2FA vs passkeys: how to actually secure your email account in 2026

Tobava Security Team · · 6 min read
← All articles

Your email account is the master key to everything else you own online — every password reset lands there. Here's what the options genuinely protect against, ranked, and what to do about it in the next ten minutes.

Why email deserves your strongest factor

Compromise someone's email and you don't need any other password. You request resets for the bank, the domain registrar, the payroll system, and read the codes as they arrive. Treat your mailbox as the highest-value account you have, because to an attacker, it is.

The options, weakest to strongest

Password only

Defeated by credential stuffing — attackers replay username/password pairs from unrelated breaches against everything. Password reuse turns one company's breach into your compromise. Non-negotiable baseline: a unique, long password from a password manager.

SMS codes

Better than nothing, and genuinely stops bulk automated attacks. Two real weaknesses:

Use it only where nothing better is offered.

Authenticator apps (TOTP)

A six-digit rotating code generated on your device — no telco involved, so SIM swapping is irrelevant. This is the practical sweet spot for most people, and it's what Tobava Mail uses for two-step verification, with an emailed code as a fallback if you lose access to your authenticator.

Still relay-phishable in principle: a convincing fake login page can capture the code and use it within its 30-second window. In practice this requires a targeted, real-time attack rather than bulk automation.

Hardware security keys and passkeys

Both use public-key cryptography and are phishing-resistant by design. The key checks the site's actual domain before responding, so a lookalike domain gets nothing — the credential simply won't work anywhere but the real site.

The honest ranking

  1. Passkey or hardware key — the only options that survive a convincing phishing site
  2. Authenticator app (TOTP) — strong, practical, right for most people today
  3. Emailed code to a separate secure address — acceptable fallback
  4. SMS — better than nothing
  5. Password alone — not sufficient for email in 2026

What to do in the next ten minutes

  1. Turn on MFA for your email account. In Tobava Mail, open Settings and find two-step verification under password and security. Choose an authenticator app if you're unsure.
  2. Record your recovery method while you're there. Note which address receives your fallback code, and keep your authenticator's own backup (most apps offer an encrypted export) somewhere that isn't the mailbox it unlocks.
  3. Do the same for your password manager and domain registrar. Those two are the next most valuable accounts you own.
  4. Check your recovery address and phone are still ones you control. Stale recovery details are a common way accounts are lost permanently.

Remembering trusted devices isn't a weakness — it's what makes strong MFA sustainable. Tobava Mail can trust a recognised browser for 30 days so you aren't prompted on every login, while still requiring a full challenge from anything new.

What MFA doesn't solve

MFA protects the login. It doesn't help if malware is already on your device, if you approve a push notification you didn't trigger (approve nothing you didn't just initiate), or if an attacker leaves a forwarding rule behind after a past compromise. After any suspected incident, check both your filter rules and your forwarding settings for anything you didn't create — they're separate screens in Tobava Mail, and checking only one is the most commonly missed step in cleaning up an account takeover.

Try Tobava Mail free

Encrypted email, a private inbox, and a full workspace — built by a cybersecurity company. No ads, no tracking, no message scanning.

Create your free account