Email Settings Email Settings Guide

Outlook.com Email Settings: IMAP, SMTP and OAuth

Every server, port and sign in step for outlook.com, hotmail.com, live.com and msn.com addresses. Copy each value with 1 tap. Read the enable step first, because Microsoft ships POP and IMAP switched off.

Tested with live connections 1 Tap Copy Enable Step First

Outlook.com Quick Settings

IMAP Server outlook.office365.com
IMAP Port 993 (SSL/TLS)
SMTP Server smtp-mail.outlook.com
SMTP Port 587 (STARTTLS)
POP3 Server outlook.office365.com
Username Your full email address

Quick answer: the Outlook.com IMAP and POP server is outlook.office365.com, on ports 993 and 995 with SSL. SMTP is smtp-mail.outlook.com on port 587 with STARTTLS. Two things trip people before any of that matters: POP and IMAP ship switched off and Microsoft now requires modern authentication rather than a typed password.

Taken from Microsoft's published settings page and confirmed by connecting. Univik tools have signed in to outlook.office365.com through every authentication change Microsoft has made since 2013. See what changed →

What Changed Recently#

Outlook.com has moved further from typed passwords than any other consumer provider. If a guide tells you to paste a password into an IMAP field, it was written for a version of Outlook.com that no longer exists.

Latest update

Modern authentication is now the documented method for POP, IMAP and SMTP. Microsoft's own settings page lists OAuth2 against all 3 protocols. An app that cannot open a Microsoft sign in window has no supported way in. That is why so many older clients and scripts died quietly instead of showing a useful error.

The basic auth retirement

Microsoft support now answers SMTP basic auth questions with a flat no. Attempts return 5.7.139 Authentication unsuccessful, basic authentication is disabled and Microsoft's engineers state that applies even when an app password is used. That sits awkwardly beside Microsoft's own settings page, which still mentions app passwords for smart devices. The password section untangles which advice applies to you.

The Gmail change

Gmail stopped pulling Outlook.com mail across. Google removed the POP fetching that let Gmail collect outside accounts, so an Outlook.com address read inside Gmail just stopped updating. Mail already imported stays put. Connect the account directly with the settings below or move it properly if Gmail is where you actually read.

Current status: POP, IMAP and SMTP all work, on the servers below, from any client that supports a Microsoft sign in. The access switch has to be on first and that catches more people than the servers ever will.

Before You Begin#

Outlook.com puts 2 gates in front of you and neither is a server value. Clear both and the rest takes 5 minutes.

1. Switch POP or IMAP on

Microsoft ships both protocols disabled. Your client connects to an account that is refusing the protocol and reports something unhelpful about the server or password instead.

Where: The 3 step fix below →

2. Pick a client that can sign in to Microsoft

Modern authentication means a Microsoft window opens and you approve access there. A client that only offers a plain password box has no supported route, whatever you type into it.

Where: Which password below →

About Outlook.com#

Outlook.com is Microsoft's consumer email service and it is the same mailbox behind addresses ending in outlook.com, hotmail.com, live.com and msn.com.

Those 4 domains carry decades of naming history and no technical difference at all. What does differ is Microsoft's business side. A Microsoft 365 work mailbox looks similar and shares the incoming server. It sends through a different host though. It also answers to an administrator who can switch protocols off entirely. This page is about the consumer service.

Service NameOutlook.com, previously Hotmail
Owned ByMicrosoft
Email Domains@outlook.com, @hotmail.com, @live.com, @msn.com and country variants
Webmail URLoutlook.com
Protocols SupportedIMAP, POP3 and SMTP, all switched off until you enable them
AuthenticationOAuth2, described by Microsoft as Modern Auth
Incoming Serveroutlook.office365.com for both IMAP and POP
Outgoing Serversmtp-mail.outlook.com, a different host from incoming

Outlook.com Webmail Login#

Three pages between them fix almost every Outlook.com connection problem:

Webmail

outlook.com

The Access Switch

Settings → Mail → Forwarding and IMAP

Recent Activity

account.live.com/activity

That third page matters more than it looks. Microsoft's security layer can flag a brand new mail client as a suspicious sign in and block it silently, with no explanation reaching your email app. Recent activity is where you approve it and it is the fix for a connection that fails even though every value is right.

Turn On POP or IMAP First#

Microsoft ships every Outlook.com account with POP and IMAP switched off. Not restricted, not limited, off. Your email client dials a number that nobody is answering, then reports whatever generic failure it has to hand, which is usually about the password. This step takes 30 seconds and prevents an hour of blaming your settings.

  1. Open Settings in Outlook.com on the web, then Mail, then Forwarding and IMAP. Microsoft relabels this screen from time to time, so if you see Sync email instead, that is the same place.
  2. Under POP and IMAP, turn on either "Let devices and apps use POP" or "Let devices and apps use IMAP", depending on which your client will use.
  3. Select Save and give it a moment before you try connecting.
The Outlook.com switch that has to be on Outlook.com ships with POP and IMAP disabled. With the setting off, an email client using correct servers and a correct password is refused and usually reports a password or server error. Turning on the setting under Settings, Mail, Forwarding and IMAP lets the same client connect without changing anything else. Switch off, the default Servers correct Sign in correct Still refused and blamed on your password Switch on Nothing else changes Same servers, same sign in The client connects Settings → Mail → Forwarding and IMAP
The 30 second step that explains most Outlook.com setup failures.
Why the IMAP switch reverts on a brand new account On a freshly created Outlook.com account, turning IMAP on and saving can appear to work while the setting reverts after signing out. Microsoft applies stricter controls to new mailboxes until they build reputation. Signing in through webmail normally for a few days, then setting it again, is what makes it persist. New account created today You switch IMAP on and save It reverts next time you look A few days on it sticks This is not something you are doing wrong Microsoft holds new mailboxes to stricter rules while they build reputation Use webmail for a few days, then set it again
The new account trap that sends people through the same settings screen a dozen times.
Brand new account and the switch keeps turning itself off? That is a known limitation rather than a mistake you are making. Microsoft applies stricter controls to freshly created mailboxes, so the IMAP setting can refuse to persist for the first few days while the account builds reputation. Sign in through webmail normally for a few days, then set it again. Nothing you change in the browser or the client will speed it up.
Enabled it and still refused? Microsoft may have flagged the new connection as suspicious. Go to account.live.com/activity, find the session that matches when your client failed, expand it and choose "This was me". Then try again.

Outlook.com IMAP Settings#

IMAP keeps mail on Microsoft servers so every device shows the same mailbox. Note the hostname: incoming uses outlook.office365.com, which surprises people who expect it to say outlook.com.

Old Outlook.com hostnames that no longer answer Hostnames such as imap-mail.outlook.com and imap.mail.outlook.com appear throughout older guides and forum posts but no longer respond. The current incoming server for both IMAP and POP is outlook.office365.com. Outgoing is smtp-mail.outlook.com. Still printed in old guides imap-mail.outlook.com imap.mail.outlook.com pop3.live.com These do not answer any more What to use instead Incoming, IMAP and POP outlook.office365.com Outgoing smtp-mail.outlook.com Both current, both documented A server not responding usually means the hostname retired, not that Outlook.com is down
Half the Outlook.com guides online still print servers that stopped answering years ago.
IMAP Serveroutlook.office365.com
Port993
EncryptionSSL/TLS (required)
UsernameYour full address, whether it ends @outlook.com, @hotmail.com, @live.com or @msn.com
AuthenticationOAuth2, called Modern Auth by Microsoft. See which password
AuthenticationRequired

Outlook.com POP3 Settings#

POP3 downloads mail to 1 device and uses the same hostname as IMAP, just a different port. It has its own switch in webmail, so turning IMAP on does not turn POP on. Not sure which you need? See the comparison below.

POP3 Serveroutlook.office365.com
Port995
EncryptionSSL/TLS (required)
UsernameYour full email address
AuthenticationOAuth2 in a Microsoft sign in window. See which password
Careful with POP3 delete settings. Some clients clear the server copy as they collect. Tick the option to keep mail on the server or POP empties outlook.com as it collects.

Outlook.com SMTP Settings#

SSL only: Outlook.com refuses unencrypted connections, so ports 143 and 110 never work here. Check what your client filled in before assuming the server name is wrong.

SMTP handles outgoing mail and this is the 1 place Outlook.com changes hostname. Incoming runs on outlook.office365.com while outgoing runs on smtp-mail.outlook.com. Microsoft's own settings page carries a line saying incoming and outgoing servers are the same, which its own table then contradicts. Follow the table, not the note.

SMTP Serversmtp-mail.outlook.com
Port587 with STARTTLS, the only combination Microsoft documents
Microsoft 365 work accountsSend through smtp.office365.com instead
EncryptionSSL or STARTTLS (required)
UsernameYour full email address
PasswordSame as incoming mail
AuthenticationRequired. Outlook.com refuses unauthenticated sending, so leave that box ticked.

Check Outlook.com IMAP Settings Online#

Every current Outlook.com value is on this page already, where every value is verified and copies in 1 tap. Hotmail, Live and MSN addresses all land here too, so check yours below if you are unsure.

Does my email address use these settings?

Runs in your browser only. Your address is never sent anywhere or stored.

Two checks prove the account is ready. Sign in at outlook.com, then open Settings → Mail → Forwarding and IMAP and confirm the protocol switch is on. Clear both and any modern client will connect.

Look Up IMAP Settings for Any Email Domain#

These tables cover the 4 Outlook.com consumer domains. Setting up an address that is not a Microsoft one at the same time? our free lookup at imapsettings.com will find it.

imapsettings.com

Complete email settings database, by Univik

Check IMAP settings online →

Enter any email address and get the incoming and outgoing server settings for that domain in 1 step:

Incoming server: hostname, port, SSL/TLS and username format
Outgoing server: SMTP hostname, port and encryption

Your address is used only to find the settings for that domain. Nothing is stored or shared.

Which Password Does Outlook.com Want?#

This is where Outlook.com differs sharply from every other provider and where Microsoft's own documentation pulls in 2 directions. Worth reading before you go hunting for a code to paste.

Which clients can still reach Outlook.com A client that opens a Microsoft sign in window uses modern authentication and connects normally. A client offering only a plain password box has no supported route, because modern authentication cannot happen inside a text field. Devices such as scanners and cameras sit in between, with Microsoft documentation pointing at app passwords while Microsoft support says basic authentication is disabled. Adding Outlook.com to an app Opens a Microsoft sign in window Outlook, Apple Mail, Thunderbird, phone apps Connects A device, not an app scanners, cameras, office printers Microsoft says both things. Test it Plain password box and nothing else older clients, scripts, anything pre OAuth No supported route Modern authentication cannot happen inside a text field
Why the fix is often a different client rather than a different password.
Your clientWhat happensWhat to do
Opens a Microsoft sign in window✓ SupportedSign in there and approve access. Nothing to paste.
Only offers a plain password box✗ No supported routeModern authentication cannot happen in a text field. Change client or use webmail.
A device rather than an app, like a camera or scannerCheck firstMicrosoft's settings page still points these at an app password. Its support engineers say basic authentication is disabled. Test before relying on it.
Microsoft says both things, so here is the honest version. The official settings page lists OAuth2 for all 3 protocols, then adds that an app password may be needed if your password is not recognised or you are connecting a smart device. Meanwhile Microsoft's support answers state plainly that basic authentication, app passwords included, is disabled for Outlook.com SMTP and returns error 5.7.139. Both come from Microsoft. Treat modern authentication as the route that is going to keep working and app passwords as a fallback that may already be gone for your account.

Set Up Outlook.com in Email Clients#

The right move in most clients is to pick Outlook or Microsoft by name, which opens the sign in window and handles everything. Manual entry is the fallback. Choose your client:

Outlook (Windows and Mac)

  1. Outlook itself: File → Add Account or Settings → Accounts → Add account in new Outlook.
  2. Type the address and let it connect. Outlook recognises its own service and signs you in without a single server field.
  3. Choose IMAP and enter outlook.office365.com port 993 (SSL) and smtp-mail.outlook.com port 587 (STARTTLS).
  4. Approve the sign in in the Microsoft window that appears.
  5. Send yourself a test and check it arrives before you rely on it.

Apple Mail (macOS)

  1. Apple Mail keeps accounts under Mail → Settings → Accounts.
  2. Choose Outlook.com from the list. Apple Mail then hands the sign in to Microsoft, which is the supported route.
  3. Avoid Other Mail Account here. That path expects a typed password, which Outlook.com no longer accepts.
  4. If server fields appear, they take outlook.office365.com and smtp-mail.outlook.com.
  5. Enable Mail in the checkbox list and finish.

iPhone and iPad

  1. Start in the iPhone Settings app under Apps → Mail → Mail Accounts, then Add Account.
  2. Tap Outlook.com on iPhone and complete the Microsoft sign in that opens.
  3. Let iOS finish. Mail, contacts and calendar arrive together on this route.
  4. Keep IMAP chosen if iOS asks and supply both hostnames from the tables.
  5. Tap Save and let iOS complete the handshake with Microsoft.

Android

  1. On Android, open your mail app and add an account, picking Outlook or Microsoft where offered.
  2. Prefer the Microsoft option over Other, since Other cannot complete a modern sign in.
  3. Approve access when the Microsoft page appears, then let the first sync run.
  4. Enter the servers: outlook.office365.com 993 SSL incoming, smtp-mail.outlook.com 465 SSL outgoing.
  5. Finish and let the first sync populate your folders.

Thunderbird

  1. Thunderbird keeps it under Account Settings, then Account Actions → Add Mail Account.
  2. Give it your name and address, then Continue and let it detect the account.
  3. Thunderbird knows Outlook.com and offers OAuth2 as the authentication method. Keep that selected.
  4. A Microsoft window opens. Approve it there and the account finishes building.
  5. Select Done. Folders sync on first open.

Outlook.com Webmail Settings#

Servers get your apps talking to the mailbox. This section is about what Outlook.com does with mail once they are, all of it behind the gear icon under View all Outlook settings.

Signature

Mail → Compose and reply. Outlook.com supports several signatures with defaults for new mail and replies. Webmail only, so your desktop client keeps its own.

Vacation Auto Reply

Mail → Automatic replies. Set a date range and choose whether people outside your contacts get one. Microsoft sends it server side, so nothing needs to stay running.

Filters and Folders

Mail → Rules. These run on Microsoft servers, ahead of any device syncing. Rules built inside desktop Outlook only fire while that app is open, which is a common source of confusion.

Spam and Blocked Senders

Mail → Junk email. Block senders or whole domains here. Check the Junk folder before concluding mail never arrived, since Microsoft filters fairly aggressively.

Outlook.com POP3 vs IMAP#

FeatureIMAPPOP3
Where mail livesOn Microsoft servers (outlook.office365.com)Downloaded to 1 device, same hostname
Multiple devices✅ Everything stays in sync❌ Each device sees different mail
Sent and deleted mail✅ Synced everywhere⚠️ Stays only on that device
Offline reading⚠️ Cached mail only✅ Full local copy
Server storage usedYes, counts against your quotaCan be freed after download
Best forPhone + computer, everyday useSingle PC, local archives
Our verdict: pick IMAP. Both need switching on separately in webmail and IMAP is the one Microsoft steers modern clients toward. A backup tool is the sane way to hold an offline archive here, since POP needs its own switch and still arrives folderless.

Outlook.com Access and Sending Limits#

The limits that stop an Outlook.com setup are mostly about access rather than volume:

POP and IMAP accessOff until you turn it on and each protocol has its own switch
AuthenticationOAuth2 only in Microsoft's documented settings, which rules out clients that cannot open a sign in window
Same account in several IMAP clientsMicrosoft acknowledges connection errors here and is working on a fix. The workaround is approving the session in Recent activity
Free storage15 GB for mail, with OneDrive counted separately. A full mailbox stops accepting new messages
EncryptionSSL on 993 and 995, STARTTLS on 587. No unencrypted option exists
Work mailboxesAn administrator can disable POP, IMAP or authenticated SMTP for your account regardless of your settings

Troubleshooting Outlook.com Connections#

Find the exact error your email app shows, then apply the fix:

Error you seeWhat it meansFix
Password rejected, though it works on the website POP or IMAP is still switched off for the account The signature Outlook.com failure. Turn the protocol on under Settings → Mail → Forwarding and IMAP, then retry without changing anything else.
5.7.139 Authentication unsuccessful, basic authentication is disabled The app tried to send with a typed password Microsoft no longer accepts that for SMTP, app passwords included. Use a client that opens a Microsoft sign in window. See which password.
Enabled IMAP and it still will not connect Microsoft flagged the new client as a suspicious sign in Go to account.live.com/activity, find the session matching the failure, expand it and choose "This was me". Then connect again.
Connection errors after adding the account to a second app The same mailbox configured as IMAP in multiple clients, which Microsoft has acknowledged as a known issue Approve the session in Recent activity as above. Microsoft says a fix is in progress, so this is a workaround rather than a cure.
Server not responding or a timeout on connect An old hostname copied from a guide written years ago Addresses like imap-mail.outlook.com and pop3.live.com no longer answer. Incoming is outlook.office365.com for both protocols. Microsoft's own advice for a stubborn profile is to delete the account and add it again so the client picks the current configuration.
Sends nothing, receives fine The outgoing hostname is wrong or an admin disabled SMTP Outgoing is smtp-mail.outlook.com on 587, not the incoming hostname. On a work account, ask IT whether authenticated SMTP is enabled for your mailbox.
A device or scanner cannot connect at all It only speaks basic authentication Microsoft's settings page still points devices at an app password while its support answers say basic auth is disabled. Test it and plan for a relay or a different mailbox if it fails.

Reader Reported Fixes

Two fixes worth trying when the steps above leave you stuck, both from real Outlook.com cases.

Add the account by name rather than typing servers. Nearly every modern client lists Outlook.com or Microsoft directly and that path opens the sign in window and finishes on its own. Reaching for manual IMAP out of habit is what lands people in the password questions this page exists to answer.

Check Recent activity before rebuilding anything. A client that fails immediately after you enabled IMAP has usually been flagged rather than misconfigured. Approving that session takes seconds, where deleting and re adding the account rarely helps and often triggers another flag.

Outlook.com vs a Microsoft 365 Work Account#

Both are Microsoft, both open in Outlook and guides mix them up constantly. If your address sits on a company domain rather than one of the 4 consumer domains, some of this page changes for you:

Personal and work accounts share incoming, split on outgoing Outlook.com personal accounts and Microsoft 365 work accounts both receive mail through outlook.office365.com. Personal accounts send through smtp-mail.outlook.com and you control the protocol switches yourself. Work accounts send through smtp.office365.com and an administrator controls whether the protocols are available at all. Incoming, both account types outlook.office365.com Outlook.com, personal smtp-mail.outlook.com You turn the protocols on in webmail settings Microsoft 365, work smtp.office365.com An admin decides whether you get them at all Same incoming host, so guides mix the 2 up constantly
The single field that separates a personal setup from a work one.
What differsOutlook.com, personalMicrosoft 365, work
Incoming serveroutlook.office365.comoutlook.office365.com, the same
Outgoing serversmtp-mail.outlook.comsmtp.office365.com
Who controls POP and IMAPYou, in webmail settingsYour administrator, who can disable both entirely
Who controls SMTP sendingYouAn admin setting, per mailbox or across the tenant
Where to ask when it failsMicrosoft consumer supportYour IT team, who can see settings you cannot
Work account failing with everything correct? On a Microsoft 365 mailbox an administrator can switch off SMTP sending for your account alone and nothing you change in your client gets past that. Ask IT whether your mailbox still has authenticated SMTP turned on before you rebuild the profile again.

Moving mail between the 2? Leaving a job or folding an old hotmail.com address into a work mailbox, means copying mail across accounts that Microsoft will not join for you. The Univik Email Migration Tool copies folder by folder over IMAP and our Email Migration Services team runs the whole thing if you would rather hand it over.

Use These Settings in Univik Email Backup#

Once you switch IMAP on, those same values let a backup tool pull the whole mailbox down to your own disk. Univik Email Backup writes the mailbox to PST, MBOX, EML or PDF on your own disk, untouched by whatever Microsoft changes next.

  1. Start Univik Email Backup on any Windows PC.
  2. Choose Outlook.com in the source list or IMAP with the servers above if it is not named.
  3. Sign in when the Microsoft window opens. Tools that offer Outlook.com by name handle this for you.
  4. Entering servers by hand? outlook.office365.com on 993 with SSL, exactly as the table lists.
  5. Choose an output format and a destination folder, then start it. Large mailboxes download in the background.
Why back up before you change anything: the access switch and the authentication rules have both moved recently and a local copy is the only thing unaffected by either. Every folder, attachment and timestamp survives into files you can open without Microsoft. Moving to a new account instead of archiving? The email migration tool transfers it mailbox to mailbox instead.

Email Settings Glossary#

IMAP

Internet Message Access Protocol. The protocol behind outlook.office365.com on port 993. Mail stays on Microsoft servers and every device mirrors the same folders.

POP3

Post Office Protocol version 3. Same hostname as IMAP on port 995. Downloads to 1 device and needs its own switch turned on in webmail. Still supported here, though it needs enabling like IMAP does.

SMTP

Simple Mail Transfer Protocol. Sends your outgoing mail. The outgoing half and the only Outlook.com value on a different hostname: smtp-mail.outlook.com.

SSL / TLS / STARTTLS

The encryption Outlook.com insists on. Outlook.com secures every connection, running SSL on 993 and 995 and STARTTLS on 587 for sending.

App Password

A generated stand in for your password. Microsoft is retiring these for Outlook.com, which is why this page points at modern authentication instead.

OAuth

The Microsoft sign in window your client opens. Microsoft calls it Modern Auth and it is now the documented method for all 3 protocols. Outlook.com got there ahead of everyone else.

How We Verify These Settings#

Univik has built email backup and migration software since 2013 and Microsoft accounts have changed more in that time than any other provider we connect to. Each authentication shift showed up in our connection logs before the guides caught up.

Every value here clears 3 checks. First, Univik Email Backup opens a live IMAP and SMTP connection to the mailbox. A line by line match against Microsoft's published settings page. And a walk through the enable and approval screens exactly as written above. Microsoft announcements send us straight back through all 3.

Spotted a value Microsoft now shows differently? Let us know and it goes back through all 3 checks, with the result recorded in what changed recently.

 Help & Support

Outlook.com Settings: FAQ

Use outlook.office365.com on port 993 with SSL for incoming and smtp-mail.outlook.com on port 587 with STARTTLS for sending. Authentication is OAuth2. Turn IMAP on first, because Microsoft ships it disabled.

Two likely reasons. IMAP or POP is still switched off for the account, which produces a password style error even though the password is fine. Or your client only offers a plain password box and Outlook.com now expects a Microsoft sign in window instead. Check the access switch first.

Microsoft answers this 2 ways. Its settings page still mentions an app password for smart devices or when a password is not recognised, while its support engineers say basic authentication including app passwords is disabled and returns error 5.7.139. Treat modern authentication as the reliable route. The password section lays out both positions.

Yes, for both IMAP and POP, even on a personal hotmail.com or live.com address. It looks like a business hostname and it is not a mistake. Outgoing is the one that differs, using smtp-mail.outlook.com.

No. All 4 consumer domains, outlook.com, hotmail.com, live.com and msn.com, run on the same platform with identical servers and ports. Only your username changes. Microsoft 365 work accounts are the ones that differ, as the comparison shows.

Almost certainly the authentication change. Older clients kept connecting with a typed password long after Microsoft started moving away from it and when enforcement caught up they failed with no explanation. Moving to a client that supports a Microsoft sign in is the fix rather than any change to your settings.

Microsoft has acknowledged this: the same Outlook.com mailbox configured as IMAP in several clients can throw connection errors and a fix is in progress. The workaround is to approve the session at account.live.com/activity under Recent activity by choosing "This was me".

IMAP for almost everyone, since it keeps every device showing the same mailbox. Note that each protocol has its own switch in webmail, so enabling IMAP does not enable POP. Both use outlook.office365.com, on 993 and 995 respectively.

Turn IMAP on, then point a backup tool at the mailbox to save it as PST, MBOX, EML or PDF. To move rather than copy, an email migration tool connects to both accounts and transfers folder by folder. See the walkthrough.

Other Email Provider Settings

Summary: Outlook.com Settings at a Glance

  • IMAP: outlook.office365.com, port 993, SSL/TLS
  • POP3: outlook.office365.com, port 995, SSL/TLS
  • SMTP: smtp-mail.outlook.com, port 465 or 587
  • Username is always your full email address
  • App password required for third party apps
  • Pick IMAP for phone + computer sync
  • Authentication is OAuth2 only
  • Username is always the full email address