×
中文

Two-factor Authentication and Client-specific Password Setup Guide

🔒1. What is Two-factor Authentication? How to Choose Based on Your Usage Habits?

1

What is Two-factor Authentication?

To address recent email security risks and enhance the security of the mail system, Zhejiang University Email System has now enabled two-factor authentication and client-specific password functionality. Two-factor authentication is an additional identity verification method added after you access https://mail.zju.edu.cn via browser, significantly improving account security.

Note:

  • If your account has mandatory two-factor authentication activated but not configured, log in at https://mail.zju.edu.cn to be directed to the setup page. Please refer to this article to complete the setup.
  • Password usage after enabling two-factor authentication:
    • Email Client (e.g., Foxmail, Outlook, built‑in email Apps on phones/computers, etc.): must use client‑specific password to log in;
    • Web (https://mail.zju.edu.cn): use your original custom password along with the second verification to log in.
2

Choosing Verification Methods for Different Usage Scenarios

Using Browser Only

Only need to enable two-factor authentication, no need to set up client-specific passwords. Currently, four verification methods are available: SMS, WeChat, ZJU DingTalk, and External OTP.

Setup 2FA

Using Email Clients

Need to complete two-factor authentication setup first, then set up client-specific passwords. Passwords used for web login and client login will be independent of each other, providing higher security.

Setup Client Password

Multiple Users or Overseas Use

External OTP App verification is recommended. It's not restricted by region, supports multiple simultaneous users, and is more suitable for work emails or overseas access.

Setup OTP

⚙️2. How to Setup Two-factor Authentication?

To set up two-factor authentication, please log in to Zhejiang University Email System (https://mail.zju.edu.cn) via browser, click 「Settings」→「Security」→「Two-factor authentication」, then select and bind verification method.

Two-factor Authentication Setup Interface
Click to enlarge
Two-factor Authentication Setup: Settings → Security → Two-factor authentication setup

Select Verification Method (Click to Expand for Detailed Setup Steps)

SMS Verification (Mainland China mobile numbers only)
1

Access the Binding Page

Log in to https://mail.zju.edu.cn and click 「Settings」→「Security」→「Two-factor authentication」to access the binding page, then click 「Bind」 next to “SMS”.

2

Enter Mobile Number

Enter your Mainland China mobile number into the "Telephone" box in the pop-up window.

3

Receive and Enter Verification Code

Click "Send", enter the received 6-digit code into the "Code" box, and click "Confirm" to complete mobile binding.

SMS Binding
Click to enlarge
SMS Binding
WeChat Verification
1

Access the Binding Page

Log in to https://mail.zju.edu.cn and click 「Settings」→「Security」→「Two-factor authentication」to access the binding page, then click 「Bind」 next to "WeChat".

2

Scan via WeChat

Scan the QR code displayed on the pop-up window using WeChat.

3

Confirm Binding

Confirm the binding operation in WeChat to complete WeChat account association.

WeChat Binding
Click to enlarge
WeChat Binding

Note: When using WeChat verification, ensure your phone time is completely synchronized with computer time, otherwise verification may fail.

ZJU DingTalk Verification (For ZJU members only)
1

Access the Binding Page

Log in to https://mail.zju.edu.cn and click 「Settings」→「Security」→「Two-factor authentication」to access the binding page, then click 「Bind」 next to "DingTalk".

2

Scan via ZJU DingTalk

Scan the QR code displayed on the pop-up window using ZJU DingTalk.

3

Confirm Binding

Confirm the binding operation in ZJU DingTalk to complete ZJU DingTalk account association.

ZJU DingTalk Binding
Click to enlarge
ZJU DingTalk Binding
External OTP App Verification (For overseas use or shared mailboxes)
1

Install OTP App

Install external OTP Apps from your phone's App store, such as Microsoft Authenticator, Google Authenticator, or Authing Token (for Huawei phones) and so on.

2

Access the Binding Page

Log in to https://mail.zju.edu.cn and click 「Settings」→「Security」→「Two-factor authentication」to access the binding page, then click 「Bind」 next to “External OTP”.

3

Scan QR Code via OTP App

Scan the QR code displayed on the pop-up window using the OTP App installed in Step 1.

4

Enter Dynamic Password

Enter the 6-digit dynamic password in the OTP App into the "Dynamic Password" box, and click "Confirm" to complete binding.

External OTP App Binding
Click to enlarge
External OTP App Binding

Important Notes:

  • Shared Accounts: Please properly save a screenshot of the QR code on the binding page for others to scan and bind, enabling multiple simultaneous users.
  • Time Synchronization: OTP dynamic passwords are time-based with 1-minute validity. Ensure phone and computer times are completely synchronized.
  • Overseas Access: OTP verification has no regional restrictions, no SMS reception needed, suitable for overseas users.

Note: If you only use ZJU Email via web browser and complete the above setup, you can use ZJU Email normally without further steps.

🔑3. How to Setup Client-specific Password?

After enabling two-factor authentication, email clients must use client‑specific password to log in. Please follow the instructions below to setup client-specific password. Email clients include Foxmail, Outlook, built‑in email Apps on phones/computers, etc.

Note: If you continue using original web password in the email client after two-factor authentication is enabled, the client may display an error such as "Account error". Once client‑specific password is configured, the client will work normally.

1

Generate Client-specific Password

  1. Log in to Zhejiang University Email System (https://mail.zju.edu.cn) via browser, complete Two-factor Authentication Setup as instructed above.
  2. Click 「Settings」→「Security」→「Client-specific password」.
  3. Click 「Generate Specific Password」, enter an identifiable password name (like "Mobile Client Password", "PC Client Password", etc.). Password name is not password!
  4. Click 「Generate」 button, system will generate a 16-character password randomly. No spaces, Case-sensitive
  5. Click 「Copy」 button to save client-specific password, as it is shown only once.
Generate Client-specific Password
Click to enlarge
Generate Client-specific Password: Settings → Security → Client-specific password → Generate Specific Password

Usage of Client-specific Password:

  • Client-specific password is 16 characters generated randomly, no spaces, case-sensitive.
  • One client-specific password can be used simultaneously on multiple devices.
  • Up to 6 client-specific password can be set, convenient for managing different devices.
  • If forgotten, you can only delete and regenerate client-specific password.
2

Setup Client-specific Password in Clients (Click to Expand for Common Client Setup Methods)

「Foxmail」PC Client Setup
  1. When Foxmail shows "Account Error", enter the generated client-specific password in “Password” box.
  2. Click 「Setup account」→「Advanced」 to configure servers.
  3. In the pop-up window, set server address and port, confirm both incoming (IMAP/POP3) and outgoing (SMTP) server passwords are updated to the client-specific password.
  4. Click 「Done」 and restart the program.
Foxmail Client Setup
Click to enlarge
Foxmail Client Setup
「Outlook」PC Client Setup
  1. Click ZJU email account, Outlook report "you need to sign in".
  2. In the pop-up window, set server address and port, confirm both incoming (IMAP/POP3) and outgoing (SMTP) server passwords are updated to the client-specific password.
  3. Click 「Continue」 and restart the program.
Outlook Client Setup
Click to enlarge
Outlook Client Setup
Mac「Mail」Client Setup
  1. When Mail App shows "Can't connect to the account "zju.edu.cn"", enter the generated client-specific password in “Password” box.
  2. Click 「Settings」→「Accounts」→「Server Settings」.
  3. Set server address and port, confirm both incoming (IMAP/POP3) and outgoing (SMTP) server passwords are updated to the client-specific password.
  4. Save settings and restart the program.
Mac Mail Client Setup
Click to enlarge
Mac Mail Client Setup
Huawei「Email」Client Setup
  1. Open 「Email」 App, click top-right 「Settings」→ select ZJU email account →「Server Settings」.
  2. In the pop-up window, set server address and port, confirm both incoming (IMAP/POP3) and outgoing (SMTP) server passwords are updated to the client-specific password (Huawei phones don't support pasting).
  3. Click 「Done」 and restart the program.
Huawei Phone Email Client Setup
Click to enlarge
Huawei Phone Email Client Setup

Note: Huawei Email client does not support password pasting, you need to manually enter the 16-character password (no spaces, case-sensitive).

iPhone「Mail」Client Setup
  1. When Mail App shows "Unable to receive mail", click phone's 「Settings」→「Apps」→「Mail」→「Mail Accounts」→「zju.edu.cn」→「Account Settings」.
  2. In the pop-up window, set IMAP account information and incoming mail server (password needs to be client-specific password).
  3. In 「Account Settings」 page click 「SMTP」, set outgoing mail server address, port and password (needs to be client-specific password), click 「Done」, then return to「Account Settings」 page.
  4. In 「Account Settings」 page click 「Advanced」, set incoming mail server port, then return to「Account Settings」 page.
  5. Click 「Done」 and restart the program.
iPhone Mail Client Setup
Click to enlarge
iPhone Mail Client Setup

Note: iPhone needs to set both incoming and outgoing server passwords separately. Ensure both are updated to the 16-character client-specific password (no spaces, case-sensitive).

Note:

  1. If errors still appear after saving the client settings, please check whether you have updated the passwords for both the incoming and outgoing mail servers, and confirm that the client‑specific password is entered correctly (16 characters, no spaces, case‑sensitive).
  2. If the issue persists, try changing network (switch Wi-Fi/mobile data) or save the settings, exit the client, wait a moment, and log back in.
  3. If still unresolved, contact Information Technology Center for technical support.

Technical Support

If you encounter any issues while using ZJU Email, please feel free to contact us:

📞

24/7 Service Hotline

0571-87951669

Security is everyone's responsibility. Thank you for your understanding and support of ZJU Email!