Email Settings Email Settings Guide

Kerio Connect Email Settings: IMAP, SMTP and POP3

Kerio Connect runs on your own server, so the mail host is your Kerio address like mail.yourdomain.com. The ports match every Kerio Connect: IMAP 993, POP3 995, SMTP 465 or 587. Copy each value with 1 tap.

Tested July 26, 2026 1 Tap Copy Admin Port Is 4040

Kerio Connect Quick Settings

IMAP Server mail.yourdomain.com
IMAP Port 993 (SSL/TLS)
SMTP Server mail.yourdomain.com
SMTP Port 465 (SSL) / 587 (STARTTLS)
POP3 Server mail.yourdomain.com
Username Your full email address

Quick answer: for Kerio Connect, the mail server is your own host, usually mail.yourdomain.com, the same address as your webmail. IMAP is port 993 with SSL/TLS. SMTP uses port 465 (SSL) or 587 (STARTTLS). POP3 is port 995 with SSL. Sign in with your full email address and your Kerio account password. The admin console sits on a separate address, mail.yourdomain.com:4040/admin, which is not a mail port.

Every setting on this page is verified with live IMAP and SMTP connections from Univik email software. We build email backup and converter tools since 2013, so we test against these servers every day. See what changed →

What Changed Recently#

Kerio Connect is stable across releases, but a few points matter when you connect a client. Here is the current status.

Latest update

Kerio Connect is now a GFI Software product. Support and documentation moved to the GFI domains. The server software, ports and admin console on 4040 work the same, so your Outlook or phone setup does not change.

Earlier change

Two step verification adds application passwords. If your admin turned on two step login, mail apps that cannot show the second prompt need an application password generated in the Kerio Connect Client. Without it, your normal password works.

Earlier change

ActiveSync stays the built in way to sync phones. Kerio Connect includes Exchange ActiveSync, so a phone can pull mail, calendar, contacts and tasks over one account without any add-on.

Current status: the client ports are the same on every Kerio Connect. Your mail host is whatever your admin set, almost always the same address as your Kerio Connect Client.

Before You Begin#

Do these 2 things first. If you skip them, your email app will reject the connection even when every server value is correct.

1. Know your mail host

Kerio has no fixed address. Your mail host is your own server name, the same one you open the Kerio Connect Client at, like mail.yourdomain.com. The admin console on port 4040 is a different thing.

Where: the address bar of your Kerio Connect Client or ask your admin

2. IMAP or POP must be allowed

Kerio lets an admin switch each protocol on or off. If no client can connect, the IMAP or POP service may be turned off for the server.

Where: Enable services in Kerio below →

About Kerio Connect#

Kerio Connect is a mail, calendar and contacts server that businesses run on their own Windows, Linux or Mac machine, now sold by GFI Software.

Because Kerio is self-hosted, no single server address fits everyone. Your mail host is the address you open the Kerio Connect Client at. The point that catches people out is the admin console, which lives on port 4040 at mail.yourdomain.com:4040/admin. That address is for managing the server, so it never goes in a mail app. Your email client uses the standard ports 993, 995, 465 and 587.

Service NameKerio Connect
Owned ByGFI Software
TypeSelf-hosted mail and collaboration server
Server HostYour own domain, like mail.yourdomain.com
WebmailKerio Connect Client
ProtocolsIMAP, POP3, SMTP, ActiveSync
App PasswordOnly if your admin turned on 2FA
Max Message SizeSet by admin
Every Kerio Connect uses the same ports: only the host changes from one server to the next. The ports 993, 995, 465 and 587 stay the same. Not sure of your host? It is the address you open the Kerio Connect Client at.

Kerio Connect Login#

You can always read your mail in a browser through the Kerio Connect Client. The key addresses are:

Connect Client

https://mail.yourdomain.com

Admin Console

mail.yourdomain.com:4040/admin

Change Password

Connect Client → Settings or ask your admin

The admin console is not a mail setting. The address on port 4040 manages the server itself. Never type it into Outlook or a phone. Mail apps only use the host and ports in the tables further down.

Enable Services in Kerio#

Kerio Connect exposes each protocol as a service that an admin can allow or deny. If a client cannot reach the server at all, the matching service may be off. This is an admin task, so skip it if IMAP already works for you.

  1. Open the admin console at https://mail.yourdomain.com:4040/admin and sign in as an administrator.
  2. Go to Configuration, then Services. This lists SMTP, IMAP, IMAPS, POP3, POP3S and more, each with an allow or deny state.
  3. Allow the ones your clients need. For secure mail apps that is IMAPS, POP3S and SMTP Submission. Start any that are stopped.
  4. Check access limits. A service can be restricted by IP address or group, so confirm the account is not blocked from outside the office.
Kerio services that must be allowed Configuration → Services Allow for mail apps IMAPS (993) POP3S (995) SMTP Submission (587) SMTPS (465) Optional, plain text IMAP (143) POP3 (110) Often left denied for security
Most admins allow only the secure services. If plain 143 or 110 fails, that is why.
Kerio Connect Client versus admin console Connect Client (read mail)https://mail.yourdomain.com Admin console (manage):4040/admin Mail apps use the IMAP and SMTP ports, not these
Reading mail and managing the server are two different addresses. Neither goes in your email app.

Kerio Connect IMAP Settings#

IMAP is the incoming protocol most people should use. Leaves mail on the Kerio server so every device shows one inbox.

IMAP ServerYour Kerio host, like mail.yourdomain.com
Port993 (SSL) or 143 (STARTTLS)
EncryptionSSL/TLS or STARTTLS
UsernameYour full email address on your domain
PasswordYour Kerio account password
AuthenticationRequired

Kerio Connect POP3 Settings#

POP3 downloads mail to 1 device. Choose it only for a local copy on one computer. Not sure? See the comparison below.

POP3 ServerYour Kerio host, like mail.yourdomain.com
Port995
EncryptionSSL/TLS (required)
UsernameYour full email address
PasswordYour Kerio account password
POP3 pulls mail down and can wipe the server copy. POP fits one computer. Tick "leave a copy on the server" so mail stays in the Kerio Connect Client or pick IMAP to keep every device matched.

Kerio Connect SMTP Settings#

Send on 465 or 587, not 4040: in mail apps use SMTP 465 or 587 with your account password and authentication switched on. Port 4040 is the admin console, never a mail port. If plain 143 or 110 will not connect, your admin allows only the secure ports, so use 993 and 995.

SMTP handles outgoing mail. If you can read mail but not send it, the problem is here.

SMTP ServerYour Kerio host, like mail.yourdomain.com
Port (SSL)465
Port (STARTTLS)587
EncryptionSSL or STARTTLS (required)
UsernameYour full email address
PasswordSame account password as incoming
AuthenticationRequired. Check "My outgoing server requires authentication" in Outlook.

Check Kerio IMAP Settings Online#

You don't need to download anything to check Kerio Connect IMAP settings. This page is the lookup itself, with verified ports you can copy in the browser. Since Kerio runs on your own domain, the host is yours, so the checker below sends known consumer domains to their own guides. For your Kerio domain, use the address you open the Connect Client at with the ports above.

Your Connect Client address is your mail host The address you open the Connect Client at Use as your IMAP host Use as your SMTP host
Not the :4040 admin address. The plain Connect Client host is your mail host.

Does my email address use these settings?

Runs in your browser only. Your address is never sent anywhere or stored.

Want to check the account itself before setting up an app? Sign in to the Kerio Connect Client, which proves your address and password work. Once that opens, any email app connects with the same details from the tables above.

Look Up IMAP Settings for Any Email Domain#

This page covers Kerio Connect. For every other address, work email on a company domain included, we run a free online lookup database: imapsettings.com.

imapsettings.com

Complete email settings database, by Univik

Check IMAP settings online →

Enter any email address and get the incoming and outgoing server settings for that domain in 1 step:

Incoming server: hostname, port, SSL/TLS and username format
Outgoing server: SMTP hostname, port and encryption

Your address is used only to find the settings for that domain. Nothing is stored or shared.

Your Password and Sign In#

For most Kerio accounts you sign in with your normal account password. An application password only matters if your admin turned on two step login.

Which password to use in mail apps Two step offUse your account password Two step onUse an application password
Most accounts fall on the left. Only reach for an application password when two step is on.
Where you sign inAccount passwordApp password
Kerio Connect Client✓ Works✗ Not used
Outlook, Apple Mail, Thunderbird (no 2FA)✓ Works✗ Not needed
Phone mail apps (no 2FA)✓ Works✗ Not needed
Any mail app once 2FA is on✗ Fails✓ Required

Get an Application Password (only with 2FA)

  1. Open the Kerio Connect Client in a browser and go to Settings.
  2. Find the two step verification area. Application passwords only appear once two step login is on.
  3. Create an application password and label it after the app, for example Outlook or iPhone Mail.
  4. Copy the generated password and paste it into that app in place of your normal one.
  5. No two step on your account? Ignore this and sign in with your usual account password.
Good to know: most Kerio accounts never need an application password. If a client is refused, first check the service is allowed and that you entered the mail host, not the 4040 admin address.

Set Up Kerio Connect in Email Clients#

Enter your Kerio mail host for both incoming and outgoing, with IMAP 993 and SMTP 465. On phones you can also add the account as Exchange to pull mail, calendar and contacts through ActiveSync.

Kerio Connect account setup at a glance What to enter in any mail app Incoming (IMAP) Server: your Kerio host Port: 993 Security: SSL/TLS Outgoing (SMTP) Server: your Kerio host Port: 465 Security: SSL/TLS Username: your full email address Password: your account password, or app password if 2FA is on
The host is the same for incoming and outgoing. Only the port changes.
How Kerio syncs mail, calendar and contacts IMAPMail only (993) ActiveSync (built in)Mail, calendar, contacts, tasks In Outlook: Kerio Outlook Connectoradds shared calendars and contacts
The mail settings here cover IMAP. For calendar and contacts on a phone, use ActiveSync.

Jump to your app:

Outlook (Windows and Mac)

  1. Open Outlook → File → Add Account (in new Outlook, Settings → Accounts → Add account).
  2. Enter your Kerio address, open Advanced options and check "Let me set up my account manually".
  3. Choose IMAP and put your mail host on port 993 (SSL) incoming and the same host on port 465 (SSL) outgoing.
  4. Enter your account password. Switch on "outgoing server requires authentication".
  5. Prefer full sync? The Kerio Outlook Connector adds shared calendars and contacts the way Exchange does.

Apple Mail (macOS)

  1. Open Mail → Settings → Accounts → Add Account → Other Mail Account.
  2. Enter your name, Kerio address and account password, then continue.
  3. When detection fails, set your Kerio mail host as both incoming and outgoing.
  4. Use IMAP 993 SSL incoming and 465 SSL outgoing, with your full address as the username.
  5. Enable Mail in the checkbox list and finish. Accept the certificate if it prompts.

iPhone and iPad

  1. For mail only, open Settings → Apps → Mail → Mail Accounts → Add Account → Other, then Add Mail Account.
  2. Enter your name, Kerio address and account password, keep IMAP selected.
  3. Set your Kerio mail host for incoming and outgoing, 993 SSL and 465 SSL.
  4. For mail, calendar and contacts together, add the account as Exchange and enter your host as the server.
  5. Tap Save and wait for iOS to verify the account.

Android

  1. Open your mail app (Gmail app, Samsung Email or another) → Add account.
  2. Choose Other or IMAP, or pick Exchange for mail, calendar and contacts in one account.
  3. Enter your address and account password, then choose Manual setup for IMAP.
  4. Enter the servers: your Kerio host 993 SSL incoming, the same host 465 SSL outgoing.
  5. Finish setup and pull down to sync your inbox.

Thunderbird

  1. Open Thunderbird → Account Settings → Account Actions → Add Mail Account.
  2. Enter your name, Kerio address and account password, then select Continue.
  3. Pick Configure manually, since Thunderbird cannot guess a self-hosted host.
  4. Point both servers at your Kerio host, IMAP 993 SSL and SMTP 465 SSL, with your full address.
  5. Select Done. Folders sync on first open.

Connect Client Settings#

Server settings connect your apps. These control how your Kerio mail behaves. All of them live in the Kerio Connect Client under Settings.

Signature

Settings, then Mail and Signature. A signature made here shows in the Connect Client only. Outlook and other apps keep their own.

Vacation Auto Reply

Settings, then Out of Office. Give it a start and end date so it stops by itself. The reply goes out even with your computer off because the Kerio server sends it.

Filters and Folders

Settings, then Filters. Rules here run on the Kerio server, so they act before your phone or Outlook sees the mail. App only rules wait until that app is running.

Spam and Blocked Senders

Settings, then Spam. Flag a message as spam to teach the filter and manage your safe sender list. The heavy spam rules are set by your admin on the server.

POP3 vs IMAP#

FeatureIMAPPOP3
Where mail livesOn the Kerio serverDownloaded to 1 device
Multiple devices✅ Everything stays in sync❌ Each device sees different mail
Sent and deleted mail✅ Synced everywhere⚠️ Stays only on that device
Offline reading⚠️ Cached mail only✅ Full local copy
Server storage usedYes, counts against your quotaCan be freed after download
Best forPhone + computer, everyday useSingle PC, local archives
Our verdict: pick IMAP for computers and ActiveSync for phones, since both keep the server and your devices matched. Reach for POP only on a single machine. For a lasting offline copy, a backup tool handles that better than POP3.

Kerio Sending and Storage Limits#

On Kerio Connect the limits are set by your admin, not a fixed policy. These are the settings that decide what goes through, each adjustable in the admin console:

Max message sizeSet in the admin console SMTP limits
Recipients per messageAdmin controlled
Mailbox quotaSet per user or domain
AttachmentsCounted inside the message size limit
Which protocols are openAllowed or denied per service
What happens at the limitOversized mail is refused, a full mailbox bounces new mail

Troubleshooting Kerio Connections#

Find the exact error your email app shows, then apply the fix:

Error you seeWhat it meansFix
Log onto incoming mail server (IMAP) failed The IMAP service is denied or the port is wrong Ask an admin to allow IMAPS, then set the client to 993 with SSL.
Cannot connect on port 4040 That is the admin console, not a mail port Use your mail host with 993 for IMAP and 465 or 587 for SMTP. Port 4040 is only for managing the server.
Certificate is not trusted The Kerio server uses a self-signed certificate On your own server this is expected. Accept it once on your own box, then add a real certificate like Let's Encrypt to clear it.
550 5.7.1 Authentication The outgoing server is not authenticating Turn on "outgoing server requires authentication" with the same login. If two step is on, use an application password.
Messages stuck in Outbox SMTP authentication is off Enable "outgoing server requires authentication" with the same login as incoming mail.

Reader Reported Fixes

Two fixes that come up over and over in Kerio setups, beyond the error table above.

Use the Connect Client address, not the :4040 one. The mail host is the plain address you open the Connect Client at. The 4040 address is the admin console. Putting the admin address into a mail app is the single most common mistake.

When plain ports fail, switch to the secure ones. Many admins deny plain 143 and 110 and allow only 993 and 995. If a plain port times out, move the client to the SSL port and the block clears.

Handling a Kerio certificate warning Certificate warning Your own server: accept once Install Let's Encrypt: no warnings
A self-signed certificate is what triggers that warning. A real certificate removes it for good.

Moving Mail to or from Kerio?#

Moving to a new Kerio server? The Univik Email Migration Tool copies every folder over IMAP. Put the old host on one side and your new Kerio host on the other, each with a full address and account password.

Leaving Kerio for Microsoft 365 or Google? The same tool reads your Kerio mailbox folder by folder with the settings on this page and writes it into the new account.

Coming to Kerio from another provider? Enter your old account on one side and your Kerio host on the other. Every folder and date stays intact.

Back up before any big change. Save the mailbox first so you keep a copy whatever happens during the move.

Rather not do it yourself? Our Email Migration Services team plans and runs the whole transfer for you and verifies every folder arrived.

Use These Settings in Univik Email Backup#

The same IMAP settings above let you download your complete Kerio mailbox to your computer. Univik Email Backup saves everything as PST, MBOX, EML or PDF files you keep forever, even if the server is retired.

  1. Download Univik Email Backup and install it on Windows.
  2. Select IMAP from the source list. Kerio is not named, so IMAP is the option to pick.
  3. Sign in with your full email address and your Kerio account password. An application password is only needed if two step login is on.
  4. If the tool asks for server details, use your Kerio host with port 993 and SSL from the IMAP table above.
  5. Pick a saving format and folder, then start the backup. Large mailboxes download in the background.
Why back up before switching providers: POP3 only grabs the inbox and vacation replies to a closed account bounce. A full IMAP backup keeps every folder, attachment and date stamp in files any email app can open later. Moving to a new account instead of archiving? Use the email migration tool to copy mail directly between accounts.

Email Settings Glossary#

IMAP

Internet Message Access Protocol. Reads mail that stays on the server, so all your devices see the same inbox, folders and read status.

POP3

Post Office Protocol version 3. Pulls mail to one device and may delete the server copy. Older method, still useful for local archives.

SMTP

Simple Mail Transfer Protocol. Sends your outgoing mail. Every account needs it next to IMAP or POP3, which only receive.

SSL / TLS / STARTTLS

Encryption for the connection. SSL/TLS encrypts from the start (ports 993, 995, 465). STARTTLS upgrades a plain connection (port 587).

App Password

A 16 character code that replaces your real password inside email apps. Safer because you can revoke 1 app without changing your main password.

OAuth

Sign in through the provider's own window instead of typing a password into the app. The modern method most providers are moving to.

How We Verify These Settings#

Univik builds email backup, migration and converter software since 2013. Our tools sign in to Kerio Connect servers over IMAP and SMTP every day for thousands of users, so a port, service or login quirk shows in our connection logs before most guides catch it.

Every value here is confirmed with 3 checks: live IMAP and SMTP connections from Univik Email Backup, a comparison against the Kerio Connect and GFI documentation, then a test sign in from a mail client. We re verify after any Kerio release and at least once a quarter.

Found something that no longer matches your Kerio server? Tell us and we will retest and update the page, with the change logged in what changed recently.

 Help & Support

Frequently Asked Questions

The mail server is your own Kerio host, the address you open the Connect Client at. IMAP is port 993 with SSL. SMTP uses port 465 with SSL or 587 with STARTTLS. Sign in with your full email address and your Kerio account password.

Common causes, in the order to check them: the IMAP service is denied in the admin console. The client points at the 4040 admin address instead of the mail host. Two step login is on so you need an application password.

IMAP on computers, ActiveSync on phones. Both keep the Kerio server and your devices matched. POP3 fits a lone computer that keeps a local download. Full comparison here.

It is your own server name, the address you open the Kerio Connect Client at, like mail.yourdomain.com. Point both incoming and outgoing at that same host. The 4040 admin address is separate and never goes in a mail app.

Only if your admin turned on two step login. Without it, your normal Kerio account password works everywhere. With it, you generate an application password in the Connect Client and use that in mail apps.

Port 4040 is the Kerio admin console, reached at mail.yourdomain.com:4040/admin. It is for managing the server, not for reading mail, so it never goes in Outlook or a phone. Mail apps use 993, 995, 465 or 587.

An IMAP client pulls mail as it syncs, but a dedicated backup tool runs faster and writes standard files you can open anywhere. See how to back up your Kerio mailbox. Do it before you move or rebuild a server so you keep your own copy.

Yes. IMAP carries mail only, but Kerio includes Exchange ActiveSync, which syncs mail, calendar, contacts and tasks over one account on a phone. On a computer, the Kerio Outlook Connector does the same inside Outlook. CalDAV and CardDAV cover other apps.

An email migration tool copies mail directly between the 2 accounts over IMAP. You need your Kerio host and account password for this side, plus the destination account details. Every folder and date stays intact.

If setting this up feels risky or you have many accounts to move, our managed email migration service does the entire job for you.

Other Email Provider Settings

Summary: Kerio Connect Settings at a Glance

  • Host: your Kerio server, your Connect Client address
  • IMAP port 993, POP3 995, both SSL/TLS
  • SMTP port 465 (SSL) or 587 (STARTTLS)
  • Username is your full email address
  • Sign in with your account password
  • App password only when 2FA is on
  • Admin console is port 4040, not a mail port
  • ActiveSync syncs mail, calendar and contacts