Email Settings Email Settings Guide

Google Workspace Email Settings: IMAP, SMTP and App Password

A Google Workspace mailbox uses the Gmail servers, even on your own company domain. The values below work in Outlook, Apple Mail, Thunderbird and your phone. Two things differ from personal Gmail: your admin can allow or block access. Basic passwords no longer work. Copy each value with 1 tap.

Tested July 25, 2026 1 Tap Copy Admin Managed

Workspace Quick Settings

IMAP Server imap.gmail.com
IMAP Port 993 (SSL/TLS)
SMTP Server smtp.gmail.com
SMTP Port 465 (SSL) / 587 (STARTTLS)
POP3 Server pop.gmail.com
Username Your full email address

Quick answer: a Google Workspace address uses the same servers as Gmail, not your company domain. Incoming is imap.gmail.com on port 993 (or POP pop.gmail.com on 995), outgoing is smtp.gmail.com on port 587, all with SSL/TLS. The username is your full Workspace address like you@yourcompany.com. Sign in with Sign in with Google (OAuth) or an app password, since Google stopped accepting plain passwords in 2025. If nothing connects, your admin may have blocked IMAP.

These values are checked with live connections, not copied from old guides, using Univik email software that authenticates to Workspace mailboxes over OAuth the way a modern client does. See what changed →

What Changed Recently#

Email providers change login rules more often than server addresses. Workspace server addresses have not changed in years. How you sign in changed completely. Here is where Google Workspace email access stands in 2026.

Google plain-password shutdown timeline June 2024 Late 2024 May 1, 2025 Now admin toggle removed password-only starts failing final cutoff OAuth or app password
Plain passwords are gone. Modern clients use OAuth automatically.

Latest update

Plain passwords stopped working, final cutoff May 1, 2025. Google finished turning off basic authentication, its "less secure apps" access, for Workspace. A mail app that signs in with just your Workspace password can no longer connect over IMAP, POP or SMTP. You now use Sign in with Google (OAuth) or an app password. This is the single biggest reason a Workspace account that worked for years suddenly stopped.

Earlier change

The IMAP on and off switch is gone. Google removed the per-user IMAP toggle from Gmail settings. IMAP is now always on over OAuth, so there is nothing to enable in your own settings. What remains is the org-level control your admin holds, which can still block POP and IMAP for everyone.

Earlier change

App passwords need 2-Step Verification. You cannot generate an app password until 2-Step Verification is on for your account. Your admin can also switch app passwords off entirely. Where they are blocked, OAuth is the only route, which every modern client supports.

Current status: Use OAuth wherever the client offers Sign in with Google. Where it does not, turn on 2-Step Verification and use an app password. Plain passwords are finished.

Before You Begin#

Two things decide whether a Workspace account connects. Both can sit outside your control. Check them before you touch a server field.

1. Your admin must allow IMAP or POP

The user IMAP switch is gone, but an admin can still block POP and IMAP for the whole organization. If yours has, no client will connect and the fix is a request to your admin, not a settings change.

Where: What your admin controls →

2. Set up an authentication method

Your Workspace password alone no longer works in email apps. The cleaner option is Sign in with Google, which most modern clients offer. The fallback is to turn on 2-Step Verification and generate an app password.

Where: OAuth and app password steps below →

About Google Workspace Email#

Google Workspace is Google's paid business suite that runs Gmail on your own company domain, used by millions of organizations worldwide.

Formerly G Suite and Google Apps, Workspace is Gmail with a business wrapper: your address ends in your company domain, but the mailbox itself sits on Google's servers. Two things set it apart from a personal Gmail account when you connect an email app. Your organization's administrator can allow or block access. Since 2025 a plain password no longer signs you in, so you use OAuth or an app password.

Service NameGoogle Workspace (formerly G Suite)
Owned ByGoogle
Mail EngineGmail, on your custom domain
Email DomainYour company domain, for example you@yourcompany.com
Webmailmail.google.com
ServersGmail (imap.gmail.com, smtp.gmail.com, pop.gmail.com)
Sign-InOAuth (Sign in with Google) or an app password with 2-Step Verification
StorageBy plan, from 30 GB per user on Business Starter up to 5 TB and beyond
The custom domain trips people up: your address ends in your company name, so it feels like the server should too. It does not. Every Workspace mailbox uses imap.gmail.com and smtp.gmail.com. Your domain changes only the username, never the server.
Workspace custom domain uses the Gmail servers Your username you@yourcompany.com your custom domain Your servers imap.gmail.com : 993 smtp.gmail.com : 587 never imap.yourcompany.com
Your domain lives in the username. The servers are always Gmail's.

Google Workspace Webmail Login#

Workspace mail opens in the Gmail interface at your company domain. The official pages are:

Webmail

mail.google.com

Account Security

admin.google.com (admins)

Reset Password

accounts.google.com

Watch out for fake support pages. Many pages ranking for email settings show a phone number and ask you to call for "expert setup help". A Workspace password reset often runs through your own admin, not a public support line. Neither Google nor Univik asks you to call a number to fix email settings. A message demanding that, with a link and a deadline, is a phishing attempt aimed at your work login.

What Your Admin Controls#

This is the part that makes Workspace different from a personal Gmail account. Some things are yours to set. Others belong to whoever runs your organization. When a setup fails for no visible reason, the cause is often on the admin side, so the fix is a short request rather than more troubleshooting.

Who controls what in Google Workspace email You control Your admin controls Turning on 2-Step Verification Generating your app passwords Choosing OAuth in your client Signature, filters, vacation Allowing POP and IMAP Permitting app passwords Approving connecting apps Location and device rules If the left is done and it still fails, ask the right
When every value is correct and it still will not connect, the block is usually on the admin side.
Admin controlWhere it lives in the Admin console
POP and IMAP access for the organizationApps → Google Workspace → Gmail → End User Access
Whether users can create app passwordsSecurity → Authentication → 2-Step Verification
Which third-party apps may connect over OAuthSecurity → Access and data control → API controls → App access control
Location and device restrictionsSecurity → Access and data control → Context-Aware Access

You do not need admin rights to read this. If a setup fails and every value matches this page, send your admin the first row: ask whether POP and IMAP are allowed for your account. That one question resolves most Workspace connection failures.

Google Workspace IMAP Settings#

IMAP is the right incoming choice for a Workspace mailbox read on more than one device. It keeps everything on Google's server so every device matches. Note the server is Gmail's. The username is your full Workspace address:

IMAP Serverimap.gmail.com (not imap.yourcompany.com)
Port993
EncryptionSSL/TLS (required)
UsernameYour full Workspace address, for example you@yourcompany.com
PasswordOAuth or an app password, never your plain password
AuthenticationRequired

Google Workspace POP3 Settings#

POP3 downloads mail to one device, useful for a single-computer setup or a local copy. Your admin must allow POP for it to work at all. Not sure which to pick? See the comparison below.

POP3 Serverpop.gmail.com
Port995
EncryptionSSL/TLS (required)
UsernameYour full Workspace address
PasswordOAuth or an app password
Careful with POP3 delete settings. Some clients pull mail off the server after download, so tick "leave a copy on the server" if you still want it in Gmail webmail. For a copy that outlives an offboarded account, a real backup beats POP.

Google Workspace SMTP Settings#

Two outgoing options: most people use smtp.gmail.com on 587 with STARTTLS. Port 465 with SSL works too. Admins sending from printers, scanners or bulk apps can instead use smtp-relay.gmail.com, which allows higher volume with IP allowlisting set in the Admin console. Both require encryption.

SMTP handles outgoing mail. If you can read but not send, the outgoing server or the sign-in method is the suspect:

SMTP Serversmtp.gmail.com (bulk: smtp-relay.gmail.com)
Port (STARTTLS)587
Port (SSL)465
EncryptionSTARTTLS or SSL (required)
UsernameYour full Workspace address
PasswordThe same OAuth or app password as incoming
AuthenticationRequired. Tick "My outgoing server requires authentication" and reuse the incoming login. This is the top reason mail receives but will not send.

Check Google Workspace IMAP Settings Online#

You don't need to download anything to check Google Workspace IMAP settings online. This page is the lookup, with every value verified and copyable. Because Workspace runs on a custom domain, a lookup by domain name cannot always tell it apart from other hosts, so the surest test is a real sign-in. Type your address for a quick check:

Does my email address use these settings?

Runs in your browser only. Your address is never sent anywhere or stored.

Want to verify the account itself before configuring an app? Sign in at mail.google.com with your Workspace address. A working webmail login proves the account is fine, so any failure in a mail app points to the sign-in method or an admin block, not your password.

Look Up IMAP Settings for Any Email Domain#

This page covers Google Workspace. For any other address, including a work domain on a different host, our free lookup database imapsettings.com returns the incoming and outgoing servers for any domain in one step.

imapsettings.com

Complete email settings database, by Univik

Check IMAP settings online →

Enter any email address and get the incoming and outgoing server settings for that domain in 1 step:

Incoming server: hostname, port, SSL/TLS and username format
Outgoing server: SMTP hostname, port and encryption

Your address is used only to find the settings for that domain. Nothing is stored or shared.

Workspace Sign-In: OAuth or App Password#

Since plain passwords stopped working, there are two ways in. OAuth, shown as Sign in with Google, is the cleaner one and every modern client supports it. An app password is the fallback for clients that have no Google sign-in button. Here is which method works where:

OAuth or app password decision Sign in with Google button? Yes No Use OAuth nothing to type Turn on 2-Step, make an app password
OAuth first. App passwords only for devices without a Google sign-in button.
Where you sign inSign in with Google (OAuth)App password
mail.google.com and the Gmail app✓ Built in✗ Not needed
Modern Outlook, Apple Mail, Thunderbird✓ Best optionFallback
Older clients, printers, scanners✗ No button✓ Required
Any plain-password setup✗ Gone since 2025✗ Gone since 2025

How to Generate a Workspace App Password

  1. Turn on 2-Step Verification at myaccount.google.com → Security. Without it, app passwords do not appear at all.
  2. Open App passwords on the same Security page, which you can also reach by searching "App passwords" in your Google Account. If it is missing, your admin has switched it off.
  3. Type a name such as "Outlook laptop" or "office scanner" and select Create.
  4. Copy the 16 character code Google shows once, then close the window.
  5. Paste it as the password in your email app, in both the incoming and outgoing sections. Spaces do not matter.
Prefer OAuth where you can: an app password gives a client full mailbox access and shows only once. OAuth is safer, since your admin can review and revoke a connected app centrally. Use app passwords mainly for devices with no Sign in with Google button. Delete any you no longer use.

Set Up Google Workspace in Email Clients#

Wherever the client shows a Sign in with Google button, use it and skip the server typing entirely. The manual values below are for clients without it. Jump to your app:

Outlook (Windows and Mac)

  1. Open Outlook → File → Add Account and type your Workspace address. New Outlook and Outlook 2016 or later open a Google sign-in window, which is the easy path.
  2. If it asks for servers, choose IMAP and enter imap.gmail.com port 993 (SSL) and smtp.gmail.com port 587 (STARTTLS).
  3. When prompted for a password, complete the Google sign-in. Paste an app password only if no Google window appears.
  4. Open More Settings → Outgoing Server and tick "My outgoing server requires authentication" with the same login.
  5. Finish and send yourself a test to confirm both directions work.

Apple Mail (macOS)

  1. Open Mail → Settings → Accounts → Add Account and select Google. This runs OAuth and needs no server typing.
  2. Sign in with your Workspace address in the Google window that opens.
  3. If you must add it as Other Mail Account, enter imap.gmail.com and smtp.gmail.com with an app password.
  4. Use your full Workspace address as the username on both servers, port 993 in and 587 out, SSL on.
  5. Enable Mail and finish.

iPhone and iPad

  1. Open Settings → Apps → Mail → Mail Accounts → Add Account → Google. Sign in through the Google window, the cleanest route on a phone.
  2. For manual setup instead, tap Other → Add Mail Account and enter your name, Workspace address and an app password.
  3. Keep IMAP selected and enter imap.gmail.com incoming and smtp.gmail.com outgoing.
  4. Use your full Workspace address as the username in both host fields, even where iOS marks the outgoing one optional.
  5. Tap Save and wait for iOS to verify.

Android

  1. Open your mail app (Gmail app, Samsung Email or another) → Add account → Google, which runs OAuth. On the Gmail app a Workspace account just signs in.
  2. For manual setup, choose Other, enter your Workspace address and an app password, then pick IMAP.
  3. Enter the servers: imap.gmail.com 993 SSL incoming, smtp.gmail.com 587 STARTTLS outgoing.
  4. Use your full Workspace address as the username on both.
  5. Finish setup and pull down to sync your inbox.

Thunderbird

  1. Open Thunderbird → Account Settings → Account Actions → Add Mail Account.
  2. Enter your name and Workspace address, then select Continue. Thunderbird detects Gmail and offers OAuth, so leave the password blank and let it open the Google window.
  3. Confirm IMAP is selected with imap.gmail.com incoming and smtp.gmail.com outgoing.
  4. Complete the Google sign-in that pops up. Use an app password only if OAuth is unavailable.
  5. Select Done. Folders sync on first open.

Google Workspace Webmail Settings#

Server settings connect your apps. These control how the mailbox behaves and live in Gmail under the gear icon → See all settings. Some may be locked by your admin.

Signature

See all settings → General → Signature. A signature set here shows in Gmail webmail only. Outlook and phone apps keep their own.

Vacation Auto Reply

See all settings → General → Vacation responder. Set start and end dates so it turns off by itself. Google sends it from the server, so it runs with your computer off. An admin can limit replies to inside your organization.

Filters and Folders

See all settings → Filters and Blocked Addresses. Filters made here run on Google's server, so mail is sorted before any device syncs. A rule built inside a desktop client only fires while that app is open.

Spam and Blocked Senders

Open a message → three dots → Block sender. Filters can also skip the inbox before it arrives. Blocked senders go to Spam. Your admin may also run organization-wide spam and compliance rules above your own.

Workspace POP3 vs IMAP#

The usual trade-off applies, against Google's server, with the reminder that POP needs admin approval.

IMAP syncs every device, POP3 downloads to one IMAP: everything in sync POP3: one device only Google server Phone Computer Webmail Read once, read everywhere Google server 1 computer Phone and webmail see nothing new
IMAP suits anyone with more than one device. POP also needs your admin to allow it.
FeatureIMAPPOP3
Where mail livesOn Google's serverDownloaded to 1 device
Multiple devices✅ Everything stays in sync❌ Each device sees different mail
Sent and deleted mail✅ Synced everywhere⚠️ Stays only on that device
Offline reading⚠️ Cached mail only✅ Full local copy
Server storage usedYes, counts against your quotaCan be freed after download
Best forPhone + computer, everyday useSingle PC, local archives
Our verdict: IMAP for daily use across devices. For a permanent copy of a Workspace mailbox, especially before an employee leaves, a backup tool keeps every folder and label in files, which POP3 cannot.

Google Workspace Sending and Storage Limits#

Workspace limits are higher than personal Gmail, but hitting one still pauses sending for up to 24 hours. The numbers that matter:

Emails per day via smtp.gmail.com2,000 for Workspace, 500 on trial accounts
Higher volume via smtp-relay.gmail.comUp to roughly 10,000 messages per day per domain
Attachment size limit25 MB to send, up to 50 MB to receive, larger via Drive links
Mailbox storageBy plan, from 30 GB per user up to 5 TB and more
What happens at the limitSending is paused for up to 24 hours, then resumes on its own

Troubleshooting Google Workspace Connections#

Find the exact error your email app shows, then apply the fix:

Error you seeWhat it meansFix
Username or password incorrect (worked for years) The client is using your plain password, which Google stopped accepting in 2025 Switch to Sign in with Google. If the client lacks it, turn on 2-Step Verification and use an app password.
IMAP access is disabled for your account Your admin has blocked POP and IMAP for the organization Ask your admin to allow it under Apps → Google Workspace → Gmail → End User Access. You cannot change this yourself.
App passwords option is missing 2-Step Verification is off or your admin disabled app passwords Turn on 2-Step Verification first. If it is still missing, your admin has switched app passwords off, so use OAuth.
Cannot connect using imap.yourcompany.com Wrong server, the custom domain is not the mail host Use imap.gmail.com. Workspace always uses the Gmail servers, whatever your domain is.
Messages stuck in Outbox SMTP authentication is off or the app never completed OAuth Use smtp.gmail.com on 587, tick outgoing authentication and finish the Google sign-in.

Reader Reported Fixes

Two fixes that come up repeatedly in real Workspace support threads, beyond the error table above.

Re-add the account to trigger the Google sign-in window. An old profile set up with a plain password will not switch to OAuth on its own. Remove the Workspace account from the client, then add it fresh so the client offers Sign in with Google, which is the smoothest fix after the 2025 change.

Ask your admin to check App access control for a blocked client. If OAuth completes but the app still cannot read mail, an admin may have set that third-party app to blocked under Security → API controls. They can move it to trusted, which clears the connection without any change on your side.

Moving To or From Google Workspace?#

Moving into Workspace from Microsoft 365, an old host or another Gmail account? Admins can run Google's built-in Data Migration Service from the Admin console, which pulls mail over IMAP into your new mailboxes without touching each device.

Setting up a single mailbox by hand instead? Use the IMAP settings on this page for the Workspace side and the old provider's for the other. Our email settings index has the servers for most providers.

Offboarding an employee? This is the one that bites teams. Once a Workspace account is deleted, its mail is gone unless it was exported first. Back the mailbox up or transfer it before you remove the license.

Leaving Workspace for another provider? The Univik Email Migration Tool copies every folder and label over IMAP into the new account. Use the Gmail settings from this page for the Workspace side.

Rather not do it yourself? Our Email Migration Services team plans and runs the whole transfer and verifies every folder arrived.

Use These Settings in Univik Email Backup#

The IMAP settings above let you download a complete Workspace mailbox to your computer. Univik Email Backup saves everything as PST, MBOX, EML or PDF files you keep, which matters most when a licensed account is about to be deleted.

  1. Download Univik Email Backup and install it on Windows.
  2. Choose Google Workspace or IMAP as the source and, where offered, sign in with Google over OAuth.
  3. For manual IMAP, enter imap.gmail.com on port 993 with SSL and use an app password.
  4. Sign in with the full Workspace address and include every folder and label so nothing is left behind.
  5. Pick PST, MBOX, EML or PDF and a folder, then start. Large mailboxes download in the background.
Why this matters for admins: deleting a Workspace license removes the mailbox with it, so plan ahead. Google Vault is a legal-hold tool, not a portable backup. A full export keeps every folder, label and date stamp in files any email app opens later. Moving the mail to another live account instead? The email migration tool copies it directly.

Email Settings Glossary#

IMAP

Internet Message Access Protocol, imap.gmail.com on port 993. Mail stays on Google's server so every device shows the same inbox, folders and read status.

POP3

Post Office Protocol version 3, pop.gmail.com on port 995. Downloads mail to one device. Your admin must allow POP for it to work.

SMTP

Simple Mail Transfer Protocol, the sending half. Workspace uses smtp.gmail.com on 587 or 465. For higher-volume admin sending there is smtp-relay.gmail.com.

SSL / TLS / STARTTLS

Encryption for the connection. SSL/TLS covers ports 993, 995 and 465. STARTTLS upgrades a plain connection on 587. Google requires encryption on all of them.

App Password

A 16 character code that stands in for your password inside an app. Workspace needs one only where OAuth is not offered. It also requires 2-Step Verification to exist.

OAuth

Sign in with Google, the secure method Workspace now requires. The app opens a Google window instead of taking a typed password. Your admin can review or revoke the connection.

How We Verify These Settings#

Univik has built email backup, migration and converter software since 2013. Workspace is one of the most common mailboxes our tools connect to over OAuth. When Google finished turning off plain-password access, our connection logs showed exactly which sign-in methods still worked, which is why this page leads with OAuth rather than the app-password steps many guides still put first.

Every value here is confirmed with three checks: a live IMAP and SMTP connection from Univik Email Backup, a comparison with Google's own Workspace documentation and a real sign-in using both OAuth and an app password. We re-check after any Google announcement and at least once a quarter.

Found a value that no longer matches what Google shows you? Tell us and we will retest and update the page, with the change logged in what changed recently.

 Help & Support

Frequently Asked Questions

Use imap.gmail.com on port 993 with SSL, the same server as Gmail, with your full Workspace address as the username. Sign in with OAuth or an app password, not a plain password. The complete table is in the IMAP settings section.

Google finished turning off plain-password access for Workspace on May 1, 2025. The password is right, the method is not accepted anymore. Switch the client to Sign in with Google. If it has no such button, turn on 2-Step Verification and use an app password.

IMAP for almost everyone, since it syncs your phone, computer and webmail. POP3 suits a single-computer download and needs your admin to allow POP. For a lasting copy of the mailbox, a backup beats both. Full comparison here.

Yes. Servers, ports and encryption never change between devices. Only the menus differ, which is what the client setup guides cover.

Always imap.gmail.com, never imap.yourcompany.com. Workspace runs on Google's servers no matter what your email domain is. Your domain only appears in the username, like you@yourcompany.com. This mix-up is the most common Workspace setup mistake.

OAuth, where the client offers Sign in with Google. It never exposes a reusable credential. Your admin can review or revoke the connection centrally. Keep app passwords for devices with no Google sign-in button. Delete any you stop using.

Export it to files before you remove the license, because deleting the account deletes the mail. A backup tool saves every folder and label as PST, MBOX, EML or PDF. Google Vault holds data for compliance but is not a portable backup. Already have exported files? An email converter turns them into your target format.

Two Workspace-specific causes stand out: Google turned off plain passwords in 2025. Your admin can also block IMAP or a connecting app at any time. Check what changed recently and the admin controls, then switch to OAuth if you have not already.

Admins can use Google's Data Migration Service to pull mail into Workspace over IMAP. To move mail out, an email migration tool copies it between accounts using the Gmail settings for the Workspace side. Every folder and label stays intact.

With many mailboxes to move, our managed email migration service can run the whole project for you.

Other Email Provider Settings

Summary: Google Workspace Settings at a Glance

  • IMAP: imap.gmail.com, port 993, SSL
  • POP3: pop.gmail.com, port 995, SSL
  • SMTP: smtp.gmail.com, port 587 or 465
  • Servers are Gmail's, not your company domain
  • Sign in with OAuth or an app password, never a plain password
  • App passwords need 2-Step Verification on
  • Your admin can block IMAP, POP or a connecting app
  • Sending: 2,000 a day, more via smtp-relay.gmail.com