What was previously only available as a beta version for selected testers is now being activated for all customers: the new Login 2.0.
Before today, mailbox.org's 2FA mechanism was unorthodox. In the login screen, you typed in the TOTP in the password field and then added a 4 digit static pin at the end. This got people confused, as it's different than the usual login+password then TOTP. Now it's just like that.
You could use third party clients with 2FA enabled in the past (at least I could). I think I used my normal password for the clients, so no real 2FA on that side, but that's no different from the new app specific passwords. IMAP doesn't allow 2FA so every mail provider allowing third party clients essentially has a weak point with no 2FA there.
How can I enable it? I received the mail but my login is still using pin+otp and in the settings there is no option to migrate to normal F2A, only the old pin+opt thing.
Maybe most people using Mailbox know about this but I'll still mention that using Mailbox kinda requires having your own domain.
Reason is the same as Posteo (unless Posteo changed something lately) : mail adresses will get recycled after some time when you stop using the service and close your account.
Most other providers blacklist adresses so they can't get reused when an account gets deleted.