2FA-Email verification codes
Last updated
Last updated
This section explains how email verification codes work as a Multi-Factor Authentication (2FA) method for personal accounts, including:
When email-based 2FA is enabled
How the verification flow works during sign-in
What users should expect after enabling 2FA
📌 This guide applies only to email-based 2FA. Other 2FA methods (Authenticator App, Passkey) are documented separately.
If you want to add an extra layer of security to your account without installing additional apps, email verification codes are the easiest way to start.
When you enable Multi-Factor Authentication (2FA) in your account settings:
Email verification is automatically enabled by default
No additional setup is required
Security overview – 2FA enabled, email listed as active method
(example: /security page showing MFA enabled status)

Email verification codes help protect your account by requiring a one-time code sent to your email after you enter your password.
This ensures that:
Before using Email verification codes for MFA, make sure that:
✅ Once MFA is enabled, email verification is automatically activated (No additional configuration is required)
✅ Sign-in is completed automatically once the code is validated.
If you don’t see the verification email:
Even if someone knows your password, they cannot sign in without access to your email
Account access remains under your control
Your account email address is verified
You can access your email inbox
MFA is enabled in account security settings

Go to Account → Security
Turn on Multi-Factor Authentication
Open the Sign In page
Enter your email address and password
Click Sign In
Select email as the verification method.
Check your email inbox for the verification message.
Note: If you do not receive the verification code, see What should I do if I don't receive a verification code when signing up or forgot password?
Enter the verification code provided.
Check your spam / junk folder
Make sure your email address is correct
Wait a few seconds and request a new code
Email verification codes are one-time use
Codes expire after a short period for security reasons
Verification is required each time you sign in when MFA is enabled
Email MFA can be combined later with:
Authenticator App (TOTP)
Passkeys (FIDO2 / WebAuthn)
Item
Description
MFA method
Email verification codes
Setup required
None (enabled automatically with MFA)
Used during
Sign-in after password
Delivery channel
Registered email address
Security level
Medium (recommended baseline)
Best for
Users who want simple MFA without extra apps

