Credential types
An SMTP-only credential still requires scopes and a sender policy. Its
accessMode is returned as read_write, but this does not grant IMAP access.
Domain and address scopes
Each credential must include between 1 and 100 unique scopes. Every scope references the ID of an exact domain that your account owns and that has a verified domain record.
A domain scope matches the exact domain, not its subdomains. For example,
*@example.com includes billing@example.com, but does not include billing@mail.example.com. To include mail.example.com, add that exact subdomain as its own verified domain record and configure a separate scope for it.
Address scopes must match their referenced domain exactly. Multiple distinct scopes can be combined, including scopes from different verified domains; duplicate scopes are rejected. Domain wildcard scopes omit the reserved dmarc@ address; add an explicit address scope if that address needs to be included.
A subdomain can inherit parts of its parent domain’s verification, but inheritance does not extend the parent’s mailbox scope. The exact subdomain must still exist as a separate verified domain record before it can be used as a login domain, sender domain, or scope.
How scopes appear in IMAP
Amailbox credential presents one combined INBOX containing incoming messages from all its scopes, plus a read-only folder for each individual scope:
Scopes is a folder container, not a selectable mailbox. Domain folders use the literal *@domain format; address folders use the complete email address.
Scope folders are always read-only, including for credentials with read_write access. Update flags or organize messages through INBOX or another writable folder instead. See IMAP behavior for folder, flag, and synchronization details.
IMAP access modes
accessMode applies only to mailbox credentials:
read: Open folders, fetch messages, search, and receiveIDLEupdates. All folders are read-only.read_write: Read messages and modify writable folders using operations such asSTORE,APPEND,COPY,MOVE, andEXPUNGE.Scopes/*folders remain read-only.
SMTP sender policies
The sender policy applies to SMTP and to HTTP sends authorized with the credential’s password. A disallowed SMTP sender is rejected with553; see Send with SMTP.
Exact identity
WithsendingMode: "identity", the credential can send only from its configured sendingAddress.
sendingName is optional and can be null; it is credential metadata and does not rewrite the outgoing display name, which comes from the message itself.
The message’s From address and any nonempty SMTP envelope MAIL FROM address must both satisfy the exact-identity policy. An empty envelope sender is permitted, but the message still needs an authorized From address.
Any scoped domain
WithsendingMode: "scoped_domains", the credential can send from any address on any exact domain represented by its scopes:
example.com allows support@example.com and billing@example.com, but not support@mail.example.com. The message’s From address and any nonempty envelope sender must both use an allowed exact domain; an empty envelope sender is permitted.
Login identity is separate
loginAddress is the username for IMAP and SMTP authentication. When a credential is created or its definition is edited, the login address must use an exact domain owned and verified by your account. It does not need to match the incoming scope or the allowed sending identity.
For example, the following configuration is valid when both domains are verified:
imap@operations.example, and it does not automatically authorize that address as an SMTP sender.
Later IMAP and SMTP login attempts recheck both the verified scope domains and the login address’s own verified domain. A domain-status change does not itself disconnect an existing IMAP session; changing or disabling the credential does. See IMAP behavior.
Permission examples
Disabled credentials cannot authenticate, regardless of their other permissions.
Manage Credentials
Create credentials, update scopes, disable access, and rotate passwords.
IMAP Behavior
Understand folders, read-only views, flags, limits, and synchronization.