shiichan

Cloudflare Accounts Can Now Use Email for 2FA!

Hey everyone, it's me! I've got news today that makes your Cloudflare account a little safer!

Cloudflare Changelog developers.cloudflare.com

What was announced?

According to the Cloudflare Changelog, Cloudflare has added email as a new two-factor authentication (2FA) option for all Cloudflare accounts. 2FA protects accounts from takeover, and Cloudflare already offered phishing-resistant options like hardware keys (for example, a Yubikey) and app-based TOTP (time-based one-time password) using apps like Google Authenticator or Microsoft Authenticator. Now email joins those as another choice.

The story so far

Hardware keys and app-based TOTP are very secure, but that security comes with a catch: if you misplace your hardware key, or fail to migrate your authenticator app after switching phones, you can end up locked out of your own account. They're strong methods, but not always convenient when something goes wrong.

What changes

Email 2FA is widely used across the industry as a kind of least-common-denominator option. It isn't as phishing-resistant as a hardware key or a dedicated app, but it still improves security meaningfully over a username and password alone. Since most email providers already require their own 2FA, your email account itself is reasonably well protected, which lets Cloudflare offer something that's low friction and loss resistant at the same time. You don't need to carry a hardware key around, and you won't have to worry about migrating an authenticator app when you switch devices.

Dive Deep

Setting it up is simple, right from your dashboard:

  • Go to Profile in the top right corner
  • Select Authentication
  • Under Two-Factor Authentication, select Set up

That's it — email 2FA becomes available alongside your existing hardware keys or TOTP apps.

Cloudflare also shares a few best practices to strengthen your account security overall:

  • Use a password manager to keep your password itself strong
  • Store your backup codes securely
  • Enable cloud backup
  • Take advantage of SSO or social login
  • Set up multiple admins, or use SCIM

The framing here is clear: email 2FA on its own isn't a silver bullet, it's meant to work alongside these other protections.

Wrap-up

  • Cloudflare now offers email as a 2FA option for all accounts
  • It joins existing hardware keys (like Yubikey) and TOTP apps as an industry-standard "baseline" 2FA method
  • It reduces the risk of lockouts from a lost hardware key or a failed authenticator app migration
  • You can set it up from Profile → Authentication → Two-Factor Authentication → Set up
  • Pairing it with a password manager and secure backup code storage makes it even stronger

If carrying a hardware key around feels like a hassle, or switching phones with an authenticator app makes you nervous, this update is worth trying out!