Skip to content

Reading mail here

Connecting a mail app

IMAP settings, and why the password is not your account password.

Settings

  • Server: shown on the Mail provider page, alongside your login username.
  • Port: 993.
  • Encryption: SSL/TLS. Not "none", not "STARTTLS on 143".
  • Username: the login username shown on that page, which is not always your account username.
  • Password: an app password, created on the same page.

Why an app password

A mail client stores the password it is given, in a way you do not control, on a device that may be lost. An app password is scoped to mail and can be revoked on its own, so a lost laptop costs you one credential rather than the account.

Each one is shown once. Create one per device, and name them after the device, because a list of app passwords is only useful if you can tell which one to revoke.

What an app password cannot do

Sign in to the web account, read your recovery key, change your password, create aliases, or see your list of recipients. It carries mail and nothing else.

Sending from a client

Submission uses the same credentials. Sending as an alias from a client works, provided the alias is yours and is switched on.

If it will not connect

  • Check the mailbox is actually enabled under Mail provider. A client cannot connect to a mailbox that does not exist.
  • Check you used the app password rather than the account password.
  • Check the client has not quietly fallen back to port 143 without encryption, which some clients do while showing a green tick.

Written for people using Skudo. If a page here is wrong or missing, tell us.