Email Settings Email Settings Guide

Amazon WorkMail Settings: IMAP and SMTP by AWS Region

Every server address and port for Amazon WorkMail in Outlook, Apple Mail, Thunderbird or your phone. The hosts are specific to your AWS region. WorkMail uses IMAP with no POP. Copy each value with 1 tap.

Tested July 27, 2026 1 Tap Copy App Password Steps

Amazon WorkMail Quick Settings

IMAP Server imap.mail.us-east-1.awsapps.com
IMAP Port 993 (SSL/TLS)
SMTP Server smtp.mail.us-east-1.awsapps.com
SMTP Port 465 (SSL only)
Region us-east-1 / us-west-2 / eu-west-1
Username Your full email address

Quick answer: the Amazon WorkMail IMAP server is imap.mail.us-east-1.awsapps.com on port 993 with SSL. The SMTP server is smtp.mail.us-east-1.awsapps.com on port 465 with SSL. Swap us-east-1 for your AWS region, such as us-west-2 or eu-west-1. WorkMail has no POP and no STARTTLS. Sign in with your full WorkMail address and your WorkMail password.

Every setting on this page is verified with live IMAP and SMTP connections from Univik email software. We build email backup and converter tools since 2013, so we test against these servers every day. See what changed →

What Changed Recently#

The biggest news for Amazon WorkMail is its retirement. Here is what that means, alongside how the servers work today.

Latest update

AWS is ending Amazon WorkMail on March 31 2027. The service stopped taking new customers on April 30 2026. Existing accounts run until March 31 2027, after which the console, web client and the IMAP and SMTP endpoints all shut down for good. Plan a move and a backup well ahead of the deadline.

Earlier change

Servers are tied to your AWS region. The host reads imap.mail.REGION.awsapps.com, where REGION is where your WorkMail organization lives. A host from the wrong region does not connect.

Earlier change

IMAP only, no POP. WorkMail retrieves mail over IMAP alone. There is no POP server. Outgoing SMTP runs on port 465 with SSL and does not offer STARTTLS.

Current status: IMAP and SMTP work today on the region hosts, using your full WorkMail address and your mailbox password. Support ends on March 31 2027.

Before You Begin#

Two things decide whether WorkMail connects on the first try. Get them right and the tables below do the rest.

1. Know your AWS region

Every WorkMail host contains your region. The wrong region means no connection, whatever else you type. Find it in the WorkMail console or your web client URL.

Where: Region endpoint steps below →

2. Use IMAP, not POP

WorkMail offers IMAP only. If your client defaults to POP, switch it to IMAP or the mailbox will not load.

Where: IMAP settings below →

About Amazon WorkMail#

Amazon WorkMail is the managed business email and calendar service from Amazon Web Services, built on AWS infrastructure with Outlook, mobile and IMAP client support.

WorkMail launched in 2016 as a managed alternative to running your own Exchange server. It works with a custom domain of your own and with Outlook over Exchange ActiveSync, mobile clients and any IMAP client. The detail that shapes every client setup is the region. Each mailbox lives in one AWS region. WorkMail lets you pick that region for data locality and encrypts your mail at rest with AWS KMS keys you control. The IMAP and SMTP hosts carry that region in their name. AWS has announced that WorkMail support ends on March 31 2027, so a backup and a migration plan matter more than usual here.

Service NameAmazon WorkMail
Owned ByAmazon Web Services
Launched2016
Email DomainsYour own domain, plus the default @alias.awsapps.com
Webmail URLhttps://alias.awsapps.com/mail
Protocols SupportedIMAP and SMTP. No POP
App Password NeededNo. Use your mailbox password
Support EndsMarch 31 2027
Amazon WorkMail support ends March 31 2027: after that date AWS shuts down the console, web client and the IMAP and SMTP endpoints. Whatever domain you use, plan to back up your mailbox and move to another provider before the deadline.

Amazon WorkMail Webmail Login#

You can always read your mail in a browser. The official sign in pages are:

Watch out for fake support pages. Many pages ranking for email settings show a phone number and ask you to call for "expert setup help". Amazon WorkMail and Univik never ask you to call a number to enter server settings. Everything you need is free on this page.

Find Your Region Endpoint#

Every WorkMail host carries your AWS region, so the first job is knowing which region your organization sits in. WorkMail runs in three regions today:

  1. US East, N. Virginia uses us-east-1, so the host is imap.mail.us-east-1.awsapps.com.
  2. US West, Oregon uses us-west-2, giving imap.mail.us-west-2.awsapps.com.
  3. Europe, Ireland uses eu-west-1, giving imap.mail.eu-west-1.awsapps.com.
  4. Not sure which one? The region shows in the WorkMail console selector. It also appears in your web client URL at https://alias.awsapps.com/mail.
Swap the region into every host. Once you know your region, put it into both hosts. The IMAP host is imap.mail.REGION.awsapps.com and the SMTP host is smtp.mail.REGION.awsapps.com. A host from the wrong region returns an authentication or connection error even when the password is right.
Use your full email address as the username. The most common WorkMail sign in failure is a username with no domain. The username must be the whole address, such as you@yourdomain.com, not only the mailbox name before the @ sign. A bare username returns a 535 authentication error even when the password and region are correct.

Amazon WorkMail IMAP Settings#

IMAP is the only incoming protocol WorkMail offers. It holds mail on the AWS server so every device shows the same inbox. There is no POP option.

IMAP Serverimap.mail.us-east-1.awsapps.com
Port993
EncryptionSSL required
UsernameYour full address, such as you@yourdomain.com, not only the mailbox name
PasswordYour WorkMail mailbox password
RegionSwap us-east-1 for us-west-2 or eu-west-1 as needed
AuthenticationRequired

Amazon WorkMail SMTP Settings#

SSL only, no STARTTLS: WorkMail SMTP runs on port 465 with SSL and does not support STARTTLS or port 587. If your client offers only 587, look for an SSL option on 465. The plain port 143 for IMAP does not connect either.

SMTP handles outgoing mail. If mail arrives but will not send, look here.

SMTP Serversmtp.mail.us-east-1.awsapps.com
Port465
EncryptionSSL required. No STARTTLS
UsernameYour full WorkMail email address
PasswordThe same mailbox password used for IMAP
RegionUse smtp.mail.us-west-2.awsapps.com and the like to match your region
AuthenticationRequired. Tick outgoing server requires authentication in your client

Check Amazon WorkMail IMAP Settings Online#

You don't need to download anything to check Amazon WorkMail IMAP settings online. This page is the lookup: every value is verified, current and copyable straight from your browser. Not sure your address uses Amazon WorkMail servers? Type it below and find out instantly.

Does my email address use these settings?

Runs in your browser only. Your address is never sent anywhere or stored.

Want to verify the mailbox before setting up a client? Sign in at your WorkMail web client, which confirms the address and password work and shows your region in the URL. With the region and password in hand, any IMAP client connects using the tables above.

Look Up IMAP Settings for Any Email Domain#

This page covers Amazon WorkMail. For every other address, work email on a company domain included, we run a free online lookup database: imapsettings.com.

imapsettings.com

Complete email settings database, by Univik

Check IMAP settings online →

Enter any email address and get the incoming and outgoing server settings for that domain in 1 step:

Incoming server: hostname, port, SSL/TLS and username format
Outgoing server: SMTP hostname, port and encryption

Your address is used only to find the settings for that domain. Nothing is stored or shared.

Set Up Amazon WorkMail in Email Clients#

The region hosts and ports are identical in every app. What differs is where each app hides its menus. Pick yours:

Outlook (Windows and Mac)

  1. Open Outlook and choose File, then Add Account. In the new Outlook this sits under Settings and Accounts.
  2. Type your WorkMail address, expand Advanced options and pick let me set up my account manually. AutoDiscover often fills the rest from your address alone.
  3. Select IMAP, then imap.mail.us-east-1.awsapps.com on 993 SSL and smtp.mail.us-east-1.awsapps.com on 465 SSL. Swap in your own region.
  4. Enter your WorkMail mailbox password at the prompt. WorkMail has no separate app password.
  5. Finish and send a test email to yourself to confirm both directions work.

Apple Mail (macOS)

  1. Open Mail → Settings → Accounts → Add Account.
  2. WorkMail will not appear in the list, so pick Other Mail Account.
  3. Give your name, full address and mailbox password, then continue.
  4. If asked for servers, enter the IMAP and SMTP values from the tables above.
  5. Enable Mail in the checkbox list and finish.

iPhone and iPad

  1. Open Settings → Apps → Mail → Mail Accounts → Add Account.
  2. Tap Other, then Add Mail Account. iOS lists no WorkMail option.
  3. Fill your details with the mailbox password, then tap Next.
  4. Keep IMAP selected and fill the incoming and outgoing servers if iOS asks.
  5. Tap Save and wait for iOS to verify the account.

Android

  1. Open your mail app (Gmail app, Samsung Email or another) → Add account.
  2. Choose Other (IMAP) when your provider is not in the list.
  3. Enter your address and mailbox password. If auto setup does not take, pick Manual setup.
  4. Add the servers: imap.mail.us-east-1.awsapps.com 993 SSL incoming, smtp.mail.us-east-1.awsapps.com 465 SSL outgoing, with your region.
  5. Finish setup and pull down to sync your inbox.

Thunderbird

  1. Open Thunderbird → Account Settings → Account Actions → Add Mail Account.
  2. Type your name, address and mailbox password, then choose Continue.
  3. Let Thunderbird probe the servers, then confirm it chose IMAP over SSL for your region.
  4. If detection fails, choose Configure manually and enter the table values above.
  5. Select Done. Folders sync on first open.

Amazon WorkMail Webmail Settings#

Those values wire up a client. The options here govern how the mailbox behaves. You change them in the WorkMail web client under Settings.

Signature

Set in the WorkMail web client. A signature saved there rides on browser sent mail. Each client keeps its own, so the one a reader sees depends on where the message left from.

Vacation Auto Reply

WorkMail calls this the Out of Office Assistant. Give it a start and end date and it closes itself. The server sends it, so it answers while your devices are off.

Filters and Folders

A rule built in the web client runs server side, sorting mail before any device fetches it. A rule kept inside Outlook runs only while Outlook is open, which is why two apps can sort one message in different ways.

Spam and Blocked Senders

Add a sender or a whole domain to the block list in the web client. If a message goes missing, check the web client spam folder first, since a client rule cannot undo what the server already did.

Why WorkMail Uses IMAP Only#

FeatureIMAP, what WorkMail usesA local backup file
Where mail livesOn the WorkMail server, in syncSaved on your own disk
Multiple devices✅ Everything stays in sync⚠️ A snapshot, not live
Survives the 2027 shutdown❌ Endpoint goes away✅ Yours to keep
Offline reading⚠️ Cached mail only✅ Full local copy
Server storage usedYes, counts against your quotaNone, it lives on your disk
Best forPhone and computer, everyday useKeeping mail past the shutdown
Our verdict: use IMAP for everyday mail, since WorkMail offers nothing else. With the 2027 shutdown coming, also keep a local backup so your mail outlives the service.

Amazon WorkMail Settings Worth Knowing#

These are the connection points that decide an Amazon WorkMail client setup:

Incoming serverimap.mail.REGION.awsapps.com 993, SSL
Outgoing serversmtp.mail.REGION.awsapps.com 465, SSL, no STARTTLS
Regionsus-east-1, us-west-2, eu-west-1
PasswordYour WorkMail mailbox password, no app password
POP supportNone. IMAP only
Support endsMarch 31 2027

Troubleshooting Amazon WorkMail Connections#

Find the exact error your email app shows, then apply the fix:

Error you seeWhat it meansFix
Authentication failed, credentials invalid Host is from the wrong AWS region Match the host to your region in the region endpoint section, such as eu-west-1 for Ireland.
Client cannot find a POP server WorkMail has no POP Set the account type to IMAP and use imap.mail.REGION.awsapps.com on 993 SSL.
Cannot connect to server Wrong port or encryption Confirm IMAP on 993 SSL and SMTP on 465 SSL. WorkMail has no 587, so SSL on 465 is the only outgoing option. A firewall or VPN can block these too.
Password keeps being asked Wrong region host or a typo in the address Confirm the region in the host and re-enter your WorkMail mailbox password.
Messages stuck in Outbox SMTP authentication is off Switch on outgoing server requires authentication and reuse the incoming login.

Reader Reported Fixes

A US client kept failing until the region matched. The mailbox lived in eu-west-1 but the client used the us-east-1 host. Because the host carries the region, the login was refused. Switching both hosts to eu-west-1 connected it at once.

An old client defaulted to POP and would not load mail. WorkMail serves no POP, so the client sat waiting on a host that never answers for POP. Changing the account type to IMAP on 993 SSL fixed it.

Moving Off WorkMail Before March 2027#

The clock is real. AWS shuts WorkMail down on March 31 2027. After that the IMAP and SMTP endpoints, the web client and the console all stop. Anything not moved by then is lost.

Back up first, using the same region host. A backup connects over imap.mail.REGION.awsapps.com on 993 SSL with your mailbox password. It is the identical credential a mail client uses to sign in.

Then move to a new provider. Pick a destination, set up the new mailbox, then copy everything across while WorkMail is still live.

Taking your mail to a new account? The Univik Email Migration Tool copies every folder from the old account to the new one. Enter the IMAP settings from this page for the Amazon WorkMail side and your new provider's settings for the other.

Rather not do it yourself? Our Email Migration Services team plans and runs the whole transfer for you and verifies every folder arrived.

Use These Settings in Univik Email Backup#

The same IMAP settings above let you download your whole WorkMail mailbox to your computer. Univik Email Backup writes everything to PST, MBOX, EML or PDF files you keep for good, which matters ahead of the 2027 shutdown.

  1. Download Univik Email Backup and install it on Windows.
  2. Select Amazon WorkMail from the source list. If it isn't listed by name, choose IMAP.
  3. Sign in with your full WorkMail address and your mailbox password. WorkMail uses no separate app password.
  4. If the tool asks for server details, use imap.mail.us-east-1.awsapps.com with port 993 and SSL from the IMAP table above.
  5. Pick a saving format and folder, then start the backup. Large mailboxes download in the background.
Why back up before the shutdown: once March 2027 passes, the endpoints go dark and the mail is gone. A full IMAP backup pulls every folder, attachment and date into files that any mail app reads later. Moving to a new account? The email migration tool copies mail account to account while WorkMail is still up.

Email Settings Glossary#

IMAP

Internet Message Access Protocol. Reads mail that stays on the server, so all your devices see the same inbox, folders and read status.

POP3

Post Office Protocol version 3. Downloads mail to 1 device and can remove it from the server. Older method, still useful for local archives.

SMTP

Simple Mail Transfer Protocol. Sends your outgoing mail. Every account needs it next to IMAP or POP3, which only receive.

SSL / TLS / STARTTLS

Encryption for the connection. SSL/TLS encrypts from the start (ports 993, 995, 465). STARTTLS upgrades a plain connection (port 587).

AWS Region

The AWS location your mailbox lives in, such as us-east-1 or eu-west-1. WorkMail server hosts carry the region in their name, so it must match your account.

AutoDiscover

A WorkMail feature that configures Outlook and mobile clients from your address and password alone, filling in the region host and settings for you.

How We Verify These Settings#

Since 2013 Univik has built email backup, migration and converter software. These tools open IMAP and SMTP sessions on the WorkMail region servers, so a changed host, port or login rule surfaces in our own logs before most guides catch it.

Every value on this page is confirmed with 3 checks: a live IMAP and SMTP connection from Univik Email Backup, a comparison against the AWS WorkMail documentation, which lists the region hosts and the March 2027 end of support. A provider notice prompts a recheck. We look again each quarter regardless.

Found something that no longer matches what Amazon WorkMail shows you? Tell us and we will retest and update the page, with the change logged in what changed recently.

 Help & Support

Frequently Asked Questions

Use imap.mail.us-east-1.awsapps.com on port 993 with SSL and your full WorkMail address. Swap us-east-1 for your AWS region. The password is your WorkMail mailbox password. The full table is under IMAP settings.

On WorkMail the usual cause is the region. The host carries your AWS region, so a mailbox in eu-west-1 will not sign in on a us-east-1 host. Confirm the region in the region endpoint section and re-enter your mailbox password.

No. WorkMail offers IMAP only, with no POP server at all. Set your client to IMAP on imap.mail.REGION.awsapps.com port 993 SSL. For a local copy, take a backup rather than looking for POP.

Yes. The region host, port 993 and SSL are identical on every device, as long as the region matches. The wording in each app is the only thing that shifts. The client setup guides cover each one.

No. WorkMail uses basic authentication, so you sign in with your ordinary WorkMail mailbox password. There is no separate app password to generate. If sign in fails, the usual cause is a wrong region in the host.

Yes. Use the SSL ports on this page, 993 for IMAP and 465 for SMTP, with your mailbox password. The link is then protected. Bear in mind AWS retires WorkMail on March 31 2027, so plan a move before then.

An IMAP client pulls mail down as it syncs, yet a dedicated backup tool is quicker and saves standalone files you can open anywhere. See how to back up your WorkMail mailbox. This matters ahead of the 2027 shutdown. Already hold files in another format? An email converter recasts them as PST, PDF or the format your next app needs.

Yes. AWS has announced that Amazon WorkMail support ends on March 31 2027. After that the console, web client and the IMAP and SMTP endpoints all shut down. See what changed recently and plan a backup and migration before the date.

An email migration tool copies mail directly between the two mailboxes over IMAP. You need the WorkMail region IMAP settings with your mailbox password for this side, plus the destination details. Do it before March 2027, since the endpoints close then. Every folder and date stays intact.

If setting this up feels risky or you have many accounts to move, our managed email migration service does the entire job for you.

Other Email Provider Settings

Summary: Amazon WorkMail Settings at a Glance

  • IMAP: imap.mail.us-east-1.awsapps.com, port 993, SSL/TLS
  • SMTP: smtp.mail.REGION.awsapps.com, port 465, SSL
  • Username is always your full email address
  • Hosts are region specific awsapps.com
  • IMAP only, there is no POP
  • SMTP is 465 SSL, no STARTTLS
  • Support ends March 31 2027