What Is Two-Factor Authentication (2FA)?
Two-factor authentication adds a second verification step when you sign in. Even if someone steals your password, they cannot access your account without the second factor — typically a 6-digit code from an authenticator app on your phone. According to Microsoft, 2FA blocks over 99.9% of automated account compromise attacks.
Why Your Business Email Needs 2FA
Business email accounts are high-value targets. A compromised account can lead to:
Business email compromise (BEC) fraud — attackers impersonate you to request wire transfers or sensitive data
Data breaches — confidential attachments and conversations exposed
Account takeover chains — your email is the master key to every service that sends password resets to it
Reputation damage — spam or phishing sent from your legitimate address
How to Enable 2FA in UGMail
UGMail supports Time-based One-Time Passwords (TOTP), the industry standard used by Google Authenticator, Authy, Microsoft Authenticator, and other apps.
Step 1: Log into your UGMail webmail at mail.ugmail.co. Click your profile icon in the top right, then select Security or navigate to Settings → Security.
Step 2: In the Security section, find Two-Factor Authentication and click Enable. A QR code will appear on screen.
Step 3: Open your authenticator app (we recommend Google Authenticator or Authy) and scan the QR code. The app will start generating 6-digit codes that refresh every 30 seconds.
Step 4: Enter the current 6-digit code from your authenticator app to confirm the setup. Once verified, 2FA is active. Save your recovery codes in a secure location.
Setting Up App Passwords for Email Clients
Once 2FA is enabled, email clients like Outlook, Thunderbird, Apple Mail, and mobile apps cannot use your regular password. Instead, create app-specific passwords:
Go to Settings → Security → App Passwords in your UGMail webmail
Click Generate New App Password
Give it a descriptive name (e.g., "Outlook Desktop", "iPhone Mail")
Copy the generated password and paste it into your email client password field
You will not see this password again, so configure your client immediately
Best practices: use one password per device, use descriptive names, revoke unused passwords, and never share app passwords.
What If I Lose My Authenticator?
Save recovery codes — when you enable 2FA, UGMail provides one-time-use recovery codes. Store them in a password manager or print and keep them safe.
Use an authenticator with cloud backup — Authy and Google Authenticator both support this.
Set up on multiple devices — scan the QR code on a second phone or tablet as a backup.
Contact support — as a last resort, UGMail support can help verify your identity and reset 2FA.
Enforcing 2FA Across Your Organization
As an admin on UGMail, you can see which accounts have 2FA enabled. We recommend: requiring 2FA for all accounts that handle sensitive data, including 2FA setup in your employee onboarding checklist, auditing 2FA status quarterly, and pairing 2FA with strong password policies (minimum 12 characters, no reuse).
2FA + SPF + DKIM + DMARC: Complete Email Security
Two-factor authentication protects account access. Complete email security also requires protecting your domain from spoofing: SPF authorizes which servers can send email for your domain, DKIM cryptographically signs outgoing messages, and DMARC tells receiving servers what to do with messages that fail SPF/DKIM checks. UGMail configures SPF, DKIM, and DMARC automatically through the DNS setup wizard.
