Security Overview
Protect accounts with 2FA, SSO, app passwords, and recovery options.
Account security (users)
Open Settings → Security in the inbox or /settings.
- Change password — update your login password.
- Two-factor authentication (2FA) — TOTP app (Google Authenticator, etc.). Setup guide →
- Recovery email and phone — alternate contacts for account recovery.
- App passwords — separate passwords for IMAP/POP clients that do not support 2FA prompts.
Login flows
- /login — email and password; 2FA step when enabled.
- SSO — organization IdP login when admin enables OIDC or SAML.
- /first-login-password — forced password change on first login.
- /forgot-password and /recover-account — email recovery with optional 2FA verification.
Organization SSO (admins)
In Admin → General → SSO, configure your identity provider, enforce SSO for all users, enable auto-provisioning, and map IdP attributes to MoovMail profiles.
Admin security actions
- Reset user password or 2FA from Admin → User Management.
- Review login history (IP, device, browser).
- Admin idle timeout logs out inactive admin sessions.
Email security
- SPF, DKIM, and DMARC protect your domain reputation — see DNS guides.
- Spam folder and server-side scanning reduce unwanted mail.
- Block sender from any open message.
2FA nudge
MoovMail may prompt users who have not enabled 2FA to set it up for better account protection.
Public security information
High-level practices are described on /security (marketing/legal page).

