Email Settings Email Settings Guide

Mailbox.org Email Settings: IMAP, POP3 and SMTP

Every server address and port for Mailbox.org in Outlook, Apple Mail, Thunderbird or your phone, taken from the mailbox.org knowledge base. The one thing that trips people up is the password: with two factor turned on, email clients need an app password, not your normal one. Copy each value with 1 tap.

Tested July 27, 2026 1 Tap Copy App Password with 2FA

Mailbox.org Quick Settings

IMAP Server imap.mailbox.org
IMAP Port 993 (SSL/TLS)
SMTP Server smtp.mailbox.org
SMTP Port 465 (SSL) / 587 (STARTTLS)
POP3 Server pop3.mailbox.org
Username Your full email address

Quick answer: the Mailbox.org IMAP server is imap.mailbox.org on port 993 with SSL/TLS. SMTP is smtp.mailbox.org on 465 (SSL) or 587 (STARTTLS). POP3 is pop3.mailbox.org on 995 with SSL. Sign in with your full main address as the username. If you have two factor turned on, the password in your client must be a mailbox.org app password rather than your login password.

Every setting on this page is verified with live IMAP and SMTP connections from Univik email software. We have built email backup and converter tools since 2013, so we set these servers up every day. See what changed →

What Changed Recently#

Mailbox.org keeps its servers stable. The moving parts are on the security side, where the login and app password system was refreshed in 2025.

Latest update

Login 2.0 and simpler app passwords. From 2025 mailbox.org rolled out a refreshed two factor system with an easier way to create Email App Passwords. If your account uses two factor, each client needs one of these app passwords, set per protocol for IMAP and SMTP.

Earlier change

Storage is being increased on paid tiers. Mailbox.org announced larger mailbox storage on the Standard and Premium plans during 2026. Existing customers were given until 31 August 2026 to lock in old pricing. Nothing about your server settings changes.

Earlier change

Servers and ports are unchanged. The IMAP, POP3 and SMTP hosts and ports on this page have been steady for years. If a guide shows different values, this page matches the current mailbox.org knowledge base.

Current status: IMAP, POP3 and SMTP all work today. Use your normal password if two factor is off. Use an app password if it is on.

Before You Begin#

Two things decide whether your setup works on the first try. Both are about the password, not the servers.

1. Check whether two factor is on

If two factor authentication is off, your normal mailbox.org password works in email clients. If it is on, that password is refused and you need an app password instead. This is the single most common reason a correct password keeps getting rejected.

Where: App password steps below →

2. Use your main address, not an alias

Mailbox.org lets you create aliases, but the username for a client must be your main address. An alias in the username field will fail to authenticate even with the right password.

Where: Your main address is the one you registered

About Mailbox.org Mail#

Mailbox.org is a paid, privacy focused email and groupware service run by the Heinlein Group in Berlin, going back to 2014.

Connecting a client to mailbox.org is standard in most ways. The servers use ordinary subdomains. The ports are the usual encrypted ones. The one detail that decides your setup is two factor. With it off, your normal password works everywhere. With it on, the web login uses a code while email clients switch to a per client app password. Get that right and the rest is routine.

Service NameMailbox.org Mail
Owned ByHeinlein Group, Berlin
Launched2014
Email Domains@mailbox.org plus alias domains. Custom domains on paid plans
Webmail URLmailbox.org
Protocols SupportedIMAP, POP3, SMTP, plus CalDAV and CardDAV
App Password NeededOnly when two factor is turned on
StorageDepends on plan. Larger on Standard and Premium
Custom domains use the same servers: if you host your own domain on mailbox.org, it still connects through imap.mailbox.org and smtp.mailbox.org. Your custom address is the username. The servers on this page do not change.

Mailbox.org Webmail Login#

You can always read your mail in a browser. The mailbox.org sign in is at:

Webmail

mailbox.org

Account Security

mailbox.org

Password Recovery

kb.mailbox.org

Watch out for fake support pages. A few of the pages ranking here lead with a support phone number and paid help offer. Neither mailbox.org nor Univik needs you to phone anyone to type in a server name. Every value here is free.

When You Need an App Password#

This is the one part of a mailbox.org setup that catches people out. Whether your client uses your normal password or a separate app password depends entirely on one setting: two factor authentication.

Your accountPassword to enter in the client
Two factor is offYour normal mailbox.org password works in IMAP, POP3 and SMTP
Two factor is onYour normal password is refused. Create an Email App Password and use that instead
Why this happens: two factor protects the web login with a one time code, but IMAP, POP3 and SMTP cannot ask for that code. Instead mailbox.org gives each client its own app password. That way a phone can be revoked on its own without touching your other devices or your main password.

How to Create a Mailbox.org App Password

  1. Sign in to mailbox.org webmail in a browser.
  2. Open All settings, then Security, then Email app passwords. This is the current path in the mailbox.org knowledge base.
  3. Create a new password and add a note so you remember which device it is for.
  4. Tick the protocols it may use, IMAP and SMTP for a normal mail client.
  5. Generate it, then copy it into your client as the password. Save it somewhere safe, because it is shown once.
Good to know: app passwords carry only the rights you grant, so one limited to IMAP and SMTP cannot touch the rest of your account. You can revoke any single one without changing your main password. If you ever turn two factor off again, your normal password starts working in clients once more.
Mailbox.org password depends on two factor Two factor on your account? Off Your normal mailbox.org password works in clients Nothing extra to do On Normal password is refused Create an app password and use that instead
The whole setup turns on one question. Two factor off means your normal password works. Two factor on means each client needs its own app password.
Where to create a mailbox.org app password All settings in webmail Security Email app passwords Tick IMAP and SMTP Generate password Only needed when two factor is on. The password shows once, so copy it.
The path to an app password. Grant it only IMAP and SMTP. Copy it right away, since it appears once.

Mailbox.org IMAP Settings#

IMAP is the incoming protocol most people should use. It keeps your mail on the server so every device shows the same inbox.

IMAP Serverimap.mailbox.org
Port993
EncryptionSSL/TLS (required)
UsernameYour full email address, including @mailbox.org
PasswordYour mailbox.org password. An app password if 2FA is on
UsernameYour full main address, not an alias
Mailbox.org server names and ports IMAP imap.mailbox.org 993 SSL POP3 pop3.mailbox.org 995 SSL SMTP smtp.mailbox.org 465 SSL Each protocol has its own subdomain. Username is your full main address.
Three standard subdomained hosts, one per protocol, all on their encrypted ports.

Mailbox.org POP3 Settings#

POP3 downloads mail to 1 device. Pick it only if you want a local copy on a single computer. Not sure? See the comparison below.

POP3 Serverpop3.mailbox.org
Port995
EncryptionSSL/TLS (required)
UsernameYour full email address
PasswordSame as IMAP. App password when 2FA is on
POP3 can remove mail from the server. Many clients delete each message once it downloads. If you want your mail to stay in webmail and on other devices, turn on leave a copy on the server. Better still, use IMAP.

Mailbox.org SMTP Settings#

Use the encrypted ports: the simplest setup is SSL/TLS on 993 for IMAP, 995 for POP3 and 465 for SMTP. Port 143 and 110 work only with STARTTLS, never in the clear. If a client filled in a plain port with no encryption, switch it to the SSL/TLS port above.

SMTP carries outgoing mail through smtp.mailbox.org. Receiving fine but unable to send points straight at the outgoing server. Nine times out of ten it is authentication left switched off. Sometimes it is the wrong kind of password.

SMTP Serversmtp.mailbox.org
Port (SSL)465
Port (STARTTLS)587
EncryptionSSL or STARTTLS (required)
UsernameYour full main address
PasswordSame as incoming, app password when 2FA is on
AuthenticationRequired. Check "My outgoing server requires authentication" in Outlook.
Mailbox.org ports and encryption reference Ports and encryption at a glance Protocol SSL/TLS port STARTTLS port IMAP 993 143 POP3 995 110 SMTP 465 587 The SSL/TLS ports on the left are the simplest choice
Every mailbox.org port in one place. Pick the SSL/TLS column unless your client only offers STARTTLS.

Check Mailbox.org IMAP Settings Online#

You don't need to download anything to check Mailbox.org IMAP settings online. This page is the lookup: every value is verified, current and copyable straight from your browser. Not sure your address uses Mailbox.org servers? Type it below and find out instantly.

Does my email address use these settings?

Runs in your browser only. Your address is never sent anywhere or stored.

Want to verify the account itself before configuring an app? Sign in at Mailbox.org webmail, which confirms the account works and shows whether two factor is on. If it is, create an app password for your client. Either way, the tables above have every value.

Look Up IMAP Settings for Any Email Domain#

This page covers Mailbox.org. For every other address, work email on a company domain included, we run a free online lookup database: imapsettings.com.

imapsettings.com

Complete email settings database, by Univik

Check IMAP settings online →

Enter any email address and get the incoming and outgoing server settings for that domain in 1 step:

Incoming server: hostname, port, SSL/TLS and username format
Outgoing server: SMTP hostname, port and encryption

Your address is used only to find the settings for that domain. Nothing is stored or shared.

Set Up Mailbox.org in Email Clients#

The servers and ports are always the same. Only the menus differ. Jump to your app:

Outlook (Windows and Mac)

  1. In Outlook choose File, then Add Account. In new Outlook the same option lives under Settings, then Accounts.
  2. Enter your main mailbox.org address, open Advanced options and tick let me set up my account manually.
  3. Choose IMAP and enter imap.mailbox.org on 993 with SSL for incoming, then smtp.mailbox.org on 465 with SSL for outgoing.
  4. Enter your password when Outlook asks. If two factor is on, use an app password here rather than your login password.
  5. Finish and send a test email to yourself to confirm both directions work.

Apple Mail (macOS)

  1. Open Mail → Settings → Accounts → Add Account.
  2. Choose Other Mail Account. Apple has no built in mailbox.org entry.
  3. Enter your name, main address and password, an app password if 2FA is on, then continue.
  4. If asked for servers, enter the IMAP and SMTP values from the tables above.
  5. Enable Mail in the checkbox list and finish.

iPhone and iPad

  1. Open Settings → Apps → Mail → Mail Accounts → Add Account.
  2. Tap Other, then Add Mail Account. iOS has no mailbox.org preset.
  3. Enter your details, using an app password if 2FA is on, then tap Next.
  4. Keep IMAP selected and fill the incoming and outgoing servers if iOS asks.
  5. Tap Save and wait for iOS to verify the account.

Android

  1. Open your mail app (Gmail app, Samsung Email or another) → Add account.
  2. Choose Other (IMAP) when your provider is not in the list.
  3. Enter your main address and password. Where automatic setup fails, choose Manual setup and enter the servers above.
  4. Enter the servers: imap.mailbox.org 993 SSL incoming, smtp.mailbox.org 465 SSL outgoing.
  5. Finish setup and pull down to sync your inbox.

Thunderbird

  1. Open Thunderbird → Account Settings → Account Actions → Add Mail Account.
  2. Enter your name, main address and password, an app password if 2FA is on, then select Continue.
  3. Check what Thunderbird detected. Confirm it chose imap.mailbox.org with SSL/TLS rather than a plain fallback.
  4. If detection fails, choose Configure manually and enter the table values above.
  5. Select Done. Folders sync on first open.
Mailbox.org account form filled in correctly Add Mail Account Incoming (IMAP) imap.mailbox.org 993 SSL Outgoing (SMTP) smtp.mailbox.org 465 SSL Username your full main address
A correctly filled mailbox.org form. Subdomained servers on SSL ports, your main address as the username, plus the right password type for your account.

Mailbox.org Webmail Settings#

Those values connect your apps. What follows shapes the mailbox itself. It lives in mailbox.org webmail rather than in any client.

Signature

Set from mailbox.org webmail settings. A signature saved in webmail rides along on browser sent mail only. Each desktop client stores its own, so expect to recreate it per app if you want a match.

Vacation Auto Reply

Set a start and finish date on the auto reply and it ends itself. Because mailbox.org runs it server side, it answers mail while every one of your devices is powered down.

Filters and Folders

Filters created in webmail act on the server, sorting each message before any client pulls it down. A rule living inside Outlook runs only when Outlook is running, so two machines can end up disagreeing on where mail went.

Spam and Blocked Senders

Mailbox.org runs multi level spam and virus filtering. Add senders or whole domains to the block list from webmail. When mail goes missing, check the spam folder in the browser first.

Map special folders on mailbox.org Duplicate Sent and Trash folders appear Advanced IMAP map the folders One Sent, one Trash, one Archive Map Drafts, Sent, Deleted and Archive to the mailbox.org folders.
If a client makes its own Sent or Trash, map the special folders in advanced IMAP settings so everything lands in one place.

POP3 vs IMAP#

FeatureIMAPPOP3
Where mail livesOn the Mailbox.org serverDownloaded to 1 device
Multiple devices✅ Everything stays in sync❌ Each device sees different mail
Sent and deleted mail✅ Synced everywhere⚠️ Stays only on that device
Offline reading⚠️ Cached mail only✅ Full local copy
Server storage usedYes, counts against your quotaCan be freed after download
Best forPhone + computer, everyday useSingle PC, local archives
Our verdict: IMAP for almost everyone, since mailbox.org is built around server side mail, filters and PGP. Reach for POP3 only if you want a local download on one machine. For a permanent offline archive a backup tool beats both protocols.
IMAP syncs, POP3 can delete on mailbox.org IMAP mail stays on the server phone, laptop and web stay in sync, with filters POP3 downloads to one device can delete server copy turn on leave a copy first
IMAP keeps everything in sync, which suits mailbox.org filters and PGP. POP3 can remove server copies unless you switch on leave a copy on the server.

Mailbox.org Settings Worth Knowing#

Mailbox.org publishes settings more readily than hard quotas. The quotas that exist depend on your plan. These are the points that actually shape a client setup:

IMAP hostimap.mailbox.org, 993 SSL/TLS
POP3 hostpop3.mailbox.org, 995 SSL/TLS
SMTP hostsmtp.mailbox.org, 465 SSL/TLS or 587 STARTTLS
App passwordNeeded only when two factor is on, set per protocol
UsernameYour full main address, never an alias
Mailbox storageDepends on plan, larger on Standard and Premium
On sending limits and trial accounts: mailbox.org does not publish a fixed daily send limit. It watches account age and recent volume and blocks only when a burst looks like abuse. One thing is firm though: an unpaid trial account cannot send to outside addresses at all. It is capped at around ten mails a day to mailbox.org addresses for testing. Sending externally starts once you pay for a plan.

Troubleshooting Mailbox.org Connections#

On mailbox.org the failures cluster around the password type and the folder mapping. Find your symptom, then the fix.

Error you seeWhat it meansFix
Endless password prompts Two factor is on but the client still has your login password Create an app password, then replace the saved password in the client with it.
Login rejected, password is correct An alias was entered as the username Use your full main address as the username, never an alias.
Sent or Trash folder duplicated The client did not map special folders Open the advanced IMAP settings and point Drafts, Sent, Deleted and Archive at the mailbox.org folders, then resync.
Cannot send, receiving works SMTP authentication is off. The password type may also be wrong Turn on outgoing server requires authentication and use the same password as incoming.
Cannot connect to server Wrong port or encryption Check IMAP 993 SSL and SMTP 465 SSL. Antivirus suites and VPN apps block these ports often enough to be worth ruling out.
Password keeps being asked 2FA is on and the client has the login password Replace it with an app password set for IMAP and SMTP.
Messages stuck in Outbox SMTP authentication is off Enable "outgoing server requires authentication" with the same login as incoming mail.

Reader Reported Fixes

Turn the two factor question into a yes or no before anything else. If your account has two factor on, no login password will ever work in a client. Create an app password, set it for IMAP and SMTP, then paste that. This single check clears most mailbox.org setup complaints online.

Map the special folders if Sent or Trash misbehaves. Some clients create their own Sent and Trash rather than using the server ones, which leaves duplicates. Open the advanced IMAP settings, point Drafts, Sent, Deleted and Archive at the mailbox.org folders, then sync again.

Four checks for a failing mailbox.org connection 1 2FA on? app password for the client 2 Username is main address not an alias 3 Hosts are the mailbox.org subdomains 4 Cannot send? SMTP auth on for outgoing Most mailbox.org failures are the password type at step 1
Work through these in order. The two factor password type at step one accounts for most mailbox.org connection failures.

Moving to Mailbox.org?#

Most people reach mailbox.org from a free provider like Gmail or Outlook.com. That old mail does not follow on its own. An IMAP connection mirrors the current server state and nothing older, so archived mail from before you switched stays put until you deliberately move it.

Set up the mailbox.org side with the values on this page. Server imap.mailbox.org, port 993 with SSL, your main address as the username. Add an app password if two factor is on. For the old account, use its own IMAP details.

Copy the old mail over. The Univik Email Migration Tool copies every folder from the old mailbox into mailbox.org. Enter the mailbox.org IMAP details for the destination and the old provider details for the source, then let it run.

Keep a copy of your own. Take a backup before you shut the old account. Deleting a free mailbox is normally final, with no route back to the messages.

Rather not do it yourself? Our Email Migration Services team plans and runs the whole transfer and checks that every folder arrived.

Use These Settings in Univik Email Backup#

The same IMAP settings above let you download your complete Mailbox.org mailbox to your computer. Univik Email Backup saves everything as PST, MBOX, EML or PDF files you keep forever, even if the account closes.

  1. Download Univik Email Backup and install it on Windows.
  2. Select Mailbox.org from the source list. If it isn't listed by name, choose IMAP.
  3. Sign in with your full main address and your password. Use an app password if two factor is on.
  4. If the tool asks for server details, use imap.mailbox.org with port 993 and SSL from the IMAP table above.
  5. Pick a saving format and folder, then start the backup. Large mailboxes download in the background.
Why back up before switching providers: POP3 only grabs the inbox and vacation replies to a closed account bounce. A full IMAP backup keeps every folder, attachment and date stamp in files any email app can open later. Moving to a new account instead of archiving? Use the email migration tool to copy mail directly between accounts.

Email Settings Glossary#

IMAP

Internet Message Access Protocol. Reads mail that stays on the server, so all your devices see the same inbox, folders and read status.

POP3

Post Office Protocol version 3. Downloads mail to 1 device and can remove it from the server. Older method, still useful for local archives.

SMTP

Simple Mail Transfer Protocol. Sends your outgoing mail. Every account needs it next to IMAP or POP3, which only receive.

SSL / TLS / STARTTLS

Encryption for the connection. SSL/TLS encrypts from the start (ports 993, 995, 465). STARTTLS upgrades a plain connection (port 587).

App password

A separate password for one client, used on mailbox.org when two factor is on. It carries only the rights you grant and can be revoked on its own.

OAuth

Sign in through the provider's own window instead of typing a password into the app. The modern method most providers are moving to.

How We Verify These Settings#

Univik has built email backup, migration and converter software since 2013. Our tools sign in to Mailbox.org over IMAP and SMTP every day for thousands of users, so a changed server, port or login rule shows up in our connection logs before most guides notice it.

We confirm each value two ways. Univik Email Backup opens a real IMAP and SMTP session to the servers. Every field is then checked against the mailbox.org knowledge base article by article. We re verify after any provider announcement and at least once a quarter.

Found something that no longer matches what Mailbox.org shows you? Tell us and we will retest and update the page, with the change logged in what changed recently.

 Help & Support

Frequently Asked Questions

Use imap.mailbox.org on port 993 with SSL/TLS. Sign in with your full main address as the username. The password is your normal mailbox.org password. Use an app password if two factor is on. The full table is in the IMAP settings section.

The most likely cause is two factor. When it is on, mailbox.org refuses your login password in clients and expects an app password instead. Create one, tick IMAP and SMTP, then paste that. If two factor is off, check you used your main address and not an alias.

IMAP for almost everyone, since mailbox.org is built around server side mail, filters and PGP. POP3 suits a single computer where you want a local download. It can delete server copies by default, so turn on leave a copy first. Full comparison here.

Yes. The hosts, ports and encryption never change between devices. Only the menus differ, which is what the client setup guides cover. If two factor is on, each device needs its own app password.

No. App passwords are only needed when two factor is switched on. With two factor off, your normal mailbox.org password works in every client. With it on, create an app password under All settings, Security, Email app passwords, then use that. Each one can be revoked on its own.

Yes. The connection is encrypted on ports 993 and 465. If you turn on two factor, each client uses its own app password, so a lost device can be cut off by deleting that one password without touching the rest.

An email client with IMAP downloads mail as it syncs, but a dedicated backup tool is faster and saves standard files you can open anywhere. See how to back up your Mailbox.org mailbox. If you already exported files in another format, an email converter changes them to PST, PDF or whatever your new app opens.

The common trigger on mailbox.org is turning on two factor. The moment you do, the login password stops working in clients and each one needs an app password. Check what changed recently, then create app passwords for your devices.

An email migration tool copies mail directly between the 2 accounts over IMAP. You need the Mailbox.org IMAP settings and your password for this side, an app password if two factor is on, plus the same details for the destination account. Every folder, label and date stays intact.

If setting this up feels risky or you have many accounts to move, our managed email migration service does the entire job for you.

Other Email Provider Settings

Summary: Mailbox.org Settings at a Glance

  • IMAP: imap.mailbox.org, port 993, SSL/TLS
  • POP3: pop3.mailbox.org, port 995, SSL/TLS
  • SMTP: smtp.mailbox.org, port 465 or 587
  • Username: your full main address
  • App password needed only with 2FA on
  • Pick IMAP for phone + computer sync
  • Encrypted ports only, SSL/TLS recommended
  • Custom domains use the same servers