Skip to content

NETSE ENTERPRISE SOLUTIONS

Zimbra FOSS / OSE

Zimbra SMS & TOTP 2FA Login

Secure webmail sign-ins with SMS OTP or Google Authenticator (TOTP). Multi-provider SMS integration, Trusted IP bypass, and App Passwords to elevate your corporate email security.

Zimbra Webmail · Secure SMS / TOTP 2FA

Step 2 — Two-Factor Verification

Enter SMS or Authenticator Code

Type the 6-digit security code sent to your mobile device.

Verify and Sign In
Netgsm / Ileti Merkezi / TFonSMS ✓ 99.9% Uptime SLA
Enterprise 2FA Module

Zimbra SMS & TOTP 2FA Login Features Catalogue

Eliminate credential theft: enforce mandatory or optional SMS OTP and Google Authenticator (TOTP) verification on Zimbra webmail logins, with dedicated IP bypass for office networks.

Core Capabilities

Technical & Operational 2FA Features

A zero-dependency, native security module built specifically for Zimbra Mailbox Servers.

Domain-Based 2FA & TOTP

Configure independent 2FA policies for each domain. Require SMS OTP and/or Google Authenticator (TOTP) on webmail logins.

  • Domain-specific policy rules
  • SMS OTP or TOTP Authenticator
  • Clear per-user method selection

Multi-SMS Provider Integration

Ready out-of-the-box for Netgsm (REST v2 & Legacy), Ileti Merkezi (API v1), and TFonSMS. Test and select sender headers with one click in the admin panel.

  • Netgsm, Ileti Merkezi & TFonSMS ready
  • Automatic sender header (msgheader) retrieval
  • One-click provider connectivity test

Flexible Enforcement Policies

Mandatory 2FA forces enrollment on first webmail login. Optional 2FA allows users to self-activate under Preferences > Security.

  • Mandatory or optional enforcement
  • Preferences > Security UI integration
  • Phased domain-by-domain rollout

Trusted IP & Office Bypass

Bypass 2FA for internal corporate networks, static IPs, or VPN blocks (CIDR). Accurate real IP detection behind Nginx/Proxies via X-Forwarded-For.

  • CIDR IP subnet support (10.0.0.0/8, etc.)
  • X-Forwarded-For real client IP parsing
  • Instant password-only sign-in from office

App Passwords for Desktop & Mobile

Enforce unique `SHA-256 (Salt + Secret)` App Passwords for Outlook, Thunderbird, Apple Mail, IMAP, POP3, SMTP, CalDAV, and CardDAV clients.

  • Protect primary account credentials
  • Per-device dedicated app password generation
  • Secure SHA-256 password hashing

SMS Rate Limiting & Abuse Prevention

Protect against malicious SMS requests and budget overruns with a 60-second Cooldown period and a 15-minute 5-SMS Window Limit.

  • 60-second request cooldown
  • 5 SMS per 15-minute window limit
  • Cost containment & SMS spam defense

Zimbra LDAP & Directory Sync

Automatically read `mobile` or `telephoneNumber` attributes from Zimbra LDAP, sync verified phone numbers, and apply interface masking (`05xx***xxxx`).

  • Automatic LDAP attribute extraction
  • Interface masking (05xx***xxxx)
  • Standard phone format normalization

Admin Console Exemption & Management

Zimbra Admin Console (ports 7071/9071) is automatically exempt to prevent admin lockouts. Admin Zimlet (`Configure > 2FA Security`) for user resets.

  • Admin port exemption (7071/9071)
  • Native Admin Zimlet UI
  • One-click user 2FA reset

Secure RSA Licensing Engine

`SHA256withRSA` digital signature verification prevents tampering. 3-day offline Grace Period for network outages and automated passthrough fallback.

  • RSA digital signature verification
  • 3-day offline Grace Period
  • Non-blocking passthrough fallback

Yearly License Plan

Flat rate server license. Unlimited users, all 2FA capabilities, and technical support included.

Enterprise License

$299 / year

Bound to your Zimbra server instance via RSA digital signature. Even if the license expires, mail flow is never locked; the engine gracefully falls back to standard password login (`passthrough`).

All Features Included

  • Zimbra SMS & TOTP 2FA plugin (Zimbra FOSS/OSE)
  • Netgsm, Ileti Merkezi & TFonSMS integration
  • Custom SMS / GSM provider integration on request
  • Domain-based independent 2FA enforcement
  • Trusted IP & CIDR VPN/Office bypass
  • App Passwords for Outlook, Thunderbird & Mobile
  • Zimbra Admin Console (7071) auto-exemption
  • English & Turkish Admin Zimlet UI
  • Server-bound RSA signed $299/year license

How Zimbra SMS & TOTP 2FA Sign-In Works

Seamless user experience in 4 simple steps.

  1. 01

    Enter Password

    Users sign in on the familiar Zimbra webmail login screen with their email and password.

  2. 02

    Receive SMS or TOTP Code

    A one-time SMS code or Authenticator prompt is triggered. Trusted office IPs skip this step.

  3. 03

    Verify Code

    Entering the correct code completes Zimbra 2FA verification and opens the user session.

  4. 04

    Access Mail Securely

    Webmail continues normally. Desktop and mobile mail apps connect using dedicated App Passwords.

Get a Quote

Zimbra SMS Login Quote Form

Submit your yearly $299 license request. Include details in your message if you require a custom SMS API gateway.

This form is protected by security verification.

Frequently Asked Questions

Answers to common questions about Zimbra SMS Login, TOTP 2FA, and licensing.

What is Zimbra SMS & TOTP 2FA Login?

It is an enterprise security extension for Zimbra webmail that adds SMS OTP and Google Authenticator (TOTP) two-factor authentication to the standard sign-in flow.

What is Zimbra Two-Factor Authentication (2FA)?

Zimbra Two-Factor Authentication (2FA) is a security layer that requires users to enter a one-time verification code sent via SMS or TOTP app after entering their email password on Zimbra webmail.

Will Zimbra minor or major updates remove the plugin?

No. The module is integrated via Zimbra CustomAuth API standards, ensuring persistence across Zimbra system upgrades.

What happens if a user loses their phone?

A system administrator can reset the user’s 2FA status with a single click inside the Zimbra Admin Zimlet (`Configure > 2FA Security`).

Can we switch SMS providers or integrate a custom GSM gateway?

Yes. Netgsm, Ileti Merkezi, and TFonSMS are supported natively. If you use a custom HTTP REST API gateway, we can add integration upon request.

How do Outlook and mobile email apps connect with 2FA enabled?

Outlook, Thunderbird, and mobile clients use dedicated App Passwords. Users generate app-specific passwords without revealing their primary domain password.

Can office networks bypass SMS 2FA?

Yes. You can define trusted corporate IP subnets or VPN CIDR blocks (`10.0.0.0/8`, `192.168.1.0/24`) to bypass 2FA while inside the office.

Does the Zimbra Admin Console (port 7071) get locked?

No. The Zimbra Admin Console (`7071` & `9071` ports) is automatically exempt from SMS 2FA to prevent administrative lockout.

What happens if the license expires or internet goes down?

The engine features a 3-day offline Grace Period. If a license expires, mail delivery and access are never blocked; the system gracefully falls back to standard password login (`passthrough`).

What is the license pricing model?

Single server license: $299/year. Unlimited users, full feature access, and setup support are included.