Start

How to Enable Two-Factor Authentication (2FA/MFA)

Enable 2FA on your Postscale account with an authenticator app, security key, Touch ID, or Windows Hello, and learn how to use recovery codes.

Updated

TL;DR

Open Dashboard > Settings and scroll to Security. Set up an authenticator app for 6-digit time-based codes, or add a security key to use a hardware key, Touch ID, or Windows Hello. Save the 10 one-time recovery codes when Postscale shows them. Email-code verification remains available as a sign-in option.

What you will learn

  • Choose between an authenticator app and a WebAuthn security key
  • Enable 2FA from your Postscale account settings
  • Save, use, and regenerate recovery codes safely

Two-factor authentication (2FA), also called multi-factor authentication (MFA), protects your Postscale dashboard with a verification method separate from your password. Each user configures MFA on their own account, so owners, admins, and members should all enable it individually.

Postscale supports two MFA methods:

MethodWhat you useBest for
Authenticator app (TOTP)A 6-digit code that changes every 30 secondsA quick setup that works with most phones and password managers
Security key (WebAuthn)A hardware key or a device authenticator such as Touch ID or Windows HelloPhishing-resistant authentication without typing a code

You can configure either method or both. Postscale also provides 10 one-time recovery codes when you enable your first MFA method. Email-code verification remains available from the sign-in screen.

Before you start

Sign in to Postscale and open Dashboard > Settings. Scroll to the Security card and find Two-factor authentication.

Before continuing:

  • make sure you can sign in to the email address on your Postscale account
  • have your authenticator app, security key, or compatible device ready
  • plan to store the recovery codes somewhere secure and separate from your second-factor device

Option 1: Set up an authenticator app

Authenticator apps use TOTP, an open standard for time-based one-time passwords. Any standard TOTP app should work, including Google Authenticator, Microsoft Authenticator, Authy, 1Password, and Bitwarden.

To enable it:

  1. In Dashboard > Settings > Security, click Set up authenticator app.
  2. Scan the QR code with your authenticator app.
  3. If you cannot scan the QR code, copy the manual key shown below it into the app instead.
  4. Click Next.
  5. Enter the current 6-digit code from the authenticator app. Postscale verifies the code and enables the method automatically.
  6. Copy or download the 10 recovery codes, then store them safely.
  7. Click Done.

The authenticator app becomes your default sign-in method when it is the first MFA method you add.

Keep the setup secret private. Anyone with the QR code or manual key can generate valid codes. Do not send it by email or chat, and do not keep an unprotected screenshot.

Option 2: Add a security key or device authenticator

Postscale uses WebAuthn for security-key authentication. You can use a compatible hardware key such as a YubiKey, or a built-in device authenticator such as Touch ID or Windows Hello.

To add one:

  1. In Dashboard > Settings > Security, click Add security key.
  2. Enter an optional name, such as YubiKey 5, MacBook Touch ID, or Windows Hello.
  3. Click Register.
  4. Follow your browser or operating system prompt. Insert and touch a hardware key, or approve the request with your device authenticator.
  5. If this is your first MFA method, copy or download the 10 recovery codes and store them safely.
  6. Click Done.

The Add security key button only appears in a browser that supports WebAuthn. Current versions of Chrome, Edge, Firefox, and Safari normally support it. If the button is missing, update your browser or use a different supported browser.

WebAuthn credentials are bound to the legitimate Postscale site, which makes this method resistant to credential phishing. A built-in authenticator may be tied to one device, so keep a recovery option available before replacing or resetting that device.

Save and use your recovery codes

Postscale generates 10 recovery codes. Each code works once and can replace your usual authenticator or security-key check when you cannot access it.

Store the codes in a password manager or another protected location. Do not keep the only copy on the same phone as your authenticator app.

To sign in with a recovery code:

  1. Enter your Postscale email address and password.
  2. Select the Recovery tab on the verification screen.
  3. Enter one unused recovery code.
  4. After signing in, replace the lost method or regenerate your recovery codes if necessary.

To replace your recovery-code set:

  1. Open Dashboard > Settings > Security.
  2. Find Recovery codes and click Regenerate.
  3. Confirm the warning.
  4. Copy or download the new codes and store them securely.

Regenerating codes immediately invalidates every code from the previous set. Whenever Postscale shows you a new set, replace any older saved copy.

Sign in after enabling MFA

After entering your email address and password, the verification screen shows the methods available to your account:

  • Email Code sends a 6-digit code and sign-in link to your account email
  • Authenticator accepts the current 6-digit code from your TOTP app
  • Security Key starts the WebAuthn prompt for your hardware key or device authenticator
  • Recovery accepts one of your one-time recovery codes

Postscale opens your default method first. You can select another available tab at any time.

If you configure both an authenticator app and a security key, a Default sign-in method selector appears under Dashboard > Settings > Security. Choose Authenticator app, Security key, or Email code. The new default takes effect the next time you sign in.

Remove a method or disable 2FA

Open Dashboard > Settings > Security, then click Remove beside the authenticator app or security key.

If another MFA method remains, that method stays active. Removing your final MFA method disables 2FA and deletes the recovery codes. Email-code verification continues to protect the normal Postscale sign-in flow.

If a device or key is lost or stolen, sign in with an email code, another configured method, or a recovery code, then remove the lost method immediately.

Troubleshooting

The authenticator code is rejected

  • Confirm that you are using the Postscale entry for the correct email address.
  • Wait for a new code and enter it before it expires.
  • Set your phone or computer to update its date and time automatically. TOTP depends on an accurate clock.
  • If setup was interrupted, close the dialog and start Set up authenticator app again so you scan the current QR code.

The security-key prompt does not appear

  • Update your browser and confirm that WebAuthn is enabled.
  • Try a normal browser window if private-browsing or browser policy blocks the prompt.
  • For a USB key, reconnect it and wait for the browser prompt before touching it.
  • For Touch ID or Windows Hello, confirm that the authenticator is configured on the device.

You no longer have the second-factor device

Choose Email Code or Recovery on the sign-in verification screen. Once you are signed in, remove the lost method and set up its replacement. If you no longer control the account email and have no working MFA method or recovery code, contact Postscale support for account-recovery assistance.

Recommended account-security checklist

  • Enable an authenticator app or security key for every Postscale team member.
  • Prefer a security key or device authenticator for accounts with owner or administrator access.
  • Keep your account email protected with MFA as well, because email-code verification remains an available sign-in method.
  • Store recovery codes separately from the device used for authentication.
  • Never share a TOTP setup key, authenticator code, security key, or recovery code with anyone.
  • Remove lost authenticators promptly and regenerate codes if you believe they were exposed.

For guidance on giving colleagues their own accounts instead of sharing login credentials, see the Team Accounts and Domain Access Guide.

Frequently asked questions

Which authenticator apps work with Postscale?
Any app that supports standard TOTP codes should work, including Google Authenticator, Microsoft Authenticator, Authy, 1Password, and Bitwarden.
Can I use Touch ID or Windows Hello?
Yes. Add it through the Security key option. Postscale uses WebAuthn, which supports hardware security keys and compatible built-in authenticators such as Touch ID and Windows Hello.
What if I lose my phone or security key?
On the sign-in verification screen, use the Recovery tab and enter one of your saved recovery codes. You can also use the Email Code tab if you still control your account email. After signing in, remove the lost method and configure its replacement.
Does Postscale support SMS codes?
No. Postscale supports authenticator-app codes, WebAuthn security keys or device authenticators, recovery codes, and email verification.
Can an organization owner enable MFA for every team member?
MFA is currently configured per user. Each team member must enable it from their own Settings page.

Related guides

Put the guide into production

Postscale brings sending, inbound processing, DMARC reporting, and masked addresses behind one API so the operational pieces stay connected.