# Protect your webmail mailbox

> Change a mailbox's password, turn two-factor authentication on or off, manage app passwords and end sessions from the Security tab in webmail.

Source: https://www.coritan.com/docs/mail/webmail/security/

In the dashboard:

- /webmail/settings/security: https://www.coritan.com/webmail/settings/security

The **Security** tab of webmail settings controls how people and mail apps sign in to a mailbox: its password, its two-factor authentication and its app passwords. For a mailbox you signed in to with its address, it also lists the browsers signed in to it. Open it from **Settings**, or go to [Security settings](https://www.coritan.com/webmail/settings/security) for the mailbox on screen.

Everything on the tab belongs to the mailbox. Your Coritan account has a password and two-factor authentication of its own, and the tab links to them when the mailbox opened through your account. For those, see [Turn on two-factor authentication](/docs/account/two-factor-authentication/).

## Before you begin

- Open the mailbox as its owner. The tab shows for your own coritan.gg mailbox, a mailbox you added to your account or an admin gave you, and any mailbox you signed in to with its own address and password. It does not show for a mailbox shared with you.
- Know the password the tab asks for:
  - When the mailbox opened through your Coritan account, the tab asks for `Your Coritan password`. That covers being signed in on coritan.com, and a mailbox that your coritan.gg sign-in opened beside its own.
  - When you signed in with this mailbox's own address, the tab asks for its **Current password**. For your coritan.gg mailbox, that is your Coritan password until you give the mailbox one of its own.
- For two-factor authentication, have an authenticator app on a phone or computer.

## Change the mailbox password

The section is called **Mailbox password** when the mailbox opened through your Coritan account, and **Password** when you signed in with its address.

1. On the **Security** tab, enter `Your Coritan password` or the **Current password**, whichever the form asks for.
2. Enter the new password in **New password**, and again in **Confirm the new password**. It must be 12–128 characters and differ from the current one.
3. If two-factor authentication is on, you can tick **Also turn off two-factor sign-in** to turn it off at the same time.
4. Select **Change password**.

We show `Password changed, and every other session signed out. Mail apps that sign in with the password need the new one.` From then on:

- enter the new password in each mail app that used the old one;
- app passwords keep working;
- every browser signed in to the mailbox with its address is signed out, except this one if you signed in that way.

The new password is for the mailbox alone. Your Coritan password stays as it is.

For your coritan.gg mailbox, the new password becomes the mailbox's own. Mail apps and the mailbox's own sign-in use it from then on, and changing your Coritan password no longer changes it. Signing in to webmail with your coritan.gg address and your Coritan password still works, and still opens every mailbox your account can open.

Through your Coritan account, the form never asks for the mailbox's old password. That makes it the way to set a new one when you have forgotten the mailbox's password.

If you change the password of a mailbox you added to your account while signed in with the mailbox's own password, the mailbox leaves your account, and so does the access you gave other people. Change it through your Coritan account to keep both.

## Turn on two-factor authentication

With two-factor authentication on, mail apps and the webmail sign-in form ask for a six-digit code from an authenticator app along with the mailbox's password. Opening the mailbox through your Coritan account never asks for it, because your account's own sign-in protects that. Signing in with your coritan.gg address and your Coritan password asks for your account's code instead, when your account has two-factor authentication on.

Mail apps cannot ask for a code. Before you turn it on, give each mail app that signs in with the password an [app password](#create-an-app-password) of its own, or it stops getting mail.

1. On the **Security** tab, under **Two-factor sign-in**, turn on **Ask for a code when signing in**.
2. In **Add this mailbox to your authenticator**, select **Open in authenticator** on the device that has the app. Or select **Copy key** and type the key into the app.
3. Select **Done**. You will not see the key again, so keep a copy somewhere safe.

Turning it on signs out every browser signed in to the mailbox with its address, except this one if you signed in that way. From then on, signing in with the mailbox's password shows **Enter your code** after it, as [Enter a code](/docs/mail/webmail/sign-in/#enter-a-code) describes.

## Turn off two-factor authentication

1. On the **Security** tab, turn off **Ask for a code when signing in**.
2. In **Turn off two-factor sign-in?**, enter `Your Coritan password`, or the mailbox's **Password** when you signed in with its address.
3. Select **Turn off two-factor**.

We show `Two-factor sign-in is off.` Every browser signed in to the mailbox with its address is signed out, except this one if you signed in that way.

When you signed in with the mailbox's address, its password stays as it is. Through your Coritan account, webmail sets the mailbox's password to your Coritan password as it turns two-factor authentication off:

- for your coritan.gg mailbox, that is its password already;
- for a mailbox you added or an admin gave you, your Coritan password becomes its password, so mail apps that used the old one need your Coritan password or an app password.

Once a mailbox's password has been changed on this tab, the switch cannot turn two-factor authentication off through your Coritan account. [Change the password](#change-the-mailbox-password) with **Also turn off two-factor sign-in** ticked instead.

## Create an app password

An app password signs one mail app in to the mailbox in place of its password, and it skips the two-factor code. Give each app its own, so you can revoke one without touching the others.

1. On the **Security** tab, under **App passwords**, type the app or device in **New app password for**, such as `Thunderbird`. It takes up to 64 characters.
2. Select **Create app password**.
3. Select **Copy password** and paste the password into the app. We show it once.
4. Select **Done**.

In the mail app, use the mailbox's address as the username and the app password as the password. [Set up mail apps and devices](/docs/mail/webmail/mail-apps/) lists the server settings.

The list also shows the passwords that webmail made for devices on the **Mail apps** tab, including those of the people you share the mailbox with. Their names end with the person's email in brackets.

The mail server keeps at most ten app passwords for a mailbox. Webmail may use one itself, and each browser signed in with the mailbox's address and each device set up on the **Mail apps** tab uses one, so you may be able to create fewer.

## Revoke an app password

1. On the **Security** tab, find the password under **App passwords** by its name.
2. Select **Revoke…** on its row, then **Revoke app password**.

We show `App password revoked.` The app or device that used it can no longer sign in, and gets no mail until you give it a new password.

## See and end sessions

A *session* is one browser signed in to the mailbox with its address and password. The **Sessions** list shows every session of the mailbox, and it is on the tab when you signed in to this mailbox with its address. Through your Coritan account there are no sessions to list.

Each row shows the browser and system, the IP address, when it signed in and when it was last used. The row for the browser you are using says **This device**.

- To sign out another browser, select **Revoke…** on its row, then **Revoke session**.
- To sign out every browser but this one, select **Sign out everywhere else…**, then **Sign out everywhere else**.
- To sign out this browser, select **Sign out…** on its row, then **Sign out**.

Ending a session does not change the password, so anyone who knows it can sign in again. To keep someone out, [change the password](#change-the-mailbox-password) as well.

Sessions also end on their own, as [How long you stay signed in](/docs/mail/webmail/sign-in/#how-long-you-stay-signed-in) explains. To sign out of Coritan on other browsers, see [Sign out and end sessions](/docs/account/sessions/). Whoever manages a Mail Hosting service can also [end a mailbox's webmail sessions](/docs/mail/mail-hosting/mailbox-security/#end-webmail-sessions) from its panel.

## Troubleshooting

There is no **Security** tab
: Only the mailbox's owner sees it. For a mailbox shared with you, ask its owner to make the change.

`That is not your Coritan password.`
: Enter the password you sign in to Coritan with, not the mailbox's password.

`That is not the current password.` or `That is not the password for this mailbox.`
: Enter the mailbox's own password. If you signed in with your coritan.gg address and your Coritan password after giving the mailbox a password of its own, the form wants the mailbox's own. To use your Coritan password instead, sign in on coritan.com and open webmail from there. Wrong passwords here count towards the same limit as signing in to the address, which [Sign in to webmail](/docs/mail/webmail/sign-in/#troubleshooting) explains, and past it the tab says there were too many requests.

`Use at least 12 characters.`
: A new password must be 12–128 characters.

`Choose a password different from the current one.`
: Type a new password that is not the one you entered first.

`The two new passwords do not match.`
: Type the same new password in both fields.

A message that starts `Could not turn it off: This mailbox has its own password`
: The mailbox's password has been changed on this tab, so the switch cannot turn two-factor authentication off through your Coritan account. [Change the password](#change-the-mailbox-password) with **Also turn off two-factor sign-in** ticked.

A mail app stopped signing in after two-factor authentication went on
: The app signs in with the mailbox's password, and it cannot send a code. [Create an app password](#create-an-app-password) and enter it in the app in place of the password.

A mail app stopped signing in after a password change
: Enter the new password in the app, or give the app an app password.

`Name the device or app it is for.`
: Type a name in **New app password for** first.

`Could not create the app password: that label is reserved.`
: The names `webmail` and `webmail session` belong to webmail. Choose another name.

A message that starts `Could not create the app password: mail engine error`
: The mail server refused the new password. The mailbox may hold ten already. Revoke one you no longer use, or end a session, then try again.

`The mail server did not return the password. Revoke this one and create another.`
: Revoke the new app password in the list, then create another.

You forgot the mailbox password
: Through your Coritan account, the form asks for your Coritan password only. Sign in on coritan.com, open webmail and [change the password](#change-the-mailbox-password). For a Mail Hosting mailbox that is not in your account, whoever manages the service can [reset its password](/docs/mail/mail-hosting/mailboxes/#reset-a-mailbox-password).

## Related

- [Sign in to webmail](/docs/mail/webmail/sign-in/)
- [Set up mail apps and devices](/docs/mail/webmail/mail-apps/)
- [Secure a mailbox](/docs/mail/mail-hosting/mailbox-security/)
- [Turn on two-factor authentication](/docs/account/two-factor-authentication/)
- [Sign out and end sessions](/docs/account/sessions/)
