E-mail Codes
E-mail codes are the third way to receive a second factor, alongside authenticator apps and SMS. After the password is accepted, a one-time code is sent to the e-mail address on the account and must be typed in to finish signing in. It is the weakest of the three, and it is useful as a fallback for people who cannot use an app or receive texts.
Where to find it
Architect Panel → Configuration:
- Site Settings — the 2FA settings, including the one-time code length and time limit that e-mail shares with SMS
Architect Panel → Layout & Pages:
- E-mail Templates — the 2-Factor Authentication Code template that carries the code
Architect Panel → Security:
- Security Check-up — the Multi-factor authentication section, which reports whether e-mail codes are offered and how it rates them
Architect Panel → Activity:
- E-mail Log — each code e-mail that was sent, or failed
Each person switches e-mail codes on for themselves on My Account, in the 2-Factor Authentication (2FA) card.
Why it is the weakest method
A code sent to somebody's mailbox is only as strong as that mailbox, and the mailbox is usually also where a password reset goes. Somebody who controls the mailbox can therefore reset the password and receive the code, so e-mail is close to a single factor. Cyber Essentials does not recognise it as multi-factor authentication. Offer it so that nobody is left with no second factor at all, not as the method that satisfies an enforcement requirement.
Making it available
Which methods are offered, and in what order, is set by your hosting administrator in the server configuration; it is not on the Site Settings screen. The shipped list is authenticator apps then SMS. To offer e-mail codes:
- Ask your hosting administrator to add e-mail to the list of 2FA methods, and to name the e-mail account the codes are sent from. Ask for an authenticator app to stay first in the list.
- Open E-mail Templates and check the 2-Factor Authentication Code template. It puts the code in the subject and body, says how many minutes it lasts, and warns the reader not to enter it if they were not signing in. Open tracking is off on purpose: keep it off.
- Open Security Check-up and confirm the Methods offered row now includes E-MAIL.
- Switch it on for your own account and sign in once to test it before telling anybody else.
How a person switches it on
- Open My Account and find the 2-Factor Authentication (2FA) card.
- In the E-mail Codes column, check the address shown is right, then turn the switch on. The card confirms "2FA by e-mail is enabled on your account."
- If the account has no e-mail address, or an address that is not valid, the switch is not offered and the card says why, with an Edit Profile button where an address can be added.
Turning e-mail codes off removes a factor, so the person is asked to confirm who they are again before the change is made.
Signing in with an e-mail code
After the password, the sign-in page says "We've sent a one-time authentication code by e-mail to" followed by a partly hidden address (the first letter, asterisks, then the domain), and asks for the code. A person with more than one method set up is asked for the first one in the order your hosting administrator set, which is another reason to keep authenticator apps first.
- Length and lifetime: e-mail codes use the same code length and time limit as SMS codes, 6 digits and 20 minutes as shipped. The Security Check-up shows them as One-time code length and One-time code validity.
- Single use: once a code is accepted, every other outstanding code for that account stops working.
What goes wrong
- "2FA by e-mail is not available on this site." E-mail is not in the methods list. Ask your hosting administrator.
- "There was a server error when attempting to send an authentication code by e-mail." The template or the sending e-mail account could not be found, or the send failed. The Error Log says which; check the E-mail Log for the attempt.
- The code never arrives. Check the E-mail Log for the message and its result, then the person's junk folder.
- Codes are visible to log readers. The E-mail Log keeps the subject and body of every message, including codes. They expire within the time limit and work once, but keep E-mail Log access to the few people who need it.
Worked example
A membership organisation enforces 2FA for staff with authenticator apps, but a few volunteers use shared or basic phones. The hosting administrator adds e-mail as a third method after TOTP and SMS. The volunteers switch on E-mail Codes on My Account and are protected against a reused password without installing anything. The Security Check-up marks E-mail codes as Review, offered alongside a stronger method, and the administrator records why it is offered.
Recommendations
- Never make e-mail the only method; the check-up marks that as Action needed.
- Keep authenticator apps first in the method order.
- Steer administrators away from e-mail codes; their accounts deserve an app or a passkey.
- Restrict who can read the E-mail Log.
- Shorten the code time limit if your mail delivers quickly; it applies to SMS too.