Big protection. Even on the free plan. Meet your new DNS home
KumoDNS
Documentation

Two-factor authentication

Turning on 2FA, what to do about the recovery codes, and how to get back in if you lose the phone.

Two-factor authentication means a password alone is not enough to sign in. After the password, the panel asks for a six-digit code from an app on your phone.

It is the single most useful thing you can do to protect a DNS account — and DNS is worth protecting, because somebody who controls it controls where your mail and your website go.

Turning it on

Security in the portal. You will need an authenticator app: Google Authenticator, Microsoft Authenticator, 1Password, Authy or any other that takes a standard TOTP secret.

  1. Open Security and start the setup.
  2. Scan the QR code with the app, or type the secret if you cannot scan. The secret is shown in four-character groups because a 32-character string read off a screen and typed into a phone is one people get wrong.
  3. Enter the six-digit code the app shows, to prove it works before anything is switched on.
  4. Save the recovery codes.

The recovery codes matter more than people expect

They are shown once, at setup. Each works exactly once, and they are the only way back in if the phone is gone.

Put them somewhere that is not the phone. A password manager, a printed copy in a drawer — anywhere that does not disappear along with the device they exist to replace. Storing them on the phone that holds the authenticator defeats the point entirely.

Signing in afterwards

Password first, then the six-digit code. The code changes every thirty seconds, and the panel accepts a small window either side, so a phone whose clock is slightly off still works.

If codes are consistently rejected, the phone's clock is the usual cause — TOTP is time-based, and a device several minutes out generates codes for the wrong moment. Turning on automatic time in the phone's settings fixes it.

If you lose the phone

Use a recovery code. Enter it where the six-digit code goes. It signs you in and is then spent.

Once in, go to Security, turn 2FA off and set it up again on the new device. That reissues the recovery codes; the old ones stop working.

If you have no recovery codes and no phone, contact support. Expect to be asked to prove the account is yours, and expect that to take longer than you would like — the check exists precisely because somebody else asking the same question is what 2FA defends against.

Turning it off

Possible at any time from Security, and it needs your password. Consider whether you actually want to: an account that manages DNS for a business is worth the extra five seconds at sign-in.

Last reviewed 2026-09-16.

Not what you needed?

Open a ticket from the control panel, or use the contact form if you cannot sign in. If a domain is down, the status page is the fastest way to find out whether it is us.

Top