Skip to main content
Connect an email client or application to Inbound using a managed Mailbox + SMTP credential. The same login email and generated password also work for sending with SMTP.

Connection settings

Port 143 and IMAP STARTTLS are not offered. Keep certificate verification enabled. Ordinary account API keys and SMTP only credentials cannot authenticate to IMAP.
SMTP does not automatically save messages to IMAP Sent, and received messages removed from INBOX reappear. Review IMAP behavior and limits before configuring a traditional email client.

Create a mailbox credential

1

Open Mailboxes & SMTP

Add and verify a domain in domain settings, including its receiving MX records if you want incoming mail. Then open the Mailboxes & SMTP dashboard and select Create credential.
2

Choose the credential and IMAP access

Select Mailbox + SMTP under Credential type. Enter a descriptive Name and a Login email on an exact domain you own and have verified. The login email is your authentication username; it does not have to match the receiving or sending address.Under IMAP access, choose Read only to prevent mailbox changes or Read and write to save messages in Sent or Drafts, change flags, and modify supported mailboxes. Read-only credentials can still send through SMTP. Scope-specific folders are always read-only.
3

Set the sender policy

Select Exact identity to restrict sending to one Exact From address covered by a scope. The optional dashboard Display name does not set the name recipients see; provide that name in your email client’s From header instead.Alternatively, select Any scoped domain to permit any sender address on each exact domain represented by your scopes. Subdomains are not included.
An address scope only limits which mail is received. With Any scoped domain, a scope for support@example.com still permits sending from billing@example.com, admin@example.com, or any other address at example.com. Choose Exact identity to restrict sending to one address.
4

Add verified domain or address scopes

Under Mail access & sending scopes, choose Domain for an entire verified domain or Address for one exact address. For an address scope, enter the local part without @, then choose the verified domain.Select Add for each scope. At least one scope is required, and scopes determine which received messages are visible through IMAP.
5

Create the credential and save its password

Select Create credential. The confirmation dialog displays the Username, generated Password, and the IMAP and SMTP connection settings.Copy the password into a password manager or secret manager before selecting I saved the password.
The generated password is a mail-scoped API key and is shown only once. Anyone with it can send mail within its sender policy, including through the HTTP email-sending endpoint. If it is lost or exposed, rotate it immediately and update every client.

Connect from your application

Store your managed credential as INBOUND_MAILBOX_LOGIN and INBOUND_MAILBOX_PASSWORD in your application’s secret manager or environment. Both examples open INBOX read-only and inspect message headers without changing mailbox state. For the TypeScript example, install ImapFlow:
BODY.PEEK reads the requested headers without marking a message as seen. Opening INBOX in read-only mode also works with both Read only and Read and write credentials.

Troubleshooting

Authentication fails

Use the managed Login email and generated mail_ or legacy imap_ password, not an ordinary account API key or your dashboard password. Confirm that the credential is enabled and that its password hasn’t been rotated. SMTP only credentials cannot authenticate to IMAP. Authentication also fails when the login email’s domain, or every scope domain, is no longer verified. After 10 failed attempts for the same login from the same IP address within 15 minutes, further attempts are rejected, even with the correct password, until the window ends. A NO [TEMPFAIL] response means the authentication service was unavailable; retry later.

The connection closes right away

The server allows 20 simultaneous connections per client IP address and replies * BYE Too many connections from this address above that. Close unused sessions or lower your client’s connection count. Connections that stay idle for 60 seconds before logging in are closed. See connection limits and timeouts.

The inbox is empty

Check that the receiving domain is verified and its receiving MX records are configured and verified in domain settings. Confirm the message’s recipient matches one of the credential’s domain or address scopes. The login email alone does not grant access to messages outside those scopes.

TLS or certificate validation fails

Use port 993 with implicit TLS (often labeled SSL/TLS), not STARTTLS, and make sure the client supports TLS 1.2 or later. Keep hostname and certificate validation enabled. Test the TLS handshake without providing a username or password:
After the handshake, type a CAPABILITY to see the advertised capabilities and b LOGOUT to close the connection.

A domain is missing from the scope selector

Add and verify the domain before creating or editing a credential, and use an exact owned, verified domain for the login email. Select Add after configuring each scope. Learn more about scopes and permissions, managing credentials, and IMAP behavior. For sending problems, see Send with SMTP.