Quick answer: the Hushmail IMAP server is imap.hushmail.com on port 993 with SSL. The SMTP server is smtp.hushmail.com on port 465 SSL. Port 587 SSL works as a fallback. POP is pop.hushmail.com on 995 SSL. Sign in with your full address and your Hushmail password. If two-step verification is on, add the security code to the password as shown below.
What Changed Recently#
Hushmail keeps its servers steady. The parts worth knowing are the two-step password format and the way outgoing mail is encrypted.
Latest update
Two-step verification adds a code to your password. Once two-step is on, a mail app wants your password, then a space, then the security code from Preferences. Without two-step, your normal password signs you in.
Earlier change
Outgoing mail is not automatically encrypted. A message you send through a mail app goes out unencrypted unless the recipient is a Hushmail user or has a password set for encrypted mail. The copy saved in Sent stays encrypted.
Earlier change
SSL is required on every port. Hushmail refuses plain connections. Use SSL with 993 for IMAP, 995 for POP and 465 for SMTP, with 587 as an outgoing fallback.
imap.hushmail.com and smtp.hushmail.com over SSL, using your full address and your Hushmail password.
Before You Begin#
Two things decide whether Hushmail connects on the first try. Sort them and the rest is plain.
1. Handle two-step verification
With two-step on, a mail app needs your password followed by a space and the security code Hushmail assigns. Without two-step, your normal password is enough.
Where: How login works below
2. Turn SSL on for every port
Hushmail accepts encrypted connections only. The most common setup mistake is leaving SSL off, which makes 993, 995 and 465 all refuse the connection.
Where: Server tables below →
About Hushmail Mail#
Hushmail is a paid secure email service from a Canadian company that has offered encrypted email since 1999, popular with healthcare and legal users.
The detail that shapes client setup is two-step verification. With it off, your normal password works in any mail app. With it on, the password field takes your password, a space, then a security code Hushmail shows in Preferences. One more thing sets Hushmail apart. Mail you send from a third-party app is not encrypted by default, since the encryption happens through Hushmail own system rather than the mail app.
| Service Name | Hushmail Mail |
| Run By | Hush Communications (Canada) |
| Serving Since | 1999 |
| Email Domains | @hush.com @hushmail.me @hush.ai plus custom domains |
| Webmail URL | hushmail.com |
| Protocols Supported | IMAP, POP, SMTP |
| Two-Step Code Needed | Only when two-step is on |
| Cost | Paid secure email service |
@hush.com, @hush.ai, @hushmail.me, @mac.hush.com, @hushmail.com or your own custom domain uses the identical servers on this page. The domain only changes the username. It never changes the server.
Hushmail Webmail Login#
Reading your mail in a browser is the quickest way to tell a wrong password apart from a wrong server. The official pages are:
How Your Password Works#
Your Hushmail password is what mail clients take. Two-step verification is the one thing that changes how you type it.
- Two-step verification off. Use your normal Hushmail password in the mail app. Nothing extra is needed.
- Two-step verification on. The password field takes your password, then a single space, then the security code Hushmail assigns you.
- Find the security code in webmail under Preferences, on the Security tab. It is the IMAP and POP password Hushmail lists there.
- Type it as one string. For a password of
mypassand a code of1234abcd, entermypass 1234abcdwith the space in the middle. - Same code everywhere. The one security code covers IMAP, POP and SMTP, so every app on the account uses the same format.
Hushmail IMAP Settings#
IMAP is the incoming protocol to pick. It leaves your mail on Hushmail servers, so every device shows the same inbox.
| IMAP Server | imap.hushmail.com | |
| Port | 993 | |
| Encryption | SSL/TLS (required) | |
| Username | Your full Hushmail address, the whole thing after the at sign included | |
| Password | Your Hushmail password. With two-step on, add the security code | |
| Authentication | Required |
Hushmail POP3 Settings#
POP pulls mail down to one machine. Choose it only when you want a single local copy. Undecided? The comparison below lays it out.
| POP3 Server | pop.hushmail.com | |
| Port | 995 | |
| Encryption | SSL/TLS (required) | |
| Username | Your full email address | |
| Password | The same Hushmail password, plus the security code if two-step is on |
Hushmail SMTP Settings#
SMTP carries outgoing mail. If reading works but sending fails, this section is where to look.
| SMTP Server | smtp.hushmail.com | |
| Port (SSL) | 465 | |
| Port (STARTTLS) | 587 | |
| Encryption | SSL or STARTTLS (required) | |
| Username | Your full email address | |
| Password | Same as incoming mail | |
| Authentication | Required. Check "My outgoing server requires authentication" in Outlook. |
Check Hushmail IMAP Settings Online#
You don't need to download anything to check Hushmail IMAP settings online. This page is the lookup: every value is verified, current and copyable straight from your browser. Not sure your address uses Hushmail servers? Type it below and find out instantly.
Does my email address use these settings?
Runs in your browser only. Your address is never sent anywhere or stored.
Want to verify the account itself before configuring an app? Sign in at Hushmail webmail, which confirms your address and password work. If two-step is on, note the security code from Preferences. With both in hand, any email app connects using the tables above.
Look Up IMAP Settings for Any Email Domain#
This page covers Hushmail. For every other address, work email on a company domain included, we run a free online lookup database: imapsettings.com.
imapsettings.com
Complete email settings database, by Univik
Enter any email address and get the incoming and outgoing server settings for that domain in 1 step:
Your address is used only to find the settings for that domain. Nothing is stored or shared.
Set Up Hushmail in Email Clients#
Same servers, same ports, whichever app you use. Only the menus change. Pick yours:
Outlook (Windows and Mac)
- In Outlook open File, then Add Account. New Outlook keeps this under Settings, then Accounts.
- Type your Hushmail address, open Advanced options and tick let me set up my account manually.
- Choose IMAP, then
imap.hushmail.comon993SSL andsmtp.hushmail.comon465SSL. - Enter your Hushmail password when Outlook asks. If two-step is on, add a space and your security code.
- Finish and send a test email to yourself to confirm both directions work.
Apple Mail (macOS)
- Open Mail → Settings → Accounts → Add Account.
- Pick Hushmail if it appears, otherwise choose Other Mail Account.
- Enter your name, full address and password, then continue. Add the security code after a space if two-step is on.
- If asked for servers, enter the IMAP and SMTP values from the tables above.
- Enable Mail in the checkbox list and finish.
iPhone and iPad
- Open Settings → Apps → Mail → Mail Accounts → Add Account.
- Tap Other, then Add Mail Account. iOS carries no Hushmail entry.
- Enter your details, adding the security code after a space if two-step is on, then tap Next.
- Keep IMAP selected and fill the incoming and outgoing servers if iOS asks.
- Tap Save and wait for iOS to verify the account.
Android
- Open your mail app (Gmail app, Samsung Email or another) → Add account.
- Choose Other (IMAP) when your provider is not in the list.
- Enter your address and password. If auto setup fails, pick Manual setup.
- Enter the servers:
imap.hushmail.com993 SSL incoming,smtp.hushmail.com465 SSL outgoing. - Finish setup and pull down to sync your inbox.
Thunderbird
- Open Thunderbird → Account Settings → Account Actions → Add Mail Account.
- Enter your name, address and password, then select Continue.
- Let Thunderbird probe the servers, then confirm it chose IMAP on the SSL ports.
- If detection fails, choose Configure manually and enter the table values above.
- Select Done. Folders sync on first open.
Hushmail Webmail Settings#
Those values connect your apps. The settings here shape how the Hushmail mailbox itself behaves. They live in Hushmail webmail rather than in any client.
Signature
Set from the Hushmail webmail preferences. A signature added here shows on mail sent from the browser. Outlook and other clients keep their own, so the two can drift apart.
Vacation Auto Reply
Give the away message a start and an end date so it stops on its own. It runs on Hushmail servers, so replies keep going out with your devices switched off.
Filters and Folders
Rules built in the browser run on the server, filing mail before any device collects it. A rule inside Outlook only fires while Outlook is open, which is why two devices can sort the same message differently.
Spam and Blocked Senders
Block senders or whole domains from the same preferences area. When mail goes missing, check the browser spam folder first, since a client side rule cannot pull back what the server already filed.
POP3 vs IMAP#
| Feature | IMAP | POP3 |
|---|---|---|
| Where mail lives | On the Hushmail server | Downloaded to 1 device |
| Multiple devices | ✅ Everything stays in sync | ❌ Each device sees different mail |
| Sent and deleted mail | ✅ Synced everywhere | ⚠️ Stays only on that device |
| Offline reading | ⚠️ Cached mail only | ✅ Full local copy |
| Server storage used | Yes, counts against your quota | Can be freed after download |
| Best for | Phone + computer, everyday use | Single PC, local archives |
Hushmail Settings Worth Knowing#
Hushmail publishes the connection details more readily than exact quotas. These are the points that shape a client setup:
| Incoming security | SSL required. IMAP 993, POP 995 |
| Outgoing security | SSL required. SMTP 465, fallback 587 |
| Password with two-step on | Your password, a space, then the security code from Preferences |
| Outgoing encryption | Mail sent from a client is not encrypted unless the recipient can receive it |
| Account type | Paid secure email, so client access is included |
| Username | Always the full email address |
Troubleshooting Hushmail Connections#
Find the exact error your email app shows, then apply the fix:
| Error you see | What it means | Fix |
|---|---|---|
| Password rejected after enabling two-step | Security code missing from the password | Enter your password, a space, then the security code from Preferences on the Security tab. |
| Recipient got a plain unencrypted email | Sent through a mail client | Mail from a client goes out unencrypted unless the recipient can receive it. Send from Hushmail webmail for encrypted delivery. |
| Cannot connect to server | Wrong port or encryption | Check IMAP 993 SSL and SMTP 465 SSL. Security software and VPN clients block these ports often enough to rule out. |
| Password keeps being asked | Two-step is on but the code is missing | Replace the saved password with your password, a space, then the security code. |
| Messages stuck in Outbox | SMTP authentication is off | Turn on outgoing server requires authentication and reuse the incoming login. |
Reader Reported Fixes
The password stopped working the day two-step went on. Switching two-step verification on changes what a mail app expects. The field now needs your password, a space, then the security code from Preferences on the Security tab. People type the password alone, get refused, then assume the account broke. It did not. Add the code after the space and it connects.
Replies from Outlook arrived unencrypted. Hushmail encryption runs inside its own system, so mail sent through a third-party client is not encrypted unless the recipient can receive it. This surprises people who expect every Hushmail message to be private. For an encrypted message to a non-Hushmail recipient, send it from Hushmail webmail rather than the client.
Keeping a Copy of Your Hushmail Mail#
A backup tool wants the same values. The IMAP host imap.hushmail.com on 993 SSL, your full address, then your Hushmail password. With two-step on, add the security code after a space, exactly as a mail client would.
Encrypted mail stays readable in a backup. A backup pulls the messages as they sit in your mailbox, so the copy you keep opens in any mail app. That is a good reason to archive a secure mailbox before you ever need to.
Since Hushmail is a paid account, a lapse in payment can put mail out of reach. A local backup means a billing gap never costs you the archive.
Taking your mail to a new account? The Univik Email Migration Tool copies every folder from the old account to the new one. Enter the IMAP settings from this page for the Hushmail side and your new provider's settings for the other.
Rather not do it yourself? Our Email Migration Services team plans and runs the whole transfer for you and verifies every folder arrived.
Use These Settings in Univik Email Backup#
The same IMAP settings above let you download your complete Hushmail mailbox to your computer. Univik Email Backup saves everything as PST, MBOX, EML or PDF files you keep forever, even if the account closes.
- Download Univik Email Backup and install it on Windows.
- Select Hushmail from the source list. If it isn't listed by name, choose IMAP.
- Sign in with your full email address and your Hushmail password. With two-step on, add a space and the security code.
- If the tool asks for server details, use
imap.hushmail.comwith port993and SSL from the IMAP table above. - Pick a saving format and folder, then start the backup. Large mailboxes download in the background.
Email Settings Glossary#
IMAP
Internet Message Access Protocol. Reads mail that stays on the server, so all your devices see the same inbox, folders and read status.
POP3
Post Office Protocol version 3. Downloads mail to 1 device and can remove it from the server. Older method, still useful for local archives.
SMTP
Simple Mail Transfer Protocol. Sends your outgoing mail. Every account needs it next to IMAP or POP3, which only receive.
SSL / TLS / STARTTLS
Encryption for the connection. SSL/TLS encrypts from the start (ports 993, 995, 465). STARTTLS upgrades a plain connection (port 587).
Security Code
A short code Hushmail assigns when two-step verification is on. You add it to your password, after a space, inside a mail app. It sits in Preferences on the Security tab.
OAuth
Signing in through a browser window rather than typing a password into an app. Hushmail keeps it simpler, with a password and, when two-step is on, an added code.
How We Verify These Settings#
Univik has built email backup, migration and converter software since 2013. Our tools sign in to Hushmail over IMAP and SMTP every day, so a changed host, port or login rule turns up in our connection logs before most guides notice.
Every value on this page is confirmed with 3 checks: a live IMAP and SMTP connection from Univik Email Backup, a comparison against Hushmail own help pages, which is where the hosts, ports and the two-step password format come from. Any provider announcement triggers a recheck. We revisit quarterly regardless.
Found something that no longer matches what Hushmail shows you? Tell us and we will retest and update the page, with the change logged in what changed recently.
Help & Support
Frequently Asked Questions
Use imap.hushmail.com on port 993 with SSL, your full address as the username, then your Hushmail password. With two-step verification on, add a space and the security code after the password. The full table sits under IMAP settings.
The usual cause is two-step verification. With it on, a mail app wants your password, a space, then the security code Hushmail shows in Preferences on the Security tab. Type them as one string, like mypass 1234abcd. Without two-step, your normal password should sign you in. See how the password works.
IMAP for almost everyone, since it keeps phone, computer and webmail on the same inbox. POP suits only a single machine where you want a local download. The comparison lays out both.
Yes. Hosts, ports and SSL stay the same on every device. Only the menu names change, which the client setup guides walk through.
Sign in to Hushmail webmail, open Preferences, then the Security tab. The IMAP and POP password listed there is the security code. Put it after your password and a space in the mail app. It stays available in Preferences, so you can check it again any time.
Yes. Use the SSL ports on this page and the connection is protected. Keep in mind that mail you send from a client is not encrypted unless the recipient can receive it, so send from webmail when a message needs Hushmail encryption.
An IMAP client pulls mail down as it syncs, though a dedicated backup tool moves faster and writes standard files that open anywhere. See how to back up your Hushmail mailbox. Already have files in another format? An email converter turns them into PST, PDF or whatever your new app reads.
On Hushmail the likeliest trigger is two-step verification being switched on, which changes what the password field expects. Add a space and the security code to your password. See what changed recently for the other cause, an outdated client.
An email migration tool copies mail straight between the two accounts over IMAP. You need the Hushmail IMAP settings and your password for this side, adding the security code if two-step is on, plus the destination details. Every folder and date stays intact.
If setting this up feels risky or you have many accounts to move, our managed email migration service does the entire job for you.
Other Email Provider Settings
Summary: Hushmail Settings at a Glance
- IMAP: imap.hushmail.com, port 993, SSL/TLS
- POP3: pop.hushmail.com, port 995, SSL/TLS
- SMTP: smtp.hushmail.com, port 465, SSL
- Username is always your full email address
- Two-step on means password + space + security code
- Pick IMAP for phone + computer sync
- Client mail sends unencrypted unless recipient can receive it
- Username is always the full email address