How to enable two-factor authentication for Webmail and Remote Administration in MDaemon

How to enable two-factor authentication for Webmail and Remote Administration in MDaemon

MDaemon version 16 onwards supports Two Factor Authentication meaning a user needs to enter a verification code before they can log into Webmail or Remote Administration.  This article utilises the Google Authenticator application.


Google Authenticator is available for both Android or iOS devices:


Google Authenticator for Android

Google Authenticator for iOS


HTTPS must be enabled for Webmail users to enable two factor authentication.

  1. Log in to Webmail via HTTPS
  2. Select Options
  3. Select Security
  4. Enter the current account password:
  5. Select Setup Two Factor Authentication
  6. Open the Google Authenticator App.
  7. Scan the QR Code displayed in Webmail to setup the account on the device. Alternatively, click Show Secret to generate a code to enter into the Google Authenticator App.
  8. Once the account has been added in Google Authenticator, enter the 6 digit verification code displayed on the app.
  9. Click Verify Pairing to finish the process.

The next time the account logs into Webmail or Remote Administration via HTTPS, the password and a code generated by the Google Authenticator app will be required to login.

    • Related Articles

    • Webmail Branding and Custom Images

      Custom Webmail images can be uploaded via MDaemon Remote Administration. The user account you login to MDaemon Remote Administration as needs to be a global administrator to make this change. Once logged into MDaemon Remote Administration select Main ...
    • How to stop Webmail from blocking images in emails

      By default Webmail will block the automatic download of remote images when viewing HTML email messages. In order to view the images, the user must click the bar that appears above the message in the browser window. This is a spam prevention feature, ...
    • Configuring ActiveSync in MDaemon and addressing common configuration issues

      MDaemon’s ActiveSync options are located at Setup -> Mobile Device Management -> ActiveSync and it’s necessary to enable ActiveSync in this location: Once enabled MDaemon will generate an ActiveSync 30 day trial key automatically. The ActiveSync ...
    • How to Enable HSTS in MDaemon

      The following line needs to be added to the [ResponseHeaders] section of the \MDaemon\WorldClient\WorldClient.ini and \MDaemon\WebAdmin\WebAdmin.ini files: Strict-Transport-Security=max-age=31536000 The Webmail and Remote Administration servers must ...
    • Configuring SSL for SMTP, IMAP and POP3 in MDaemon

      This article details how you’d configure MDaemon so that it accepts SMTP, IMAP and POP3 connections over SSL. Choose Security -> Security Manager-> SSL & TLS -> MDaemon. Click Enable SSL, STARTTLS, and STLS. Click Enable the dedicated SSL ports for ...