Skip to content

Connecting a mail client

Every Mailspace mailbox can be opened in a desktop or phone mail app as well as in webmail — the Mailboxes list describes them as Mailboxes with IMAP/SMTP access and webmail login. This guide covers the two things you need for that: the connection settings the dashboard shows you, and app passwords, a separate credential you can hand to one mail app instead of giving it the mailbox password.

It does not give click-by-click instructions for any particular mail app. Apple Mail, Outlook, Thunderbird, the Gmail app and the rest all ask for the same five things — a server name, a port, an encryption setting, a username and a password — but they ask in different places, and they rename the fields. Get the values from the dashboard, then put them wherever your app asks for them.

Before you start

  • A mailspace that has finished setting up. Until it is provisioned, its management pages send you back to the domain-verification step instead — see Verifying your domain.
  • At least one mailbox, and its password. If nobody knows the password any more, set a new one on the mailbox rather than hunting for the old one.
  • To create, restrict or revoke an app password you need to be a workspace member who can make changes. A view-only member is turned away with You do not have permission to perform this action.

Let the mail app try first

The dashboard's own advice, printed at the top of the Connection Info card, is worth following: "Most email apps set this up automatically. Enter these details by hand only if automatic setup (autodiscover) doesn't work."

  1. Enter the full email address and the mailbox password in your mail app and let it look up the rest. Most apps offer this as the first, simplest option and only reveal server fields if the lookup fails.

  2. If the lookup fails, check the autoconfiguration DNS records. Automatic setup relies on two CNAME records — autoconfig.<your-domain> and autodiscover.<your-domain> — which are listed with the rest of the mail records on the mailspace's DNS Records page. On a domain whose DNS we run, they are written for you; on a domain using DNS elsewhere you have to add them at your own DNS provider, and until you do, automatic setup has nothing to find.

Either way you can always fill the settings in by hand, which is what the rest of this page is about.

Read the settings off the Connection Info card

  1. Open the mailspace. Choose Mailspace in the workspace sidebar, then the mailspace you want. You land on its Overview page.

  2. Find the Connection Info card. It sits on the Overview page and is badged Manual setup. Everything a mail app asks for is on it, in three blocks: Sign in, Incoming and Outgoing.

  3. Copy the server name. Every protocol row shows the same server name — the card repeats it per row because that is how mail apps ask for it, field by field. It is mail. followed by the mailspace's primary domain. Each row has a copy button (Copy IMAP server, Copy POP3 server, Copy SMTP server) so you can paste the exact value rather than retyping it.

  4. Pick incoming or outgoing per field. The card labels the ports with their encryption, exactly as your mail app needs them:

    Block Protocol What the card says it does Port and encryption
    Incoming IMAP syncs mail across devices 993 · SSL/TLS
    Incoming POP3 downloads to one device 995 · SSL/TLS
    Outgoing SMTP sends your mail 465 · SSL/TLS or 587 · STARTTLS

    Choose IMAP unless you have a specific reason not to: POP3 downloads mail to one device, so a second device or webmail won't see the same mailbox state. For outgoing mail either SMTP port works — use whichever encryption setting your app offers, and if it lists both, 587 · STARTTLS is the one most apps default to.

  5. Use the same credentials for sending. The Sign in block gives Username as your full email address and Password as your mailbox password, and the Outgoing block adds: "Requires sign-in — use the same username and password." Mail apps often leave outgoing authentication switched off by default, or offer to send anonymously — don't; sending needs the same sign-in as receiving.

    The word (set or reset) beside the password is a link to the Mailboxes list, where you can set a new password on the mailbox — see Managing mailboxes.

Copy, don't transcribe

The card is the authority for your mailspace, not this page. If a value on screen ever differs from what you read here, the screen wins — use its copy buttons.

Use an app password for a mail app

An app password is a second credential on the same mailbox, meant for exactly this job. The dashboard describes them as Separate credentials for mail clients and apps — recommended for IMAP/SMTP/JMAP. They are a recommendation rather than a requirement: the mailbox password works in a mail app too. What an app password buys you is containment — one credential per app, each with its own name, each revocable on its own.

You can only add one to a mailbox that already exists; while creating a mailbox the field reads Only available after creation.

  1. Open the mailbox's settings. Go to Mailboxes, open the row's actions menu and choose Edit mailbox. The page is titled with the mailbox's address and has a Back button to the list.

  2. Scroll to Security → App passwords. The field shows how many the mailbox currently has, and lists them if there are any. Each row carries its name and Created plus the date — that date is the only history kept for a credential; there is no "last used" anywhere.

  3. Save any other pending edits first. The dialog warns Adding reloads this page — save any other changes first. Unlike the rest of the mailbox form, an app password is not deferred until you press save: it is created on the server the moment you confirm.

  4. Click Add app password, then name it in the New app password dialog. The Name / description field is required — leave it blank and the dialog answers Give this app password a name. Name it after the thing that will hold it, the way the dialog's own example does (e.g. Thunderbird on laptop): the name is what you'll read months later when deciding which one is safe to revoke.

  5. Confirm your identity with your passkey or password, if you haven't recently. Creating an app password is a sensitive action, so it can prompt for a re-confirmation step. Restricting or revoking an existing one does not.

  6. Copy the password before you close anything. Copy this password now — it won't be shown again. Use the Copy button beside it, paste it into the mail app, and only then dismiss the panel — the confirm button turns into Done once the secret is on screen. This is the one and only time the value is readable: it is handed over once and never stored anywhere you can read it back. If the identity check in step 5 fired, the page reloads and the new password appears in a New app password panel at the top of the mailbox page instead of in the dialog — same value, same copy button, and it is gone on the next render.

  7. Use it exactly like the mailbox password. Same server name, same ports, same username — your full email address. Only the password differs.

Lost an app password? Make another one.

There is no way to see an app password again after that first screen, and no "show" button anywhere. If it wasn't captured, revoke it and add a replacement. Revoking is immediate and can't be undone — the dialog names the credential and warns that any mail client signed in with it will stop connecting.

Restrict an app password to known addresses

The shield button on an app-password row (Restrict to IP addresses) opens an Allowed IP addresses editor on that row. Enter one or more addresses or CIDR ranges, comma separated — the placeholder shows the shape, 192.168.1.0/24, 203.0.113.7 — and leave it empty to allow any address. A row with a restriction shows a badge counting the addresses.

The restriction takes effect straight away and applies only to that one credential — it cannot lock anyone out of webmail or affect the mailbox's own password. What it does not do is explain itself to the blocked app: A mail client connecting from anywhere else is refused without being told the address is why — it sees a permission or connection error, not a wrong password. Only use it for an app on a connection whose address doesn't change.

If the mail app won't connect

Work through these before assuming the password is wrong.

  • Certificate warnings usually mean DNS, not a bad certificate. The mailspace's certificate is issued for the mail host alone, and the Mail Authentication card on the Overview page has a Mail host row described as Mail server address — required for SSL. If that row reads ✕ Not found or ! Mismatch rather than ✓ Detected, the mail host isn't pointing at us and mail apps will complain. The card's DNS Records button takes you to the exact values.

  • An unexplained refusal, or a connection that simply drops, can be an IP restriction rather than a credential problem. There are two, at two levels: the per-credential Allowed IP addresses above, and the mailbox's own Sign-in IP restriction, whose footnote spells out the blast radius — it covers webmail and every mail client, and someone signing in from anywhere else is refused without being told the address is why — they see a permission or connection error, not a wrong password. Check both on the mailbox's settings page.

  • Sending fails while receiving works points at the outgoing side: the account has no sign-in configured, or it is set to a different username. The card is explicit that outgoing Requires sign-in — use the same username and password.

  • Nothing on the mailbox can be changed at all. If the mailspace is scheduled for deletion, its pages go read-only with This mailspace is scheduled for deletion and can't be changed. Restore it first. — see Deleting and restoring a mailspace. A mailspace whose mail is on hold can't be managed either.

  • Rule out the mail app. Sign in to Webmail with the same address and mailbox password. If webmail works and the app doesn't, the credentials are fine and the problem is in the app's settings. The Webmail button is on the Overview page and on every row of the Mailboxes list; when it is greyed out its tooltip names the webmail host and tells you to add that DNS record at your DNS provider first.

Next steps

  • Add an app password per device rather than reusing one, so losing a phone costs you one revocation instead of a password change everywhere.
  • Set up the rest of the mailboxes your team needs — see Managing mailboxes.
  • Check the Mail Authentication card on the mailspace Overview page if outgoing mail is being rejected or filtered by the receiving side.
  • Not ordered a mailspace yet? Start at Ordering a Mailspace.