Quick answer: for Kerio Connect, the mail server is your own host, usually mail.yourdomain.com, the same address as your webmail. IMAP is port 993 with SSL/TLS. SMTP uses port 465 (SSL) or 587 (STARTTLS). POP3 is port 995 with SSL. Sign in with your full email address and your Kerio account password. The admin console sits on a separate address, mail.yourdomain.com:4040/admin, which is not a mail port.
What Changed Recently#
Kerio Connect is stable across releases, but a few points matter when you connect a client. Here is the current status.
Latest update
Kerio Connect is now a GFI Software product. Support and documentation moved to the GFI domains. The server software, ports and admin console on 4040 work the same, so your Outlook or phone setup does not change.
Earlier change
Two step verification adds application passwords. If your admin turned on two step login, mail apps that cannot show the second prompt need an application password generated in the Kerio Connect Client. Without it, your normal password works.
Earlier change
ActiveSync stays the built in way to sync phones. Kerio Connect includes Exchange ActiveSync, so a phone can pull mail, calendar, contacts and tasks over one account without any add-on.
Before You Begin#
Do these 2 things first. If you skip them, your email app will reject the connection even when every server value is correct.
1. Know your mail host
Kerio has no fixed address. Your mail host is your own server name, the same one you open the Kerio Connect Client at, like mail.yourdomain.com. The admin console on port 4040 is a different thing.
Where: the address bar of your Kerio Connect Client or ask your admin
2. IMAP or POP must be allowed
Kerio lets an admin switch each protocol on or off. If no client can connect, the IMAP or POP service may be turned off for the server.
About Kerio Connect#
Kerio Connect is a mail, calendar and contacts server that businesses run on their own Windows, Linux or Mac machine, now sold by GFI Software.
Because Kerio is self-hosted, no single server address fits everyone. Your mail host is the address you open the Kerio Connect Client at. The point that catches people out is the admin console, which lives on port 4040 at mail.yourdomain.com:4040/admin. That address is for managing the server, so it never goes in a mail app. Your email client uses the standard ports 993, 995, 465 and 587.
| Service Name | Kerio Connect |
| Owned By | GFI Software |
| Type | Self-hosted mail and collaboration server |
| Server Host | Your own domain, like mail.yourdomain.com |
| Webmail | Kerio Connect Client |
| Protocols | IMAP, POP3, SMTP, ActiveSync |
| App Password | Only if your admin turned on 2FA |
| Max Message Size | Set by admin |
993, 995, 465 and 587 stay the same. Not sure of your host? It is the address you open the Kerio Connect Client at.
Kerio Connect Login#
You can always read your mail in a browser through the Kerio Connect Client. The key addresses are:
Connect Client
https://mail.yourdomain.com
Admin Console
mail.yourdomain.com:4040/admin
Change Password
Connect Client → Settings or ask your admin
4040 manages the server itself. Never type it into Outlook or a phone. Mail apps only use the host and ports in the tables further down.
Enable Services in Kerio#
Kerio Connect exposes each protocol as a service that an admin can allow or deny. If a client cannot reach the server at all, the matching service may be off. This is an admin task, so skip it if IMAP already works for you.
- Open the admin console at
https://mail.yourdomain.com:4040/adminand sign in as an administrator. - Go to Configuration, then Services. This lists SMTP, IMAP, IMAPS, POP3, POP3S and more, each with an allow or deny state.
- Allow the ones your clients need. For secure mail apps that is IMAPS, POP3S and SMTP Submission. Start any that are stopped.
- Check access limits. A service can be restricted by IP address or group, so confirm the account is not blocked from outside the office.
Kerio Connect IMAP Settings#
IMAP is the incoming protocol most people should use. Leaves mail on the Kerio server so every device shows one inbox.
| IMAP Server | Your Kerio host, like mail.yourdomain.com | |
| Port | 993 (SSL) or 143 (STARTTLS) | |
| Encryption | SSL/TLS or STARTTLS | |
| Username | Your full email address on your domain | |
| Password | Your Kerio account password | |
| Authentication | Required |
Kerio Connect POP3 Settings#
POP3 downloads mail to 1 device. Choose it only for a local copy on one computer. Not sure? See the comparison below.
| POP3 Server | Your Kerio host, like mail.yourdomain.com | |
| Port | 995 | |
| Encryption | SSL/TLS (required) | |
| Username | Your full email address | |
| Password | Your Kerio account password |
Kerio Connect SMTP Settings#
465 or 587 with your account password and authentication switched on. Port 4040 is the admin console, never a mail port. If plain 143 or 110 will not connect, your admin allows only the secure ports, so use 993 and 995.
SMTP handles outgoing mail. If you can read mail but not send it, the problem is here.
| SMTP Server | Your Kerio host, like mail.yourdomain.com | |
| Port (SSL) | 465 | |
| Port (STARTTLS) | 587 | |
| Encryption | SSL or STARTTLS (required) | |
| Username | Your full email address | |
| Password | Same account password as incoming | |
| Authentication | Required. Check "My outgoing server requires authentication" in Outlook. |
Check Kerio IMAP Settings Online#
You don't need to download anything to check Kerio Connect IMAP settings. This page is the lookup itself, with verified ports you can copy in the browser. Since Kerio runs on your own domain, the host is yours, so the checker below sends known consumer domains to their own guides. For your Kerio domain, use the address you open the Connect Client at with the ports above.
Does my email address use these settings?
Runs in your browser only. Your address is never sent anywhere or stored.
Want to check the account itself before setting up an app? Sign in to the Kerio Connect Client, which proves your address and password work. Once that opens, any email app connects with the same details from the tables above.
Look Up IMAP Settings for Any Email Domain#
This page covers Kerio Connect. For every other address, work email on a company domain included, we run a free online lookup database: imapsettings.com.
imapsettings.com
Complete email settings database, by Univik
Enter any email address and get the incoming and outgoing server settings for that domain in 1 step:
Your address is used only to find the settings for that domain. Nothing is stored or shared.
Your Password and Sign In#
For most Kerio accounts you sign in with your normal account password. An application password only matters if your admin turned on two step login.
| Where you sign in | Account password | App password |
|---|---|---|
| Kerio Connect Client | ✓ Works | ✗ Not used |
| Outlook, Apple Mail, Thunderbird (no 2FA) | ✓ Works | ✗ Not needed |
| Phone mail apps (no 2FA) | ✓ Works | ✗ Not needed |
| Any mail app once 2FA is on | ✗ Fails | ✓ Required |
Get an Application Password (only with 2FA)
- Open the Kerio Connect Client in a browser and go to Settings.
- Find the two step verification area. Application passwords only appear once two step login is on.
- Create an application password and label it after the app, for example Outlook or iPhone Mail.
- Copy the generated password and paste it into that app in place of your normal one.
- No two step on your account? Ignore this and sign in with your usual account password.
4040 admin address.
Set Up Kerio Connect in Email Clients#
Enter your Kerio mail host for both incoming and outgoing, with IMAP 993 and SMTP 465. On phones you can also add the account as Exchange to pull mail, calendar and contacts through ActiveSync.
Jump to your app:
Outlook (Windows and Mac)
- Open Outlook → File → Add Account (in new Outlook, Settings → Accounts → Add account).
- Enter your Kerio address, open Advanced options and check "Let me set up my account manually".
- Choose IMAP and put your mail host on port
993(SSL) incoming and the same host on port465(SSL) outgoing. - Enter your account password. Switch on "outgoing server requires authentication".
- Prefer full sync? The Kerio Outlook Connector adds shared calendars and contacts the way Exchange does.
Apple Mail (macOS)
- Open Mail → Settings → Accounts → Add Account → Other Mail Account.
- Enter your name, Kerio address and account password, then continue.
- When detection fails, set your Kerio mail host as both incoming and outgoing.
- Use IMAP 993 SSL incoming and 465 SSL outgoing, with your full address as the username.
- Enable Mail in the checkbox list and finish. Accept the certificate if it prompts.
iPhone and iPad
- For mail only, open Settings → Apps → Mail → Mail Accounts → Add Account → Other, then Add Mail Account.
- Enter your name, Kerio address and account password, keep IMAP selected.
- Set your Kerio mail host for incoming and outgoing, 993 SSL and 465 SSL.
- For mail, calendar and contacts together, add the account as Exchange and enter your host as the server.
- Tap Save and wait for iOS to verify the account.
Android
- Open your mail app (Gmail app, Samsung Email or another) → Add account.
- Choose Other or IMAP, or pick Exchange for mail, calendar and contacts in one account.
- Enter your address and account password, then choose Manual setup for IMAP.
- Enter the servers: your Kerio host 993 SSL incoming, the same host 465 SSL outgoing.
- Finish setup and pull down to sync your inbox.
Thunderbird
- Open Thunderbird → Account Settings → Account Actions → Add Mail Account.
- Enter your name, Kerio address and account password, then select Continue.
- Pick Configure manually, since Thunderbird cannot guess a self-hosted host.
- Point both servers at your Kerio host, IMAP 993 SSL and SMTP 465 SSL, with your full address.
- Select Done. Folders sync on first open.
Connect Client Settings#
Server settings connect your apps. These control how your Kerio mail behaves. All of them live in the Kerio Connect Client under Settings.
Signature
Settings, then Mail and Signature. A signature made here shows in the Connect Client only. Outlook and other apps keep their own.
Vacation Auto Reply
Settings, then Out of Office. Give it a start and end date so it stops by itself. The reply goes out even with your computer off because the Kerio server sends it.
Filters and Folders
Settings, then Filters. Rules here run on the Kerio server, so they act before your phone or Outlook sees the mail. App only rules wait until that app is running.
Spam and Blocked Senders
Settings, then Spam. Flag a message as spam to teach the filter and manage your safe sender list. The heavy spam rules are set by your admin on the server.
POP3 vs IMAP#
| Feature | IMAP | POP3 |
|---|---|---|
| Where mail lives | On the Kerio server | Downloaded to 1 device |
| Multiple devices | ✅ Everything stays in sync | ❌ Each device sees different mail |
| Sent and deleted mail | ✅ Synced everywhere | ⚠️ Stays only on that device |
| Offline reading | ⚠️ Cached mail only | ✅ Full local copy |
| Server storage used | Yes, counts against your quota | Can be freed after download |
| Best for | Phone + computer, everyday use | Single PC, local archives |
Kerio Sending and Storage Limits#
On Kerio Connect the limits are set by your admin, not a fixed policy. These are the settings that decide what goes through, each adjustable in the admin console:
| Max message size | Set in the admin console SMTP limits |
| Recipients per message | Admin controlled |
| Mailbox quota | Set per user or domain |
| Attachments | Counted inside the message size limit |
| Which protocols are open | Allowed or denied per service |
| What happens at the limit | Oversized mail is refused, a full mailbox bounces new mail |
Troubleshooting Kerio Connections#
Find the exact error your email app shows, then apply the fix:
| Error you see | What it means | Fix |
|---|---|---|
| Log onto incoming mail server (IMAP) failed | The IMAP service is denied or the port is wrong | Ask an admin to allow IMAPS, then set the client to 993 with SSL. |
| Cannot connect on port 4040 | That is the admin console, not a mail port | Use your mail host with 993 for IMAP and 465 or 587 for SMTP. Port 4040 is only for managing the server. |
| Certificate is not trusted | The Kerio server uses a self-signed certificate | On your own server this is expected. Accept it once on your own box, then add a real certificate like Let's Encrypt to clear it. |
| 550 5.7.1 Authentication | The outgoing server is not authenticating | Turn on "outgoing server requires authentication" with the same login. If two step is on, use an application password. |
| Messages stuck in Outbox | SMTP authentication is off | Enable "outgoing server requires authentication" with the same login as incoming mail. |
Reader Reported Fixes
Two fixes that come up over and over in Kerio setups, beyond the error table above.
Use the Connect Client address, not the :4040 one. The mail host is the plain address you open the Connect Client at. The 4040 address is the admin console. Putting the admin address into a mail app is the single most common mistake.
When plain ports fail, switch to the secure ones. Many admins deny plain 143 and 110 and allow only 993 and 995. If a plain port times out, move the client to the SSL port and the block clears.
Moving Mail to or from Kerio?#
Moving to a new Kerio server? The Univik Email Migration Tool copies every folder over IMAP. Put the old host on one side and your new Kerio host on the other, each with a full address and account password.
Leaving Kerio for Microsoft 365 or Google? The same tool reads your Kerio mailbox folder by folder with the settings on this page and writes it into the new account.
Coming to Kerio from another provider? Enter your old account on one side and your Kerio host on the other. Every folder and date stays intact.
Back up before any big change. Save the mailbox first so you keep a copy whatever happens during the move.
Rather not do it yourself? Our Email Migration Services team plans and runs the whole transfer for you and verifies every folder arrived.
Use These Settings in Univik Email Backup#
The same IMAP settings above let you download your complete Kerio mailbox to your computer. Univik Email Backup saves everything as PST, MBOX, EML or PDF files you keep forever, even if the server is retired.
- Download Univik Email Backup and install it on Windows.
- Select IMAP from the source list. Kerio is not named, so IMAP is the option to pick.
- Sign in with your full email address and your Kerio account password. An application password is only needed if two step login is on.
- If the tool asks for server details, use your Kerio host with port
993and SSL from the IMAP table above. - Pick a saving format and folder, then start the backup. Large mailboxes download in the background.
Email Settings Glossary#
IMAP
Internet Message Access Protocol. Reads mail that stays on the server, so all your devices see the same inbox, folders and read status.
POP3
Post Office Protocol version 3. Pulls mail to one device and may delete the server copy. Older method, still useful for local archives.
SMTP
Simple Mail Transfer Protocol. Sends your outgoing mail. Every account needs it next to IMAP or POP3, which only receive.
SSL / TLS / STARTTLS
Encryption for the connection. SSL/TLS encrypts from the start (ports 993, 995, 465). STARTTLS upgrades a plain connection (port 587).
App Password
A 16 character code that replaces your real password inside email apps. Safer because you can revoke 1 app without changing your main password.
OAuth
Sign in through the provider's own window instead of typing a password into the app. The modern method most providers are moving to.
How We Verify These Settings#
Univik builds email backup, migration and converter software since 2013. Our tools sign in to Kerio Connect servers over IMAP and SMTP every day for thousands of users, so a port, service or login quirk shows in our connection logs before most guides catch it.
Every value here is confirmed with 3 checks: live IMAP and SMTP connections from Univik Email Backup, a comparison against the Kerio Connect and GFI documentation, then a test sign in from a mail client. We re verify after any Kerio release and at least once a quarter.
Found something that no longer matches your Kerio server? Tell us and we will retest and update the page, with the change logged in what changed recently.
Help & Support
Frequently Asked Questions
The mail server is your own Kerio host, the address you open the Connect Client at. IMAP is port 993 with SSL. SMTP uses port 465 with SSL or 587 with STARTTLS. Sign in with your full email address and your Kerio account password.
Common causes, in the order to check them: the IMAP service is denied in the admin console. The client points at the 4040 admin address instead of the mail host. Two step login is on so you need an application password.
IMAP on computers, ActiveSync on phones. Both keep the Kerio server and your devices matched. POP3 fits a lone computer that keeps a local download. Full comparison here.
It is your own server name, the address you open the Kerio Connect Client at, like mail.yourdomain.com. Point both incoming and outgoing at that same host. The 4040 admin address is separate and never goes in a mail app.
Only if your admin turned on two step login. Without it, your normal Kerio account password works everywhere. With it, you generate an application password in the Connect Client and use that in mail apps.
Port 4040 is the Kerio admin console, reached at mail.yourdomain.com:4040/admin. It is for managing the server, not for reading mail, so it never goes in Outlook or a phone. Mail apps use 993, 995, 465 or 587.
An IMAP client pulls mail as it syncs, but a dedicated backup tool runs faster and writes standard files you can open anywhere. See how to back up your Kerio mailbox. Do it before you move or rebuild a server so you keep your own copy.
Yes. IMAP carries mail only, but Kerio includes Exchange ActiveSync, which syncs mail, calendar, contacts and tasks over one account on a phone. On a computer, the Kerio Outlook Connector does the same inside Outlook. CalDAV and CardDAV cover other apps.
An email migration tool copies mail directly between the 2 accounts over IMAP. You need your Kerio host and account password for this side, plus the destination account details. Every folder and date stays intact.
If setting this up feels risky or you have many accounts to move, our managed email migration service does the entire job for you.
Other Email Provider Settings
Summary: Kerio Connect Settings at a Glance
- Host: your Kerio server, your Connect Client address
- IMAP port 993, POP3 995, both SSL/TLS
- SMTP port 465 (SSL) or 587 (STARTTLS)
- Username is your full email address
- Sign in with your account password
- App password only when 2FA is on
- Admin console is port 4040, not a mail port
- ActiveSync syncs mail, calendar and contacts