
Written and reviewed by the team operating TempMail Cloud. Product claims are checked against our live service and our editorial standards.
An online TOTP generator must be judged by what it does with the setup secret, including its Save and Share controls. Local calculation does not mean a secret can never leave the device. Use synthetic test secrets when evaluating a tool; use an authenticator appropriate to your security needs for important accounts.
What TempMail Cloud does with a key
| Action | Current behavior | What to consider |
|---|---|---|
| Generate a code | Calculates in the browser using the entered Base32 key | The device, browser, extensions and delivered page code still matter |
| Save Key as a guest | Stores the key in browser local storage | Closing the tab does not delete a saved key |
| Save Key while signed in | Sends the key to the account service for synchronization | This is server-held storage, separate from calculation |
| Create a sharing link | Uses a separate sharing workflow | Review that workflow's permissions and retention before proceeding |
| Clear the input field | Removes the visible input | It does not revoke a provider enrollment or erase saved copies |
The 2FA tool currently generates six digits with SHA-1 and a 30-second period. A service using different parameters needs a compatible authenticator. The generator cannot infer the secret from an email address or recover another provider's account.
A safe evaluation recipe
Use an isolated test account that you own, with no access to customer or production data. Review the page's privacy explanation before entering its test key. Decide separately whether you want to calculate, save, synchronize or share it. Confirm the test account accepts a current code, then remove the test enrollment when the evaluation is over.
For example, saving a disposable QA key while signed in is an intentional account-sync test. Merely closing that tab is not a deletion test. To assess deletion, use the saved-key controls and verify the relevant account state. Do not substitute your work account's real authenticator seed for the disposable fixture.
This is a proposed test procedure, not a claim that we performed a security assessment of every browser or account configuration.
The setup secret matters more than one code
A TOTP code is calculated from a shared secret and time. Someone with a copy of the secret can keep generating codes until the account replaces that enrollment. Treat QR images, backup exports and copied setup text as credentials. The algorithm's requirements are described in RFC 6238.
If a real secret reached an untrusted page, deleting the local text is insufficient. Use the affected provider's official security settings or recovery route to replace the authenticator, then review its active sessions and recovery methods. Keep a working recovery option available while making that change.
A valid code does not prove the login page is legitimate
An attacker can relay a manually entered code to the real site. NIST does not classify manually entered OTP authentication as phishing-resistant. Where supported, consider passkeys or security keys and review their recovery arrangements. NIST phishing-resistance guidance.
For a rejected code, use time and setup troubleshooting. For the difference between receiving a message and generating a code, read TOTP versus email OTP.