Skip to main content
Inbound gives your email clients and applications direct access to email through standard IMAP and SMTP. Create managed credentials in the Mailboxes & SMTP dashboard, choose which verified domains or addresses they can access, and connect using the generated login email and password.

Connection settings

Use the credential’s Login email and generated password. IMAP requires a Mailbox + SMTP credential; either credential type can send with SMTP. All connections require TLS 1.2 or later: IMAP uses implicit TLS only, and SMTP on port 587 must upgrade with STARTTLS before authentication. See Connect with IMAP and Send with SMTP for client settings.

How it works

A managed credential combines three things:
  1. An identity - A login email and generated password used to authenticate.
  2. Access scopes - One or more verified domains or exact email addresses the credential can access.
  3. Permissions - The available protocols, IMAP access level, and authorized SMTP sender addresses.
For IMAP-enabled credentials, Inbound provides INBOX, Sent, Drafts, Trash, and Junk, plus read-only folders for individual scopes. The combined INBOX contains received mail covered by the credential’s scopes. SMTP uses the same login email and password and enforces the credential’s sender policy.
The login email must use an exact domain you own and have verified when you create or edit the credential. It is an authentication username and does not need to match the receiving or sending addresses, which are controlled separately by scopes and sender policy.

Choose a credential type

For Mailbox + SMTP, select Read and write if your client needs to save messages in Sent or Drafts or change message flags. Read only still allows SMTP sending. Scope-specific folders remain read-only with either setting. For send-only applications, create an SMTP only credential and use either SMTP configuration above. The same scope and sender-policy rules still apply. Both credential types require at least one scope covering a whole verified domain, such as *@example.com, or one exact address, such as support@example.com.
Any scoped domain permits sending from every address on a represented domain, even when the receiving scope covers only one address. For example, a scope for support@example.com also permits SMTP sending from billing@example.com. Select Exact identity to restrict sending to one address.
Add and verify a domain before creating a credential. Only verified domains appear in the scope selector. Receiving mail also requires the domain’s receiving MX records to be configured and verified.

Mail-scoped API keys and security

The generated credential password is itself a mail-scoped API key, typically beginning with mail_; older credentials can begin with imap_. It authenticates IMAP and SMTP alongside the login email and can also authorize HTTP email sending under the same sender policy. It cannot manage account resources. Ordinary account API keys, often stored as INBOUND_API_KEY, are a separate credential type. They can access permitted HTTP API resources but cannot authenticate to IMAP or SMTP. When you create or rotate a credential, its password is shown exactly once. Save it in a password manager or secret manager. If it is lost or exposed, use Rotate password immediately; the previous password stops working at once.
Anyone with the managed password can send mail allowed by its sender policy. Never expose it in source code, commit it to version control, or disable TLS certificate verification. Disabling or deleting a credential prevents further use.

Next steps

Connect with IMAP

Create a credential and configure an email client or application

Send with SMTP

Send from any SMTP client, with limits and reply codes

Scopes and Permissions

Understand domain scopes, address scopes, sender policies, and IMAP access

Manage Credentials

Edit, rotate, disable, enable, or delete managed credentials

IMAP Behavior

Folders, supported IMAP features, limits, and known limitations