Two-factor authentication asks for a six-digit code from an app on your phone as well as your password. A stolen password alone then gets nobody into your account, which holds your domains and your sites.
Setting it up
- Go to Security in the sidebar and click Turn on in the Two-factor authentication card.
- Scan the QR code with an authenticator app: Google Authenticator, Microsoft Authenticator, 1Password, Bitwarden and Authy all work. If you cannot scan, type the key shown under the code into the app instead.
- Enter the six-digit code the app shows to confirm.
- Save the recovery codes shown next. Each one signs you in once if your phone is lost. Store them in a password manager or print them; they are shown in full only at this moment.
From then on, signing in asks for the code after your password.
Lost your phone
Sign in with your password, then enter one of your recovery codes in place of the app code. Once in, go to Security and either set the app up again on a new phone or turn two-factor off. Regenerate codes issues a fresh set and invalidates the old ones.
No phone and no codes: open a ticket from the email address on the account and we verify you another way. It takes longer, by design.
Turning it off
Turn off in the Two-factor card opens a confirmation that asks for your password. The security log records the change, and you get an email.