Connection settings
Use the credential’s Login email and generated password. IMAP requires a Mailbox + SMTP credential; either credential type can send with SMTP. All connections require TLS 1.2 or later: IMAP uses implicit TLS only, and SMTP on port
587 must upgrade with STARTTLS before authentication. See Connect with IMAP and Send with SMTP for client settings.
How it works
A managed credential combines three things:- An identity - A login email and generated password used to authenticate.
- Access scopes - One or more verified domains or exact email addresses the credential can access.
- Permissions - The available protocols, IMAP access level, and authorized SMTP sender addresses.
INBOX, Sent, Drafts, Trash, and Junk, plus read-only folders for individual scopes. The combined INBOX contains received mail covered by the credential’s scopes. SMTP uses the same login email and password and enforces the credential’s sender policy.
The login email must use an exact domain you own and have verified when you create or edit the credential. It is an authentication username and does not need to match the receiving or sending addresses, which are controlled separately by scopes and sender policy.
Choose a credential type
For Mailbox + SMTP, select Read and write if your client needs to save messages in
Sent or Drafts or change message flags. Read only still allows SMTP sending. Scope-specific folders remain read-only with either setting.
For send-only applications, create an SMTP only credential and use either SMTP configuration above. The same scope and sender-policy rules still apply.
Both credential types require at least one scope covering a whole verified domain, such as *@example.com, or one exact address, such as support@example.com.
Add and verify a domain before creating a credential. Only verified domains appear in the scope selector. Receiving mail also requires the domain’s receiving MX records to be configured and verified.
Mail-scoped API keys and security
The generated credential password is itself a mail-scoped API key, typically beginning withmail_; older credentials can begin with imap_. It authenticates IMAP and SMTP alongside the login email and can also authorize HTTP email sending under the same sender policy. It cannot manage account resources.
Ordinary account API keys, often stored as INBOUND_API_KEY, are a separate credential type. They can access permitted HTTP API resources but cannot authenticate to IMAP or SMTP.
When you create or rotate a credential, its password is shown exactly once. Save it in a password manager or secret manager. If it is lost or exposed, use Rotate password immediately; the previous password stops working at once.
Next steps
Connect with IMAP
Create a credential and configure an email client or application
Send with SMTP
Send from any SMTP client, with limits and reply codes
Scopes and Permissions
Understand domain scopes, address scopes, sender policies, and IMAP access
Manage Credentials
Edit, rotate, disable, enable, or delete managed credentials
IMAP Behavior
Folders, supported IMAP features, limits, and known limitations