Skip to main content
Resources

ICANN Account MFA FAQs

Background

What Is Multi-Factor Authentication (MFA)?

Multi-factor authentication is a multistep account login process in which a user is granted access to an application only after presenting two or more pieces of evidence, or authentication factors, such as a password, key card, PIN, fingerprint, etc.

What Authentication Factors Will I Need to Use to Access My ICANN Account?

ICANN Account requires a user-selected password that is created when setting up your ICANN Account and a time-based one-time password (TOTP) generated by a TOTP authenticator app.

Why Should I Use MFA on My ICANN Account?

Using MFA significantly reduces the risk of bad actors gaining access to your ICANN Account and helps ensure that your sensitive data remains protected

Enabling MFA on Your ICANN Account

How Do I Enable TOTP MFA on My ICANN Account?

To enable TOTP MFA on your ICANN Account follow these steps:

  1. Log in to your ICANN Account with your username and password.
  2. Navigate to the "Manage Your Account" page by hovering over your username on the upper right corner of the ICANN Account homepage and then clicking on "Manage Account."
  3. Click on the "Security" tile.
  4. On the "Manage Your Security Settings" page, click on "Manage MFA."
  5. On the "Manage Your Multi-Factor Authentication Settings" page, select to enable "Time-Based One-Time Password Authentication" by clicking the blue "Enable" link and following the prompts on the screen.

Where Can I Download a TOTP Authenticator App?

Visit your Smartphone's app marketplace (that is, App Store for iOS, Google Play Store for Android, AppGallery for HarmonyOS, etc.) and search for "TOTP authenticator app."

How Do I Connect My ICANN Account to My TOTP Authenticator App?

Open your TOTP authenticator app on your smartphone and click on the "+" icon. The TOTP authenticator app will prompt you to scan a QR code. Using your smartphone's QR scanner, scan the QR code provided on the second step of the ICANN Account TOTP Authentication Setup page. Finally, follow the prompts on your TOTP authenticator app and on the ICANN Account TOTP Authentication Setup page to complete the setup process.

How Do I Enable Voice Call MFA on My ICANN Account?

To enable Voice Call MFA on your ICANN Account, follow these steps:

  1. Log in to your ICANN Account with your username and password.
  2. Navigate to the "Manage Your Account" page by hovering over your username on the upper right corner of the ICANN Account homepage and then clicking on "Manage Account."
  3. Click on the "Security" tile.
  4. On the "Manage Your Security Settings" page, click on "Manage MFA."
  5. On the "Manage Your MFA Settings" page, select to enable Voice Call Authentication by clicking the blue "Enable" link and following the prompts on the screen.

Can I Use Voice Call Authentication Internationally?

Yes, Voice Call authentication is available internationally.

Can I Enable Both TOTP and Voice Call Authentication?

Yes, you can activate both TOTP and Voice Call Authentication for your ICANN Account. When both are active, the system will ask you which method you'd like to use for verification. Furthermore, using both methods offers a backup option if you cannot access one or the other.

Troubleshooting ICANN Account MFA

What If I Lose Access to My TOTP Authenticator App and Am Locked Out Of My ICANN Account?

To avoid being locked out of your ICANN Account if you cannot access your TOTP authenticator app, it is recommended that you enable both TOTP and Voice Call Authentication. This way, if one method becomes unavailable, you'll still have an alternate way to verify your identity and access your account.

What TOTP Authenticator Apps Does ICANN Recommend?

ICANN does not endorse any specific TOTP authenticator app. However, ICANN Account's MFA is compatible with apps that use the TOTP protocol. To find a trustworthy TOTP authenticator app, browse the Apple App Store or the Google Play Store for "TOTP authenticator." It's a good idea to opt for apps with reliable user reviews and recommendations.

Domain Name System
Internationalized Domain Name ,IDN,"IDNs are domain names that include characters used in the local representation of languages that are not written with the twenty-six letters of the basic Latin alphabet ""a-z"". An IDN can contain Latin letters with diacritical marks, as required by many European languages, or may consist of characters from non-Latin scripts such as Arabic or Chinese. Many languages also use other types of digits than the European ""0-9"". The basic Latin alphabet together with the European-Arabic digits are, for the purpose of domain names, termed ""ASCII characters"" (ASCII = American Standard Code for Information Interchange). These are also included in the broader range of ""Unicode characters"" that provides the basis for IDNs. The ""hostname rule"" requires that all domain names of the type under consideration here are stored in the DNS using only the ASCII characters listed above, with the one further addition of the hyphen ""-"". The Unicode form of an IDN therefore requires special encoding before it is entered into the DNS. The following terminology is used when distinguishing between these forms: A domain name consists of a series of ""labels"" (separated by ""dots""). The ASCII form of an IDN label is termed an ""A-label"". All operations defined in the DNS protocol use A-labels exclusively. The Unicode form, which a user expects to be displayed, is termed a ""U-label"". The difference may be illustrated with the Hindi word for ""test"" — परीका — appearing here as a U-label would (in the Devanagari script). A special form of ""ASCII compatible encoding"" (abbreviated ACE) is applied to this to produce the corresponding A-label: xn--11b5bs1di. A domain name that only includes ASCII letters, digits, and hyphens is termed an ""LDH label"". Although the definitions of A-labels and LDH-labels overlap, a name consisting exclusively of LDH labels, such as""icann.org"" is not an IDN."