Connection settings
Port
143 and IMAP STARTTLS are not offered. Keep certificate verification enabled. Ordinary account API keys and SMTP only credentials cannot authenticate to IMAP.
SMTP does not automatically save messages to IMAP
Sent, and received messages removed from INBOX reappear. Review IMAP behavior and limits before configuring a traditional email client.Create a mailbox credential
1
Open Mailboxes & SMTP
Add and verify a domain in domain settings, including its receiving MX records if you want incoming mail. Then open the Mailboxes & SMTP dashboard and select Create credential.
2
Choose the credential and IMAP access
Select Mailbox + SMTP under Credential type. Enter a descriptive Name and a Login email on an exact domain you own and have verified. The login email is your authentication username; it does not have to match the receiving or sending address.Under IMAP access, choose Read only to prevent mailbox changes or Read and write to save messages in
Sent or Drafts, change flags, and modify supported mailboxes. Read-only credentials can still send through SMTP. Scope-specific folders are always read-only.3
Set the sender policy
Select Exact identity to restrict sending to one Exact From address covered by a scope. The optional dashboard Display name does not set the name recipients see; provide that name in your email client’s From header instead.Alternatively, select Any scoped domain to permit any sender address on each exact domain represented by your scopes. Subdomains are not included.
4
Add verified domain or address scopes
Under Mail access & sending scopes, choose Domain for an entire verified domain or Address for one exact address. For an address scope, enter the local part without
@, then choose the verified domain.Select Add for each scope. At least one scope is required, and scopes determine which received messages are visible through IMAP.5
Create the credential and save its password
Select Create credential. The confirmation dialog displays the Username, generated Password, and the IMAP and SMTP connection settings.Copy the password into a password manager or secret manager before selecting I saved the password.
Connect from your application
Store your managed credential asINBOUND_MAILBOX_LOGIN and INBOUND_MAILBOX_PASSWORD in your application’s secret manager or environment. Both examples open INBOX read-only and inspect message headers without changing mailbox state.
For the TypeScript example, install ImapFlow:
BODY.PEEK reads the requested headers without marking a message as seen. Opening INBOX in read-only mode also works with both Read only and Read and write credentials.Troubleshooting
Authentication fails
Use the managed Login email and generatedmail_ or legacy imap_ password, not an ordinary account API key or your dashboard password. Confirm that the credential is enabled and that its password hasn’t been rotated. SMTP only credentials cannot authenticate to IMAP.
Authentication also fails when the login email’s domain, or every scope domain, is no longer verified. After 10 failed attempts for the same login from the same IP address within 15 minutes, further attempts are rejected, even with the correct password, until the window ends. A NO [TEMPFAIL] response means the authentication service was unavailable; retry later.
The connection closes right away
The server allows 20 simultaneous connections per client IP address and replies* BYE Too many connections from this address above that. Close unused sessions or lower your client’s connection count. Connections that stay idle for 60 seconds before logging in are closed. See connection limits and timeouts.
The inbox is empty
Check that the receiving domain is verified and its receiving MX records are configured and verified in domain settings. Confirm the message’s recipient matches one of the credential’s domain or address scopes. The login email alone does not grant access to messages outside those scopes.TLS or certificate validation fails
Use port993 with implicit TLS (often labeled SSL/TLS), not STARTTLS, and make sure the client supports TLS 1.2 or later. Keep hostname and certificate validation enabled. Test the TLS handshake without providing a username or password:
a CAPABILITY to see the advertised capabilities and b LOGOUT to close the connection.