With the Two-Factor Authentication (2FA) you protect your CURIAWEB customer account in addition to your password with a second security factor. When logging in, in addition to your email address and your password, you need a time-limited security code generated by an authenticator app.
This is particularly useful because you manage important areas such as hosting products, domains, invoices, and personal account data via your CURIAWEB customer center. If your password should ever fall into the wrong hands, having 2FA enabled alone is no longer enough to log into your account.
Recommendation: Activate two-factor authentication for your CURIAWEB account. The additional login step takes only a few seconds and significantly improves the protection of your customer account.
What is two-factor authentication? #
During a normal login, your identity is verified using one factor: your password. With two-factor authentication enabled, an additional factor is added.
For the CURIAWEB customer center, the login then consists of:
- your password and
- a time-limited code from your authenticator app.
Even if another person knows your password, they still lack the second factor. This significantly reduces the risk of unauthorized access.
Why is 2FA useful for your customer portal? #
Passwords can be compromised in various ways. Typical causes are phishing, malware, data leaks at other services, or using the same password for multiple accounts.
Unauthorized access to a hosting customer account would be particularly critical. Depending on the permissions, the CURIAWEB customer center can be used, for example, to manage products and domains, view support tickets, or access technical administration functions.
If you also allow other people to work with your customer account, you should generally not share your master password. We explain how to set up separate access details instead in the article User management: Set up access for web designers or employees.
What do you need for the setup? #
Before you enable 2FA, you need an authenticator app on your smartphone or another suitable device. This app generates the time-based security codes that you will enter later during login.
For example, authenticator apps that support time-based one-time passwords (TOTP) are suitable. These include, among others:
- Google Authenticator
- Microsoft Authenticator
- Authy
- other TOTP-compatible authenticator apps
Which app you use is fundamentally your decision. It is important that you have permanent access to the set-up app or its recovery options.
How to Enable Two-Factor Authentication #
The setup is done directly in the security settings of your CURIAWEB customer account.
- Log in to CURIAWEB Customer Center a.
- Click on your name or profile menu in the top right corner.
- Open „Security settings“.
- Click on „Enable two-factor authentication“.
- Open your authenticator app.
- Scan the QR code displayed in the customer portal.
- Your authenticator app is now generating a security code.
- Enter this code in the customer center for confirmation.
- Complete the activation.
- Save the backup code displayed below in a secure location.
Important: Do not complete the setup until your authenticator app has correctly saved the CURIAWEB access and generates a valid code.
What happens when you scan the QR code? #
The displayed QR code contains the information used to link your authenticator app to your CURIAWEB account. Once scanned, the app can continuously generate new one-time codes.
These codes are each valid for only a short time. After expiration, a new code is automatically generated. As a result, an intercepted or already used code has very limited usability.
The QR code should therefore also be treated confidentially. It contains information that can be used to set up the second factor.
How login works after activation #
After you have successfully enabled 2FA, logging in will take place in two steps in the future.
- You log in with your email address and password.
- The customer service center will then request your current 2FA code.
- You open your authenticator app.
- You enter the currently displayed code.
- Upon successful verification, you will gain access to your customer account.
So the password remains necessary. 2FA doesn't replace your password, it complements it with a second layer of security.
Be sure to keep the backup code in a safe place #
Upon activation you receive a Backup code. This is especially important if you no longer have access to your authenticator app later, for example because your smartphone is lost or broken.
Therefore, save the backup code in a secure location immediately after setup. A protected password manager or a securely stored printed copy, for example, are suitable.
Do not save backup codes on your smartphone: If your smartphone and backup code are lost together, the backup won't help you at the crucial moment. Therefore, keep the code stored as separately as possible from the device with your authenticator app.
What to do when switching smartphones? #
When using a new smartphone, you should ensure that your authenticator accounts are available on the new device before deleting or resetting the old one.
How the transfer works depends on the authenticator app being used. Some apps offer an export or synchronization function, while others require the accounts to be set up again.
Be sure to test whether a login code generated by the new device works after the switch, before you finally reset the old device.
What to do if you no longer have access to your authenticator app? #
If you lose your smartphone or for any other reason no longer have access to your authenticator app, you will need the backup code saved during setup or the designated recovery method.
If you are still unable to log in with this method, please contact CURIAWEB Support. For security reasons, a verification may be required in such cases before changes can be made to the two-factor authentication.
We explain how to open a support ticket in the manual Create a support ticket in the CURIAWEB customer center.
Never share 2FA codes with other people #
A current 2FA code is a component of your access credentials. Therefore, treat it with the exact same confidentiality as your password.
Never share a current authenticator code or your backup code with other people via email, chat, or phone. A security code should only be entered where it is needed for the intended login or recovery process.
Safety rule: Passwords, current 2FA codes, and backup codes do not belong in support tickets. CURIAWEB does not need this data to handle a standard support request.
2FA does not replace a secure password #
Two-factor authentication is an additional security measure and not a substitute for a good password. Continue to use a long and unique password that you do not use for other services at the same time.
The combination of a strong individual password and activated two-factor authentication offers significantly better protection than a password alone.
Check account security regularly #
It is worth checking the security of your CURIAWEB account occasionally. In particular, verify whether your registered email address is still up to date, whether you have access to your authenticator app, and whether your backup code is still kept secure.
If other people have access to your customer account, you should also regularly check whether this access is still needed. User permissions that are no longer required should be removed.