Skip to content

Account security and recovery

Mailclient always verifies your mailbox password with the configured mail server. You can add an authenticator app or passkey as a second factor.

Set up an authenticator

  1. Open Settings > Security.
  2. Select Set up authenticator.
  3. Scan the QR code with an authenticator app. If scanning is unavailable, enter the displayed secret key manually.
  4. Enter the current six-digit code from the app.
  5. Select Confirm authenticator.
  6. Save the 10 recovery codes shown on the next screen.

Each recovery code works once. Store the codes outside Mailclient, preferably in a password manager or another secure location that you can reach if your phone is lost.

To replace the codes, select Regenerate recovery codes under Security. The old unused codes stop working immediately, and the replacement codes are shown only once.

Add a passkey

A passkey uses your device screen lock, fingerprint, face recognition, security key, or password manager to verify you.

  1. Open Settings > Security.
  2. Select Add a passkey.
  3. Follow the browser or operating-system prompt.
  4. Give the passkey a recognizable name if prompted.
  5. Save the recovery codes if Mailclient displays a new set.

Register more than one passkey if you routinely use multiple devices. Remove a lost or retired device with Remove beside its passkey entry.

Passkeys supplement the mailbox password in this application; they do not replace the initial mailbox credential step.

Complete a protected sign-in

After your username and password are accepted, Mailclient may ask for a second factor:

  • Approve the passkey prompt if one is registered.
  • Enter the six-digit code from your authenticator.
  • Enter one of your saved recovery codes.
  • Select Email me a code if security email is available.
  • Approve the request from another signed-in Mailclient session if cross-device approval is enabled.

The single Verification code box accepts authenticator, emailed, and recovery codes. A recovery code is consumed after a successful use.

If you see an approval banner on a device where you are already signed in, check the displayed IP address and device information. Select That's me — approve only for a sign-in you just started. Otherwise select That's not me — deny, change your mailbox password, and review your sessions.

Review account activity

Under Settings > Security you can:

  • Check the last sign-in time and recent sign-in IP addresses
  • Select Log out other devices to invalidate other Mailclient sessions
  • Turn cross-device approval on or off
  • Remove passkeys you no longer control

IP addresses can represent a home router, mobile carrier, VPN, or company gateway, so they may not uniquely identify a device.

If you lose access

Try the available methods in this order:

  1. Use another registered passkey.
  2. Use a saved recovery code.
  3. Select Email me a code, if offered.
  4. Approve the attempt from a device where Mailclient is already signed in.
  5. Email sysadmin@wolf-cloud.com to request a reset of your local second-factor state.

Wolf-Cloud's system administrator cannot recover a lost authenticator secret or reveal old recovery codes. After access is restored, remove lost passkeys, regenerate recovery codes, and review other sessions.

Password changes

You can change your Wolf-Cloud password at password.wolf-cloud.com or with Settings > Security > Change password in Mailclient.

This self-service method works only when you still know your current password. If you have forgotten it, email sysadmin@wolf-cloud.com for assistance. Never send your old or desired password by email.

After changing the password, existing Mailclient sessions may stop connecting to the mailbox. Sign out and sign in again with the new password.