Domain Stabilizer
Sign in

Security

Last updated: Oct 07, 2026

ESENPT

Who signed in with your email, two-factor authentication, your sessions and the export of the account data, in one screen.

What it is

Security is where you review and protect your own access to the console. It is in the account menu: Account → Security.

Almost everything on this screen is about you as a person, not about the account: your sign-ins, your devices, your sessions and your two-factor authentication. Every member manages their own, whatever their role. The one exception is the last block, the export of the account data, which needs a permission.

What it is for

  • See who signed in with your email. The screen lists your latest sign-in attempts, with their result, the browser and the IP address.
  • Add a second step to signing in. With two-factor authentication on, getting into your mailbox is not enough to get into the console.
  • Close what you left open. One button ends all your sessions, on every device.
  • Take your data with you. The account data can be downloaded as a single ZIP file at any time.

How it works

  • You sign in with a code sent to your email. There is no password.
  • Two-factor authentication is optional and personal. Each person turns it on for themselves, with an authenticator app on their phone. If you belong to more than one account, it applies to all of them.
  • With it on, the app code is asked for at every sign-in, after the code sent by email.
  • A trusted device does not wait for the emailed code. If you tick Trust this device for 30 days: we will not ask for the emailed code when signing in, for 30 days that browser signs in just by entering your email. If you have two-factor authentication on, the code from your app is still asked for: trusting a device never removes that step. After several wrong app codes, the device stops being trusted.
  • Turning it on gives you 10 recovery codes. They are shown once. Each one replaces the app code a single time, for when you do not have your phone.
  • Turning it off, or generating new recovery codes, asks for your second factor: a code from the app or a recovery code. The code sent by email is not enough.
  • You get an email when it matters: when your two-factor authentication is turned off, and when a recovery code is used to sign in. The second one tells you how many codes you have left.
  • If you lose both the phone and the recovery codes, an Owner of your account can reset your two-factor authentication from Team. Nobody can reset their own that way.
  • The export is a ZIP file built at the moment you ask for it. The Owner can always download it; other roles, if their role includes managing the account.

What you see on screen

The screen is a column of blocks.

  • Recent sign-ins. Your last 10 sign-in attempts, in a table: When, Outcome, Device (the browser) and IP. Failed attempts appear too, with their reason. A check mark next to the browser means that device was marked as trusted in that sign-in.
  • Trusted devices. The browsers where you ticked Trust this device for 30 days: we will not ask for the emailed code when signing in. The one you are using carries the This device mark; the others carry a Revoke button. When the list has a device other than the one you are using, Manage devices appears next to the title.
  • Active sessions. The Sign out everywhere button.
  • Two-factor authentication. A mark says whether it is On or Off. When it is off, the Turn on button. When it is on, the date since when, how many of your 10 recovery codes are still unused, and two buttons: Generate new codes and Turn off. With 3 codes or fewer left, a warning appears.
  • Export the account data. A description of what the file contains and the Download ZIP button.

How to…

Turn on two-factor authentication

You need an authenticator app on your phone, such as Google Authenticator, 1Password or Authy.

  1. Open Account → Security.
  2. In Two-factor authentication, press Turn on. The Turn on two-factor authentication dialog opens.
  3. Scan the QR code with your app. If you cannot scan it, type into the app the key shown below the QR code.
  4. Enter the six-digit code the app shows in Code from the app and press Confirm and turn on.
  5. The Save your recovery codes dialog shows your 10 recovery codes. Press Copy or Download and keep them somewhere safe, outside your email.
  6. Press I have saved them.

The recovery codes are not shown again. The dialog does not close until you press I have saved them.

Nothing changes until step 4: if you close the dialog before confirming, two-factor authentication stays off.

Sign in with two-factor authentication on

  1. Enter your email and the code you receive by email, as always.
  2. The console then asks for the six-digit code from your authenticator app. Enter it.

Without your phone, press I do not have my phone: use a recovery code and enter one of your recovery codes. That code stops working after that sign-in, and you receive an email saying how many you have left.

Generate new recovery codes

Do it when you have few left, or if you think someone else has seen them.

  1. In Two-factor authentication, press Generate new codes.
  2. In Code from the app, or a recovery code, enter a code from your app or a recovery code you still have.
  3. Press Generate new codes to confirm.
  4. Save the 10 new codes and press I have saved them.

The previous codes stop working at that moment, including the ones you had not used.

Turn off two-factor authentication

  1. In Two-factor authentication, press Turn off.
  2. In Code from the app, or a recovery code, enter a code from your app or a recovery code.
  3. Press Turn off to confirm.

From then on you sign in with the email code only. Your recovery codes stop working, and you receive an email confirming the change. If you turn it on again later, you scan a new QR code and get new recovery codes.

Remove a trusted device

  • One device. In Trusted devices, press Revoke on its row. The device you are using has no button.
  • All of them. Press Manage devices. The Revoke all trusted devices dialog opens; press Revoke all. This removes every device from the list, including the one you are using.

A device you do not remove leaves the list on its own after 30 days.

Sign out on every device

  1. In Active sessions, press Sign out everywhere.
  2. Read the confirmation and press Sign out everywhere.

Signing out on every device also removes all your trusted devices: the next sign-in on each of them will ask for the emailed code.

All your sessions end, including this one, and you are taken to the sign-in page. It only affects your sessions, not those of the other members.

Download the account data

  1. Go to the last block, Export the account data.
  2. Press Download ZIP. The browser downloads a ZIP file with the name of the account and the date.

The file contains:

  • The account and the list of its Workspaces.
  • For each Workspace, its client contacts and the reports already generated for it.
  • For each domain, its analyses, its continuous stabilization history, scores, measurements, alerts with their evidence, its timeline and its evidence reports.
  • A manifest listing what the file contains and anything that was left out.

Data is always included. If the reports together are too large, the ones that do not fit are left out and the manifest lists them.

If you get stuck

The screen says the code is not correct

The code from the app changes every 30 seconds. Check that it is the one showing right now, and that you are looking at the entry for this console in your app, then try again. If it keeps failing, check that the date and time of your phone are set automatically.

A code that just worked is rejected

A code from the app is accepted only once. If you have just used it, for example to turn on two-factor authentication, wait for the app to show the next one. A recovery code also works only once.

Sign-in sends you back to the start

When you sign in, you have 5 attempts for the second factor; the message tells you how many are left. After the fifth wrong one, the code sent by email is cancelled too. Ask for a new email code and start again.

You do not have your phone

At sign-in, press I do not have my phone: use a recovery code and enter one of your recovery codes. Once inside, you can turn two-factor authentication off with another recovery code, and turn it on again with your new phone.

You lost the phone and the recovery codes

Ask an Owner of your account to reset your two-factor authentication. They do it from Team, with the Reset 2-factor button in your entry of the member list. See Team. You receive an email saying who did it, and from then on you sign in with the email code only.

An Owner cannot reset their own. If you are the only Owner of the account, the console gives you no way to recover access by yourself: write to us from your account email.

The screen warns that few recovery codes are left

The warning appears with 3 unused codes or fewer. Press Generate new codes to get 10 new ones before you run out. See Security.

A sign-in you do not recognise

If Recent sign-ins shows a successful sign-in that was not you, press Sign out everywhere to end every session, and turn on two-factor authentication if it is off. A failed attempt is one that did not get in.

The export does not download

  • Your role does not include managing the account. Instead of the file, the browser shows an error message. Ask the account Owner to download it or to change your role.
  • You downloaded it several times in a row. The export can be requested 3 times per hour. Wait and try again.

A message says the action could not be completed

The message shows a code in parentheses. Try again in a minute. If the block Two-factor authentication did not load, press Retry. If it keeps happening, send us that code with your account email.

Domain Stabilizer

Domain stabilization: DMARC, SSL, DNS, MX, blacklists and uptime — exact fixes and evidence of the work.

Secure connection (TLS)
GDPR‑aligned practices
Helpful support
Product
PricingFree domain diagnosis

© 2026 Domain Stabilizer. All rights reserved.

Made with ❤️ for teams that care about reliable delivery.