to the person's personal address, and the sign-in goes on only with that code. Off by default.

Why not the work mailbox​

In SimpleTwo the work mailbox opens with the same password as the identity sign-in. A code sent there can be read by anybody who knows the password, so it is not a second factor. Codes therefore go only to an external address the person has confirmed. An address in any of the organisation's domains — the mail role's domains, the company provider's domains, the domain of the person's login — or in any subdomain of them is refused by identity and again by the mail role.

How to turn it on​

It needs the mail role with an MX node: the letter leaves through it, from no-reply@<the organisation's first domain>, and is DKIM-signed on the MX node like any outbound letter. There is nothing else to configure: the coordinator tells identity where the mail node is.

In the identity console, on the Policies tab, in the Sign-in requirements block, set Sign-in codes by e-mail to on and save. Without a mail role, with one that does not answer, or with one that has no MX node, the console refuses and says why.

In the credential policy's JSON the field is email_codes: off (the default) or on.

How a person adds the address​

In the portal /me, on the Security tab, a Sign-in codes by e-mail card appears.

  1. The person enters a personal address and the current password and presses Send a confirmation code. The password is asked so that somebody holding an open session cannot put in an address of their own.
  2. A letter with a code arrives at the address. The person enters the code in the portal and presses Confirm the address.
  3. From then on the address is a second factor. Another address replaces it only once it has been confirmed itself. Turning it off is in the same card, with the password too.

What the sign-in looks like​

After the password, on the sign-in page:

  • when the e-mail code is the only second factor, the letter goes at once and the page asks for the code from it; Send another code is there for a letter that did not arrive;
  • when there is also an authenticator app, the page asks for its code first, with Send a code by e-mail instead below the field.

A code works once, for 10 minutes. Five wrong tries burn it; wrong codes count toward the account's lockout the same way a wrong authenticator code does. At most five codes an hour per account (confirmations and sign-ins together) and twenty from one source address. When the letter could not be sent, the page says so and does not let the sign-in through.

The sign-in log records such a sign-in as "password + e-mail code", the ID token as amr with email and mfa. A password and an e-mail code are two factors. An authenticator code and an e-mail code are not: both are "something that arrived on a device".

E-mail codes count for the "Require a second factor" policy and for an application's require_mfa on identity's sign-in page. The messenger's password sign-in does not take them — it asks only for an authenticator code — so after the grace period the messenger sends a person who has only an address to the portal to add an authenticator app, as it does a person who has only a passkey.

Help desk​

Reset 2FA on the person's page in the console removes the confirmed address too, together with the authenticator and the passkeys. In the people list the factor shows as "e-mail code" and counts as a second factor for "Administrators without a second factor".

Not yet​

  • "Forgot password?" does not use the confirmed address: the reset code still arrives only in the SimpleTwo apps where the person is already signed in.
  • A notice on the person's devices that a new address was added.