On this page
Account
Two-factor authentication
Add an extra layer of security to your account.
Overview
Two-factor authentication (2FA) means that even if someone gets hold of your password, they still can't sign in to your account. When 2FA is turned on, you'll need to enter a short code from an authenticator app on your phone every time you sign in. Only you can access your account.
DomainDash uses time-based one-time passwords (TOTP), which work with popular authenticator apps like Google Authenticator, Authy, 1Password, and Microsoft Authenticator.
Two-factor authentication lives on the Sign-in & security page, alongside your password.
Changing your password
Your password also lives on the Sign-in & security page.
- Go to Sign-in & security
Click your avatar in the navigation, select Profile, then open the Sign-in & security page.
- Click Change next to Password
Click the Change button in the password row.
- Enter your current password
Type your existing password to confirm it's really you.
- Choose a new password
Enter your new password and confirm it. We recommend mixing in numbers and symbols for extra security.
- Update your password
Save the change and you're done. You'll stay signed in on your current device.
Enabling two-factor authentication
- Go to Sign-in & security
Click your avatar in the navigation, select Profile, then open the Sign-in & security page.
- Click Set up next to two-factor authentication
In the two-factor authentication row, click the Set up button. A modal will appear asking you to confirm your password.
- Confirm your password
Enter your current password and click Continue. This is a security check to make sure it's really you.
- Scan the QR code
Open your authenticator app (e.g. Google Authenticator, Authy, or 1Password) and scan the QR code shown on screen. If you can't scan the code, click the setup key underneath and enter it into your app manually.
- Enter the 6-digit code
Your authenticator app will show a 6-digit code that changes every 30 seconds. Type the current code into the field and click Verify and enable.
- Save your recovery codes
DomainDash will show you a set of recovery codes. Copy or write these down and store them somewhere safe. You'll need them if you ever lose access to your authenticator app. Click Done when you're ready.
Once enabled, the two-factor authentication row on Sign-in & security shows a green Enabled badge.
Recovery codes
Recovery codes are your safety net: a backup way into your account if you lose your phone, delete your authenticator app, or can't reach your codes for any reason. Keep them somewhere safe and you'll never be locked out of your own account. Each recovery code can only be used once.
Viewing your recovery codes
To see your current recovery codes, go to Sign-in & security and click Recovery codes in the two-factor authentication row (this button only appears once 2FA is enabled). Store them somewhere safe, like a password manager or a printed copy in a secure location.
Regenerating recovery codes
If you've used some of your recovery codes, or you think they might have been compromised, generate a fresh set. Click Recovery codes, then click Regenerate codes. This creates a brand-new set and immediately invalidates all the previous ones. Click Copy all to grab the new set, then save them.
Save your new codes straight away
When you regenerate recovery codes, the old ones stop working immediately. Make sure you save the new set before closing the modal.
Disabling two-factor authentication
If you need to turn off 2FA, for example when switching authenticator apps, you can disable it from Sign-in & security.
- Go to Sign-in & security
Click your avatar in the navigation, select Profile, then open the Sign-in & security page.
- Click Disable next to two-factor authentication
In the two-factor authentication row, click the Disable button. A confirmation modal will appear.
- Confirm your password
Enter your current password and click Disable 2FA. Two-factor authentication is now turned off.
After disabling 2FA, you'll only need your email and password to sign in. If you're switching to a new authenticator app, we'd recommend enabling 2FA again straight away to keep your account protected.
Re-enable 2FA after switching apps
If you're moving to a new phone or a different authenticator app, disable 2FA first, then set it up again with your new app. This ensures the QR code and setup key are in sync.
Related
- Profile settings to manage your name, email, mobile number, and timezone
- Notification preferences to choose which emails, Slack messages, and texts you get
Start checking your sites for free
DomainDash keeps an eye on your uptime, SSL, DNS, and domain registration so you don't have to — and tells you the moment something needs your attention. Set up in under a minute, no credit card.
Last updated: 19 June 2026