Security
Two-factor authentication, passkeys, and sessions.
Everything here lives under Settings > Security and concerns signing in to Warmbly. For authenticating the domains you send from (SPF, DKIM, DMARC), see Deliverability.
How signing in works
| Method | Steps |
|---|---|
| Password | Email, password, a 6-digit emailed code, then your authenticator code if 2FA is on |
| Passkey | Pick the passkey and unlock with Touch ID, Face ID, Windows Hello, or a security key. No password, no emailed code |
| Google / Apple | One tap, natively in the iOS app. No emailed code, since the provider already verified you |
A first sign-in with a new address via Google or Apple creates your account, workspace, and free trial automatically.
Passwordless by design
A passkey is tied to your device and unlocked with biometrics or a PIN, so it already proves both something you have and something you are or know. That is why it skips the emailed code.
Two-factor authentication
2FA (TOTP) adds a rotating 6-digit code to every password sign-in, so a stolen password alone is not enough. Any standard authenticator works: Google Authenticator, 1Password, Authy.
Enable 2FA runs three steps: copy the setup secret into your authenticator, enter a code to confirm it works (it verifies as soon as the sixth digit lands), and save your one-time recovery codes.
Recovery codes are shown only once
They are displayed a single time during setup, each works once, and they are your way back in if you lose your authenticator. Store them in a password manager before closing the wizard; Copy all grabs them at once.
At sign-in, the code submits automatically once six digits are in. Without your authenticator, choose Use a recovery code.
Disabling asks for a current code or a recovery code first. With 2FA off you are protected only by your password plus the emailed code, and setting it up again issues a fresh secret and new recovery codes, invalidating the old ones.
Passkeys
A passkey signs you in with whatever unlocks your device. Nothing is phishable, because the credential never leaves the device. Current Chrome, Safari, Edge, and Firefox all support them; if yours does not, the Security page says so and you keep using your password.
Add a passkey prompts your device to confirm, then asks you to name it ("MacBook Touch ID", "YubiKey"). Add one per device you sign in from. A passkey syncing through iCloud Keychain or Google Password Manager is marked Synced and works on your other signed-in devices.
Each entry shows when it was added and last used, and can be renamed or removed.
No passkey on this device?
Unsynced passkeys live only on the device that created them. On a device without one, Warmbly says none was found and you sign in with your password, then add a passkey there.
Sessions
Every signed-in device appears under Sessions with its device (Chrome on macOS), location where known, sign-in method (Email, Google, Apple, or Passkey), and last activity. Your current device is tagged This device.
Sign out ends one session; Sign out other sessions clears everything except where you are now.
If something looks wrong
Sign out the session, change your password, and make sure 2FA is on. Signing out other sessions is the fastest way to cut off access.
Password and alerts
Change your password under Password: current password, then a new one of at least 12 characters with upper and lower case and a number. Changing it signs out every other device automatically, while the device you change it on stays in. Accounts that only use Google, Apple, or a passkey have no password to change.
Sign-in alerts notify you when your account is accessed from a new browser and OS combination, naming the device and location with a reminder to act if it was not you. They appear in your in-app feed by default; enable email under Settings > Notifications, Security section, Email channel. Your first sign-in is never alerted, as there is nothing to compare against.
Strongest setup
- Add a passkey so daily sign-in is fast and phishing-resistant.
- Turn on 2FA and store the recovery codes safely, so password sign-ins keep a second factor.
- Review sessions periodically and sign out anything unfamiliar.