Quick answer: the Mailbox.org IMAP server is imap.mailbox.org on port 993 with SSL/TLS. SMTP is smtp.mailbox.org on 465 (SSL) or 587 (STARTTLS). POP3 is pop3.mailbox.org on 995 with SSL. Sign in with your full main address as the username. If you have two factor turned on, the password in your client must be a mailbox.org app password rather than your login password.
What Changed Recently#
Mailbox.org keeps its servers stable. The moving parts are on the security side, where the login and app password system was refreshed in 2025.
Latest update
Login 2.0 and simpler app passwords. From 2025 mailbox.org rolled out a refreshed two factor system with an easier way to create Email App Passwords. If your account uses two factor, each client needs one of these app passwords, set per protocol for IMAP and SMTP.
Earlier change
Storage is being increased on paid tiers. Mailbox.org announced larger mailbox storage on the Standard and Premium plans during 2026. Existing customers were given until 31 August 2026 to lock in old pricing. Nothing about your server settings changes.
Earlier change
Servers and ports are unchanged. The IMAP, POP3 and SMTP hosts and ports on this page have been steady for years. If a guide shows different values, this page matches the current mailbox.org knowledge base.
Before You Begin#
Two things decide whether your setup works on the first try. Both are about the password, not the servers.
1. Check whether two factor is on
If two factor authentication is off, your normal mailbox.org password works in email clients. If it is on, that password is refused and you need an app password instead. This is the single most common reason a correct password keeps getting rejected.
Where: App password steps below →
2. Use your main address, not an alias
Mailbox.org lets you create aliases, but the username for a client must be your main address. An alias in the username field will fail to authenticate even with the right password.
Where: Your main address is the one you registered
About Mailbox.org Mail#
Mailbox.org is a paid, privacy focused email and groupware service run by the Heinlein Group in Berlin, going back to 2014.
Connecting a client to mailbox.org is standard in most ways. The servers use ordinary subdomains. The ports are the usual encrypted ones. The one detail that decides your setup is two factor. With it off, your normal password works everywhere. With it on, the web login uses a code while email clients switch to a per client app password. Get that right and the rest is routine.
| Service Name | Mailbox.org Mail |
| Owned By | Heinlein Group, Berlin |
| Launched | 2014 |
| Email Domains | @mailbox.org plus alias domains. Custom domains on paid plans |
| Webmail URL | mailbox.org |
| Protocols Supported | IMAP, POP3, SMTP, plus CalDAV and CardDAV |
| App Password Needed | Only when two factor is turned on |
| Storage | Depends on plan. Larger on Standard and Premium |
imap.mailbox.org and smtp.mailbox.org. Your custom address is the username. The servers on this page do not change.
Mailbox.org Webmail Login#
You can always read your mail in a browser. The mailbox.org sign in is at:
When You Need an App Password#
This is the one part of a mailbox.org setup that catches people out. Whether your client uses your normal password or a separate app password depends entirely on one setting: two factor authentication.
| Your account | Password to enter in the client |
|---|---|
| Two factor is off | Your normal mailbox.org password works in IMAP, POP3 and SMTP |
| Two factor is on | Your normal password is refused. Create an Email App Password and use that instead |
How to Create a Mailbox.org App Password
- Sign in to mailbox.org webmail in a browser.
- Open All settings, then Security, then Email app passwords. This is the current path in the mailbox.org knowledge base.
- Create a new password and add a note so you remember which device it is for.
- Tick the protocols it may use, IMAP and SMTP for a normal mail client.
- Generate it, then copy it into your client as the password. Save it somewhere safe, because it is shown once.
Mailbox.org IMAP Settings#
IMAP is the incoming protocol most people should use. It keeps your mail on the server so every device shows the same inbox.
| IMAP Server | imap.mailbox.org | |
| Port | 993 | |
| Encryption | SSL/TLS (required) | |
| Username | Your full email address, including @mailbox.org | |
| Password | Your mailbox.org password. An app password if 2FA is on | |
| Username | Your full main address, not an alias |
Mailbox.org POP3 Settings#
POP3 downloads mail to 1 device. Pick it only if you want a local copy on a single computer. Not sure? See the comparison below.
| POP3 Server | pop3.mailbox.org | |
| Port | 995 | |
| Encryption | SSL/TLS (required) | |
| Username | Your full email address | |
| Password | Same as IMAP. App password when 2FA is on |
Mailbox.org SMTP Settings#
SMTP carries outgoing mail through smtp.mailbox.org. Receiving fine but unable to send points straight at the outgoing server. Nine times out of ten it is authentication left switched off. Sometimes it is the wrong kind of password.
| SMTP Server | smtp.mailbox.org | |
| Port (SSL) | 465 | |
| Port (STARTTLS) | 587 | |
| Encryption | SSL or STARTTLS (required) | |
| Username | Your full main address | |
| Password | Same as incoming, app password when 2FA is on | |
| Authentication | Required. Check "My outgoing server requires authentication" in Outlook. |
Check Mailbox.org IMAP Settings Online#
You don't need to download anything to check Mailbox.org IMAP settings online. This page is the lookup: every value is verified, current and copyable straight from your browser. Not sure your address uses Mailbox.org servers? Type it below and find out instantly.
Does my email address use these settings?
Runs in your browser only. Your address is never sent anywhere or stored.
Want to verify the account itself before configuring an app? Sign in at Mailbox.org webmail, which confirms the account works and shows whether two factor is on. If it is, create an app password for your client. Either way, the tables above have every value.
Look Up IMAP Settings for Any Email Domain#
This page covers Mailbox.org. For every other address, work email on a company domain included, we run a free online lookup database: imapsettings.com.
imapsettings.com
Complete email settings database, by Univik
Enter any email address and get the incoming and outgoing server settings for that domain in 1 step:
Your address is used only to find the settings for that domain. Nothing is stored or shared.
Set Up Mailbox.org in Email Clients#
The servers and ports are always the same. Only the menus differ. Jump to your app:
Outlook (Windows and Mac)
- In Outlook choose File, then Add Account. In new Outlook the same option lives under Settings, then Accounts.
- Enter your main mailbox.org address, open Advanced options and tick let me set up my account manually.
- Choose IMAP and enter
imap.mailbox.orgon993with SSL for incoming, thensmtp.mailbox.orgon465with SSL for outgoing. - Enter your password when Outlook asks. If two factor is on, use an app password here rather than your login password.
- Finish and send a test email to yourself to confirm both directions work.
Apple Mail (macOS)
- Open Mail → Settings → Accounts → Add Account.
- Choose Other Mail Account. Apple has no built in mailbox.org entry.
- Enter your name, main address and password, an app password if 2FA is on, then continue.
- If asked for servers, enter the IMAP and SMTP values from the tables above.
- Enable Mail in the checkbox list and finish.
iPhone and iPad
- Open Settings → Apps → Mail → Mail Accounts → Add Account.
- Tap Other, then Add Mail Account. iOS has no mailbox.org preset.
- Enter your details, using an app password if 2FA is on, then tap Next.
- Keep IMAP selected and fill the incoming and outgoing servers if iOS asks.
- Tap Save and wait for iOS to verify the account.
Android
- Open your mail app (Gmail app, Samsung Email or another) → Add account.
- Choose Other (IMAP) when your provider is not in the list.
- Enter your main address and password. Where automatic setup fails, choose Manual setup and enter the servers above.
- Enter the servers:
imap.mailbox.org993 SSL incoming,smtp.mailbox.org465 SSL outgoing. - Finish setup and pull down to sync your inbox.
Thunderbird
- Open Thunderbird → Account Settings → Account Actions → Add Mail Account.
- Enter your name, main address and password, an app password if 2FA is on, then select Continue.
- Check what Thunderbird detected. Confirm it chose
imap.mailbox.orgwith SSL/TLS rather than a plain fallback. - If detection fails, choose Configure manually and enter the table values above.
- Select Done. Folders sync on first open.
Mailbox.org Webmail Settings#
Those values connect your apps. What follows shapes the mailbox itself. It lives in mailbox.org webmail rather than in any client.
Signature
Set from mailbox.org webmail settings. A signature saved in webmail rides along on browser sent mail only. Each desktop client stores its own, so expect to recreate it per app if you want a match.
Vacation Auto Reply
Set a start and finish date on the auto reply and it ends itself. Because mailbox.org runs it server side, it answers mail while every one of your devices is powered down.
Filters and Folders
Filters created in webmail act on the server, sorting each message before any client pulls it down. A rule living inside Outlook runs only when Outlook is running, so two machines can end up disagreeing on where mail went.
Spam and Blocked Senders
Mailbox.org runs multi level spam and virus filtering. Add senders or whole domains to the block list from webmail. When mail goes missing, check the spam folder in the browser first.
POP3 vs IMAP#
| Feature | IMAP | POP3 |
|---|---|---|
| Where mail lives | On the Mailbox.org server | Downloaded to 1 device |
| Multiple devices | ✅ Everything stays in sync | ❌ Each device sees different mail |
| Sent and deleted mail | ✅ Synced everywhere | ⚠️ Stays only on that device |
| Offline reading | ⚠️ Cached mail only | ✅ Full local copy |
| Server storage used | Yes, counts against your quota | Can be freed after download |
| Best for | Phone + computer, everyday use | Single PC, local archives |
Mailbox.org Settings Worth Knowing#
Mailbox.org publishes settings more readily than hard quotas. The quotas that exist depend on your plan. These are the points that actually shape a client setup:
| IMAP host | imap.mailbox.org, 993 SSL/TLS |
| POP3 host | pop3.mailbox.org, 995 SSL/TLS |
| SMTP host | smtp.mailbox.org, 465 SSL/TLS or 587 STARTTLS |
| App password | Needed only when two factor is on, set per protocol |
| Username | Your full main address, never an alias |
| Mailbox storage | Depends on plan, larger on Standard and Premium |
Troubleshooting Mailbox.org Connections#
On mailbox.org the failures cluster around the password type and the folder mapping. Find your symptom, then the fix.
| Error you see | What it means | Fix |
|---|---|---|
| Endless password prompts | Two factor is on but the client still has your login password | Create an app password, then replace the saved password in the client with it. |
| Login rejected, password is correct | An alias was entered as the username | Use your full main address as the username, never an alias. |
| Sent or Trash folder duplicated | The client did not map special folders | Open the advanced IMAP settings and point Drafts, Sent, Deleted and Archive at the mailbox.org folders, then resync. |
| Cannot send, receiving works | SMTP authentication is off. The password type may also be wrong | Turn on outgoing server requires authentication and use the same password as incoming. |
| Cannot connect to server | Wrong port or encryption | Check IMAP 993 SSL and SMTP 465 SSL. Antivirus suites and VPN apps block these ports often enough to be worth ruling out. |
| Password keeps being asked | 2FA is on and the client has the login password | Replace it with an app password set for IMAP and SMTP. |
| Messages stuck in Outbox | SMTP authentication is off | Enable "outgoing server requires authentication" with the same login as incoming mail. |
Reader Reported Fixes
Turn the two factor question into a yes or no before anything else. If your account has two factor on, no login password will ever work in a client. Create an app password, set it for IMAP and SMTP, then paste that. This single check clears most mailbox.org setup complaints online.
Map the special folders if Sent or Trash misbehaves. Some clients create their own Sent and Trash rather than using the server ones, which leaves duplicates. Open the advanced IMAP settings, point Drafts, Sent, Deleted and Archive at the mailbox.org folders, then sync again.
Moving to Mailbox.org?#
Most people reach mailbox.org from a free provider like Gmail or Outlook.com. That old mail does not follow on its own. An IMAP connection mirrors the current server state and nothing older, so archived mail from before you switched stays put until you deliberately move it.
Set up the mailbox.org side with the values on this page. Server imap.mailbox.org, port 993 with SSL, your main address as the username. Add an app password if two factor is on. For the old account, use its own IMAP details.
Copy the old mail over. The Univik Email Migration Tool copies every folder from the old mailbox into mailbox.org. Enter the mailbox.org IMAP details for the destination and the old provider details for the source, then let it run.
Keep a copy of your own. Take a backup before you shut the old account. Deleting a free mailbox is normally final, with no route back to the messages.
Rather not do it yourself? Our Email Migration Services team plans and runs the whole transfer and checks that every folder arrived.
Use These Settings in Univik Email Backup#
The same IMAP settings above let you download your complete Mailbox.org mailbox to your computer. Univik Email Backup saves everything as PST, MBOX, EML or PDF files you keep forever, even if the account closes.
- Download Univik Email Backup and install it on Windows.
- Select Mailbox.org from the source list. If it isn't listed by name, choose IMAP.
- Sign in with your full main address and your password. Use an app password if two factor is on.
- If the tool asks for server details, use
imap.mailbox.orgwith port993and SSL from the IMAP table above. - Pick a saving format and folder, then start the backup. Large mailboxes download in the background.
Email Settings Glossary#
IMAP
Internet Message Access Protocol. Reads mail that stays on the server, so all your devices see the same inbox, folders and read status.
POP3
Post Office Protocol version 3. Downloads mail to 1 device and can remove it from the server. Older method, still useful for local archives.
SMTP
Simple Mail Transfer Protocol. Sends your outgoing mail. Every account needs it next to IMAP or POP3, which only receive.
SSL / TLS / STARTTLS
Encryption for the connection. SSL/TLS encrypts from the start (ports 993, 995, 465). STARTTLS upgrades a plain connection (port 587).
App password
A separate password for one client, used on mailbox.org when two factor is on. It carries only the rights you grant and can be revoked on its own.
OAuth
Sign in through the provider's own window instead of typing a password into the app. The modern method most providers are moving to.
How We Verify These Settings#
Univik has built email backup, migration and converter software since 2013. Our tools sign in to Mailbox.org over IMAP and SMTP every day for thousands of users, so a changed server, port or login rule shows up in our connection logs before most guides notice it.
We confirm each value two ways. Univik Email Backup opens a real IMAP and SMTP session to the servers. Every field is then checked against the mailbox.org knowledge base article by article. We re verify after any provider announcement and at least once a quarter.
Found something that no longer matches what Mailbox.org shows you? Tell us and we will retest and update the page, with the change logged in what changed recently.
Help & Support
Frequently Asked Questions
Use imap.mailbox.org on port 993 with SSL/TLS. Sign in with your full main address as the username. The password is your normal mailbox.org password. Use an app password if two factor is on. The full table is in the IMAP settings section.
The most likely cause is two factor. When it is on, mailbox.org refuses your login password in clients and expects an app password instead. Create one, tick IMAP and SMTP, then paste that. If two factor is off, check you used your main address and not an alias.
IMAP for almost everyone, since mailbox.org is built around server side mail, filters and PGP. POP3 suits a single computer where you want a local download. It can delete server copies by default, so turn on leave a copy first. Full comparison here.
Yes. The hosts, ports and encryption never change between devices. Only the menus differ, which is what the client setup guides cover. If two factor is on, each device needs its own app password.
No. App passwords are only needed when two factor is switched on. With two factor off, your normal mailbox.org password works in every client. With it on, create an app password under All settings, Security, Email app passwords, then use that. Each one can be revoked on its own.
Yes. The connection is encrypted on ports 993 and 465. If you turn on two factor, each client uses its own app password, so a lost device can be cut off by deleting that one password without touching the rest.
An email client with IMAP downloads mail as it syncs, but a dedicated backup tool is faster and saves standard files you can open anywhere. See how to back up your Mailbox.org mailbox. If you already exported files in another format, an email converter changes them to PST, PDF or whatever your new app opens.
The common trigger on mailbox.org is turning on two factor. The moment you do, the login password stops working in clients and each one needs an app password. Check what changed recently, then create app passwords for your devices.
An email migration tool copies mail directly between the 2 accounts over IMAP. You need the Mailbox.org IMAP settings and your password for this side, an app password if two factor is on, plus the same details for the destination account. Every folder, label and date stays intact.
If setting this up feels risky or you have many accounts to move, our managed email migration service does the entire job for you.
Other Email Provider Settings
Summary: Mailbox.org Settings at a Glance
- IMAP: imap.mailbox.org, port 993, SSL/TLS
- POP3: pop3.mailbox.org, port 995, SSL/TLS
- SMTP: smtp.mailbox.org, port 465 or 587
- Username: your full main address
- App password needed only with 2FA on
- Pick IMAP for phone + computer sync
- Encrypted ports only, SSL/TLS recommended
- Custom domains use the same servers