Usage
Enabling Email OTP
Each user enables Email OTP from their security settings page (My account → Security → TFA). The account must have a valid email address — the setup form refuses to enable the plugin otherwise and links to the account edit page instead.
Logging in
After entering their username and password, users land on the TFA entry form:
- The form shows the destination email address in masked form (for
example
j***e@example.com). - Click Send to receive a one-time code by email. The code entry field appears once a code has been sent, along with the code validity period.
- Enter the code and click Verify to complete the login, or click Resend to request a new code.
The email subject and body can be customized on the TFA settings page (Configuration → People → Two-factor Authentication).