Quick answer: the Amazon WorkMail IMAP server is imap.mail.us-east-1.awsapps.com on port 993 with SSL. The SMTP server is smtp.mail.us-east-1.awsapps.com on port 465 with SSL. Swap us-east-1 for your AWS region, such as us-west-2 or eu-west-1. WorkMail has no POP and no STARTTLS. Sign in with your full WorkMail address and your WorkMail password.
What Changed Recently#
The biggest news for Amazon WorkMail is its retirement. Here is what that means, alongside how the servers work today.
Latest update
AWS is ending Amazon WorkMail on March 31 2027. The service stopped taking new customers on April 30 2026. Existing accounts run until March 31 2027, after which the console, web client and the IMAP and SMTP endpoints all shut down for good. Plan a move and a backup well ahead of the deadline.
Earlier change
Servers are tied to your AWS region. The host reads imap.mail.REGION.awsapps.com, where REGION is where your WorkMail organization lives. A host from the wrong region does not connect.
Earlier change
IMAP only, no POP. WorkMail retrieves mail over IMAP alone. There is no POP server. Outgoing SMTP runs on port 465 with SSL and does not offer STARTTLS.
Before You Begin#
Two things decide whether WorkMail connects on the first try. Get them right and the tables below do the rest.
1. Know your AWS region
Every WorkMail host contains your region. The wrong region means no connection, whatever else you type. Find it in the WorkMail console or your web client URL.
2. Use IMAP, not POP
WorkMail offers IMAP only. If your client defaults to POP, switch it to IMAP or the mailbox will not load.
Where: IMAP settings below →
About Amazon WorkMail#
Amazon WorkMail is the managed business email and calendar service from Amazon Web Services, built on AWS infrastructure with Outlook, mobile and IMAP client support.
WorkMail launched in 2016 as a managed alternative to running your own Exchange server. It works with a custom domain of your own and with Outlook over Exchange ActiveSync, mobile clients and any IMAP client. The detail that shapes every client setup is the region. Each mailbox lives in one AWS region. WorkMail lets you pick that region for data locality and encrypts your mail at rest with AWS KMS keys you control. The IMAP and SMTP hosts carry that region in their name. AWS has announced that WorkMail support ends on March 31 2027, so a backup and a migration plan matter more than usual here.
| Service Name | Amazon WorkMail |
| Owned By | Amazon Web Services |
| Launched | 2016 |
| Email Domains | Your own domain, plus the default @alias.awsapps.com |
| Webmail URL | https://alias.awsapps.com/mail |
| Protocols Supported | IMAP and SMTP. No POP |
| App Password Needed | No. Use your mailbox password |
| Support Ends | March 31 2027 |
Amazon WorkMail Webmail Login#
You can always read your mail in a browser. The official sign in pages are:
Webmail
Account Security
Password Recovery
Find Your Region Endpoint#
Every WorkMail host carries your AWS region, so the first job is knowing which region your organization sits in. WorkMail runs in three regions today:
- US East, N. Virginia uses
us-east-1, so the host is imap.mail.us-east-1.awsapps.com. - US West, Oregon uses
us-west-2, giving imap.mail.us-west-2.awsapps.com. - Europe, Ireland uses
eu-west-1, giving imap.mail.eu-west-1.awsapps.com. - Not sure which one? The region shows in the WorkMail console selector. It also appears in your web client URL at
https://alias.awsapps.com/mail.
imap.mail.REGION.awsapps.com and the SMTP host is smtp.mail.REGION.awsapps.com. A host from the wrong region returns an authentication or connection error even when the password is right.
you@yourdomain.com, not only the mailbox name before the @ sign. A bare username returns a 535 authentication error even when the password and region are correct.
Amazon WorkMail IMAP Settings#
IMAP is the only incoming protocol WorkMail offers. It holds mail on the AWS server so every device shows the same inbox. There is no POP option.
| IMAP Server | imap.mail.us-east-1.awsapps.com | |
| Port | 993 | |
| Encryption | SSL required | |
| Username | Your full address, such as you@yourdomain.com, not only the mailbox name | |
| Password | Your WorkMail mailbox password | |
| Region | Swap us-east-1 for us-west-2 or eu-west-1 as needed | |
| Authentication | Required |
Amazon WorkMail SMTP Settings#
SMTP handles outgoing mail. If mail arrives but will not send, look here.
| SMTP Server | smtp.mail.us-east-1.awsapps.com | |
| Port | 465 | |
| Encryption | SSL required. No STARTTLS | |
| Username | Your full WorkMail email address | |
| Password | The same mailbox password used for IMAP | |
| Region | Use smtp.mail.us-west-2.awsapps.com and the like to match your region | |
| Authentication | Required. Tick outgoing server requires authentication in your client |
Check Amazon WorkMail IMAP Settings Online#
You don't need to download anything to check Amazon WorkMail IMAP settings online. This page is the lookup: every value is verified, current and copyable straight from your browser. Not sure your address uses Amazon WorkMail servers? Type it below and find out instantly.
Does my email address use these settings?
Runs in your browser only. Your address is never sent anywhere or stored.
Want to verify the mailbox before setting up a client? Sign in at your WorkMail web client, which confirms the address and password work and shows your region in the URL. With the region and password in hand, any IMAP client connects using the tables above.
Look Up IMAP Settings for Any Email Domain#
This page covers Amazon WorkMail. For every other address, work email on a company domain included, we run a free online lookup database: imapsettings.com.
imapsettings.com
Complete email settings database, by Univik
Enter any email address and get the incoming and outgoing server settings for that domain in 1 step:
Your address is used only to find the settings for that domain. Nothing is stored or shared.
Set Up Amazon WorkMail in Email Clients#
The region hosts and ports are identical in every app. What differs is where each app hides its menus. Pick yours:
Outlook (Windows and Mac)
- Open Outlook and choose File, then Add Account. In the new Outlook this sits under Settings and Accounts.
- Type your WorkMail address, expand Advanced options and pick let me set up my account manually. AutoDiscover often fills the rest from your address alone.
- Select IMAP, then
imap.mail.us-east-1.awsapps.comon993SSL andsmtp.mail.us-east-1.awsapps.comon465SSL. Swap in your own region. - Enter your WorkMail mailbox password at the prompt. WorkMail has no separate app password.
- Finish and send a test email to yourself to confirm both directions work.
Apple Mail (macOS)
- Open Mail → Settings → Accounts → Add Account.
- WorkMail will not appear in the list, so pick Other Mail Account.
- Give your name, full address and mailbox password, then continue.
- If asked for servers, enter the IMAP and SMTP values from the tables above.
- Enable Mail in the checkbox list and finish.
iPhone and iPad
- Open Settings → Apps → Mail → Mail Accounts → Add Account.
- Tap Other, then Add Mail Account. iOS lists no WorkMail option.
- Fill your details with the mailbox password, then tap Next.
- Keep IMAP selected and fill the incoming and outgoing servers if iOS asks.
- Tap Save and wait for iOS to verify the account.
Android
- Open your mail app (Gmail app, Samsung Email or another) → Add account.
- Choose Other (IMAP) when your provider is not in the list.
- Enter your address and mailbox password. If auto setup does not take, pick Manual setup.
- Add the servers:
imap.mail.us-east-1.awsapps.com993 SSL incoming,smtp.mail.us-east-1.awsapps.com465 SSL outgoing, with your region. - Finish setup and pull down to sync your inbox.
Thunderbird
- Open Thunderbird → Account Settings → Account Actions → Add Mail Account.
- Type your name, address and mailbox password, then choose Continue.
- Let Thunderbird probe the servers, then confirm it chose IMAP over SSL for your region.
- If detection fails, choose Configure manually and enter the table values above.
- Select Done. Folders sync on first open.
Amazon WorkMail Webmail Settings#
Those values wire up a client. The options here govern how the mailbox behaves. You change them in the WorkMail web client under Settings.
Signature
Set in the WorkMail web client. A signature saved there rides on browser sent mail. Each client keeps its own, so the one a reader sees depends on where the message left from.
Vacation Auto Reply
WorkMail calls this the Out of Office Assistant. Give it a start and end date and it closes itself. The server sends it, so it answers while your devices are off.
Filters and Folders
A rule built in the web client runs server side, sorting mail before any device fetches it. A rule kept inside Outlook runs only while Outlook is open, which is why two apps can sort one message in different ways.
Spam and Blocked Senders
Add a sender or a whole domain to the block list in the web client. If a message goes missing, check the web client spam folder first, since a client rule cannot undo what the server already did.
Why WorkMail Uses IMAP Only#
| Feature | IMAP, what WorkMail uses | A local backup file |
|---|---|---|
| Where mail lives | On the WorkMail server, in sync | Saved on your own disk |
| Multiple devices | ✅ Everything stays in sync | ⚠️ A snapshot, not live |
| Survives the 2027 shutdown | ❌ Endpoint goes away | ✅ Yours to keep |
| Offline reading | ⚠️ Cached mail only | ✅ Full local copy |
| Server storage used | Yes, counts against your quota | None, it lives on your disk |
| Best for | Phone and computer, everyday use | Keeping mail past the shutdown |
Amazon WorkMail Settings Worth Knowing#
These are the connection points that decide an Amazon WorkMail client setup:
| Incoming server | imap.mail.REGION.awsapps.com 993, SSL |
| Outgoing server | smtp.mail.REGION.awsapps.com 465, SSL, no STARTTLS |
| Regions | us-east-1, us-west-2, eu-west-1 |
| Password | Your WorkMail mailbox password, no app password |
| POP support | None. IMAP only |
| Support ends | March 31 2027 |
Troubleshooting Amazon WorkMail Connections#
Find the exact error your email app shows, then apply the fix:
| Error you see | What it means | Fix |
|---|---|---|
| Authentication failed, credentials invalid | Host is from the wrong AWS region | Match the host to your region in the region endpoint section, such as eu-west-1 for Ireland. |
| Client cannot find a POP server | WorkMail has no POP | Set the account type to IMAP and use imap.mail.REGION.awsapps.com on 993 SSL. |
| Cannot connect to server | Wrong port or encryption | Confirm IMAP on 993 SSL and SMTP on 465 SSL. WorkMail has no 587, so SSL on 465 is the only outgoing option. A firewall or VPN can block these too. |
| Password keeps being asked | Wrong region host or a typo in the address | Confirm the region in the host and re-enter your WorkMail mailbox password. |
| Messages stuck in Outbox | SMTP authentication is off | Switch on outgoing server requires authentication and reuse the incoming login. |
Reader Reported Fixes
A US client kept failing until the region matched. The mailbox lived in eu-west-1 but the client used the us-east-1 host. Because the host carries the region, the login was refused. Switching both hosts to eu-west-1 connected it at once.
An old client defaulted to POP and would not load mail. WorkMail serves no POP, so the client sat waiting on a host that never answers for POP. Changing the account type to IMAP on 993 SSL fixed it.
Moving Off WorkMail Before March 2027#
The clock is real. AWS shuts WorkMail down on March 31 2027. After that the IMAP and SMTP endpoints, the web client and the console all stop. Anything not moved by then is lost.
Back up first, using the same region host. A backup connects over imap.mail.REGION.awsapps.com on 993 SSL with your mailbox password. It is the identical credential a mail client uses to sign in.
Then move to a new provider. Pick a destination, set up the new mailbox, then copy everything across while WorkMail is still live.
Taking your mail to a new account? The Univik Email Migration Tool copies every folder from the old account to the new one. Enter the IMAP settings from this page for the Amazon WorkMail side and your new provider's settings for the other.
Rather not do it yourself? Our Email Migration Services team plans and runs the whole transfer for you and verifies every folder arrived.
Use These Settings in Univik Email Backup#
The same IMAP settings above let you download your whole WorkMail mailbox to your computer. Univik Email Backup writes everything to PST, MBOX, EML or PDF files you keep for good, which matters ahead of the 2027 shutdown.
- Download Univik Email Backup and install it on Windows.
- Select Amazon WorkMail from the source list. If it isn't listed by name, choose IMAP.
- Sign in with your full WorkMail address and your mailbox password. WorkMail uses no separate app password.
- If the tool asks for server details, use
imap.mail.us-east-1.awsapps.comwith port993and SSL from the IMAP table above. - Pick a saving format and folder, then start the backup. Large mailboxes download in the background.
Email Settings Glossary#
IMAP
Internet Message Access Protocol. Reads mail that stays on the server, so all your devices see the same inbox, folders and read status.
POP3
Post Office Protocol version 3. Downloads mail to 1 device and can remove it from the server. Older method, still useful for local archives.
SMTP
Simple Mail Transfer Protocol. Sends your outgoing mail. Every account needs it next to IMAP or POP3, which only receive.
SSL / TLS / STARTTLS
Encryption for the connection. SSL/TLS encrypts from the start (ports 993, 995, 465). STARTTLS upgrades a plain connection (port 587).
AWS Region
The AWS location your mailbox lives in, such as us-east-1 or eu-west-1. WorkMail server hosts carry the region in their name, so it must match your account.
AutoDiscover
A WorkMail feature that configures Outlook and mobile clients from your address and password alone, filling in the region host and settings for you.
How We Verify These Settings#
Since 2013 Univik has built email backup, migration and converter software. These tools open IMAP and SMTP sessions on the WorkMail region servers, so a changed host, port or login rule surfaces in our own logs before most guides catch it.
Every value on this page is confirmed with 3 checks: a live IMAP and SMTP connection from Univik Email Backup, a comparison against the AWS WorkMail documentation, which lists the region hosts and the March 2027 end of support. A provider notice prompts a recheck. We look again each quarter regardless.
Found something that no longer matches what Amazon WorkMail shows you? Tell us and we will retest and update the page, with the change logged in what changed recently.
Help & Support
Frequently Asked Questions
Use imap.mail.us-east-1.awsapps.com on port 993 with SSL and your full WorkMail address. Swap us-east-1 for your AWS region. The password is your WorkMail mailbox password. The full table is under IMAP settings.
On WorkMail the usual cause is the region. The host carries your AWS region, so a mailbox in eu-west-1 will not sign in on a us-east-1 host. Confirm the region in the region endpoint section and re-enter your mailbox password.
No. WorkMail offers IMAP only, with no POP server at all. Set your client to IMAP on imap.mail.REGION.awsapps.com port 993 SSL. For a local copy, take a backup rather than looking for POP.
Yes. The region host, port 993 and SSL are identical on every device, as long as the region matches. The wording in each app is the only thing that shifts. The client setup guides cover each one.
No. WorkMail uses basic authentication, so you sign in with your ordinary WorkMail mailbox password. There is no separate app password to generate. If sign in fails, the usual cause is a wrong region in the host.
Yes. Use the SSL ports on this page, 993 for IMAP and 465 for SMTP, with your mailbox password. The link is then protected. Bear in mind AWS retires WorkMail on March 31 2027, so plan a move before then.
An IMAP client pulls mail down as it syncs, yet a dedicated backup tool is quicker and saves standalone files you can open anywhere. See how to back up your WorkMail mailbox. This matters ahead of the 2027 shutdown. Already hold files in another format? An email converter recasts them as PST, PDF or the format your next app needs.
Yes. AWS has announced that Amazon WorkMail support ends on March 31 2027. After that the console, web client and the IMAP and SMTP endpoints all shut down. See what changed recently and plan a backup and migration before the date.
An email migration tool copies mail directly between the two mailboxes over IMAP. You need the WorkMail region IMAP settings with your mailbox password for this side, plus the destination details. Do it before March 2027, since the endpoints close then. Every folder and date stays intact.
If setting this up feels risky or you have many accounts to move, our managed email migration service does the entire job for you.
Other Email Provider Settings
Summary: Amazon WorkMail Settings at a Glance
- IMAP: imap.mail.us-east-1.awsapps.com, port 993, SSL/TLS
- SMTP: smtp.mail.REGION.awsapps.com, port 465, SSL
- Username is always your full email address
- Hosts are region specific awsapps.com
- IMAP only, there is no POP
- SMTP is 465 SSL, no STARTTLS
- Support ends March 31 2027