🤖 Teach your AI coding agent how to send email with Postmark Skills
x
How do I use two factor authentication (2FA)? | Postmark Support Center

How do I use two factor authentication (2FA)?

Two-factor authentication (2FA) adds a step to logging in, so a password on its own isn't enough to reach your Postmark account. You can turn on 2FA on any plan, including the free Developer plan, and any user on your account can turn it on for themselves. Which methods you can set up depends on your plan — see Available methods by plan below. An account owner can also require 2FA for everyone on the account.

Available methods by plan

You can turn on 2FA on any plan. The methods available depend on which plan you're on:

  • Free Developer plan — App authentication
  • Basic, Pro, and Platform — App authentication or SMS authentication

If you already have SMS authentication set up, your confirmed number keeps working exactly as it does today, even if your account moves to the free Developer plan. What you can't do on the free plan is add SMS as a new method.

You can compare plans on our pricing page.

Setup#

  1. While logged into your Postmark account, select your name in the top right then choose Profile to access your user settings.
  2. Scroll down to the Security area and select Turn on next to Two-factor authentication.
  3. Confirm your password.
  4. Choose Set up for either App authentication or SMS authentication. On the free Developer plan, App authentication is the only option.
  5. Once your authentication method is confirmed, download your backup codes and save these in a secure location.These are important to gain access to your account in case you change your phone number or lose your phone.
  6. After the setup process is complete, you can add an additional authentication method (either App or SMS authentication).

Make App authentication the primary method#

  1. While logged into your Postmark account, select your name in the top right then choose Profile to access your user settings.
  2. Scroll down to the Security area and select Manage next to Two-factor authentication.
  3. Enter your password to confirm.
  4. Then select Set as primary for App authentication.

Postmark supports Google Authenticator, Authy and 1Password.

Logging In#

Once 2FA has been enabled, the next time you log in you will need to enter in a code after using your username and password to log in.

Enter

Retrieving Backup Codes#

If you did not save your backup codes when completing the 2FA setup, you can still retrieve them.

  1. While logged into your Postmark account, select your name in the top right then choose Profile to access your user settings.
  2. Scroll down to the Security area and select Manage next to Two-factor authentication.
  3. Enter your password to confirm.
  4. Then select View codes.
  5. Your backup codes will then be available to download or print.

Require 2FA for all Users#

It's possible to require all users on an account to use 2FA.

  1. While logged into your Postmark account, select Account from the top header.
  2. Choose Require 2FA on the Account Overview page.
  3. Confirm the User password.
  4. The next time a user without 2FA enabled logs in, they're prompted to set-up 2FA.

Note: The user requiring 2FA must already have 2FA set-up.

Viewing Users’ 2FA Settings#

If you are the account owner, you can see who has 2FA enabled while viewing Users. You can use this area to quickly see who has enabled or disabled 2FA.

SMS Limitations#

You can set up SMS authentication on the Basic, Pro, and Platform plans. On the free Developer plan, use App authentication instead. 

Due to local regulations, we are unable to send SMS messages to some countries: 

  • Russia. 
  • Starting July 31st, 2023 we are unable to send SMS messages to Singapore. We have paused the ability to add new Singapore numbers, while previously added numbers will work until July 31st, 2023.

For countries where we are unable to send SMS messages, app-based authentication remains available.

Tips#

  • Save your backup codes
  • We don’t provide an option for using a backup number with SMS authentication. This means that if you change your phone number, you will need to use a backup code to get logged in and change your 2FA phone number.
  • If you are traveling and unable to receive SMS messages, use a backup code to get logged in.
  • If you are using app authentication and have a new phone without the app installed, you will need to use a backup code or an SMS text to get logged in.

What happens if I get locked out of my account?#

In the event you cannot use the authentication method you enabled for 2FA to get access to your account, you will need to use a backup code or the backup method of SMS. This is why it is very important that you save your backup codes for situations where you need them to get access to your account. Please contact our success team if you do not have a backup code and cannot complete the 2FA step using SMS or an authentication app.

On the free Developer plan, App authentication is your only method, which makes your backup codes your only way back in. Download them during setup and store them somewhere you can reach without your phone.

Last updated September 23rd, 2026

Still need some help?

Our customer success team has your back!