Browse templates

IMAP server meaning: the mail server that lets every app, including your sales tools, read the same inbox.

Last checked Oct 1, 202618 min readSources named below

Definition

An IMAP server is a mail server that runs the Internet Message Access Protocol (IMAP), the standard that lets an email client read and manage messages that stay stored on the server.

The current version is IMAP4rev2, published by the IETF as RFC 9051 in August 2021. It describes IMAP as a way for a client to access and manipulate mail on a server, with remote folders that work like local ones, and with a way for an offline client to resynchronize later.

The practical result: your email inbox lives in one place. Your phone, your laptop, webmail and any sales tool you connect all ask the same IMAP server what is in the mailbox, so an email read, moved or deleted on one of those devices looks the same on all of them.

IMAP server meaning, in plain terms

The IMAP server meaning is easiest to see from what it replaced. POP3, the older protocol, was designed so that mail is normally downloaded and then deleted from the server. An IMAP server works the other way: the server keeps the master copy, and every email client is a window onto it.

  • Storage: messages, attachments and folders are kept on the mail server, not only on a device.
  • Sync: flags such as read, answered and flagged are stored on the server, so every connected app shows the same state.
  • Remote work on mail: the client can search, fetch only headers or one part of a message, create and rename folders, and move messages without downloading the whole mailbox.
  • Offline and back: a client can work offline and resynchronize when it reconnects.

What an IMAP server does not do is send email. RFC 9051 says so directly: posting mail is handled by a mail submission protocol such as the one in RFC 6409, which is SMTP-based. That split matters when you connect a mailbox to a sales tool, because reading and sending are two separate permissions.

What an IMAP account means

An IMAP account is simply an email account that an app reaches through an IMAP server. The account has a username, usually your full email address, a server name, a port and a sign-in method. The same mailbox can be an IMAP account in one app and a webmail account in the browser.

Advantages and limits of an IMAP server

AdvantageLimit to know about
Multiple devices and users of one account see the same mailboxEach provider caps connections; Gmail allows up to 15 email clients per account
Mail survives a lost laptop, because the server holds itMail stays on the server, so the account's storage is what fills up
Clients fetch only what they need, such as headers firstVery large folders can slow a client; Gmail lets you cap folder size
New mail can be pushed with IDLESessions end and must reconnect; Gmail lists about 24 hours

How an IMAP server works

An IMAP session is a conversation between the email client and the server over a TCP connection. The client sends tagged commands, the server answers with data and a completion result, and the client acts on what it learns.

Connectport 993, TLS first
AuthenticateOAuth token or password
Selecta mailbox such as INBOX
Fetch and searchheaders, bodies, flags
IDLEwait for new mail
Client and serverAUTHENTICATE or LOGINSELECTFETCH, SEARCH, STORE, MOVEServer pushes updates

RFC 9051 defines four connection states: not authenticated, authenticated, selected and logout. Most commands are only valid in certain states, which is why a client must sign in before it can open a mailbox, and must open a mailbox before it can touch messages.

The IMAP commands behind every email app

StateCommands in RFC 9051What they do
Any stateCAPABILITY, NOOP, LOGOUTList what the server supports, keep alive, end the session
Not authenticatedSTARTTLS, AUTHENTICATE, LOGINSecure the connection and sign in
AuthenticatedSELECT, CREATE, RENAME, LIST, STATUS, APPEND, IDLEOpen and manage mailboxes, add messages, wait for news
SelectedFETCH, SEARCH, STORE, COPY, MOVE, EXPUNGE, UIDRead, find, flag, file and remove messages

The IDLE command lets the server tell the client about new messages, deletions and flag changes as they happen, instead of the client polling. It was an extension in the older IMAP4rev1 and is part of the core protocol in IMAP4rev2, along with MOVE.

Every message in a mailbox has a unique identifier (UID). Clients and sales tools can use it to remember which messages they already processed, so they pick up where they left off after a disconnect.

RFC 9051 also says the plain LOGIN command, which carries a password, should be used only as a last resort after AUTHENTICATE fails. That line in the standard is the protocol side of the move to OAuth described further down.

IMAP4rev1 and IMAP4rev2: the versions behind the standard

From 2003 to 2021 the reference text was RFC 3501, IMAP4rev1, published in March 2003. It replaced an earlier version, RFC 2060. RFC 9051 obsoleted RFC 3501 in 2021 and became the current standard for an IMAP server.

  • Extensions folded in: IDLE, MOVE, NAMESPACE, UNSELECT, UIDPLUS, ENABLE and the special-use mailbox attributes, among others, are now part of the base protocol.
  • UTF-8: mailbox names and message headers may use UTF-8.
  • Removed or deprecated: the CHECK command was removed, and the \Recent flag and LSUB command were deprecated.
  • New keywords: servers should support $Forwarded, $MDNSent, $Junk, $NotJunk and $Phishing.

An IMAP server can advertise both IMAP4rev1 and IMAP4rev2 in its CAPABILITY response. A client that wants the newer behavior then issues ENABLE IMAP4rev2. For users, the version is invisible; for a tool vendor, it decides which features the connection can rely on.

What an IMAP server keeps in sync

The sync that makes IMAP useful runs on flags stored with each message on the server. RFC 9051 defines a set of system flags that every client understands.

FlagMeaning in RFC 9051Why a sales team cares
\SeenMessage has been readA tool that marks replies as read changes what you see in your inbox
\AnsweredMessage has been answeredShows which prospect replies someone already handled
\FlaggedFlagged for urgent or special attentionThe star or flag you set on a hot reply syncs to every device
\DeletedMarked for removal by a later EXPUNGEA deletion in one app removes the message everywhere
\DraftComposition not finishedDrafts started on a phone can be finished on a laptop

Folders sync the same way. Google's Gmail Help says that when you add Gmail to another email client, your messages and labels are synced with that client.

Special-use folders: Sent, Drafts, Junk and Trash

RFC 9051 lets a server mark the role of a mailbox with attributes such as \Sent, \Drafts, \Junk, \Trash, \Archive and \All. The folder names users see can differ between providers; the attribute tells a client which folder plays which role.

This matters to sales tools in a concrete way. A tool that logs your outreach has to find the folder that holds sent mail, and a tool that checks for replies should not mistake the Junk folder for the inbox. All special-use attributes are optional, so some servers expose none.

IMAP vs POP3: which one to use

POP3, the Post Office Protocol version 3, is the older way to receive email. RFC 1939 describes it as a way for a workstation to retrieve mail a server is holding, and notes that normally mail is downloaded and then deleted. IMAP was built for managing mail on the server instead.

ComparedIMAPPOP3
Where mail livesOn the server, the master copyDownloaded to one local device, often removed from the server
Sync directionTwo-way: changes in any app reach the serverOne-way: server to device
Read status across devicesSyncedEach device treats downloaded mail as new
Sent itemsStored on the server for every deviceSaved only on the device that sent them
FoldersServer folders, shared by all appsCreated separately on each device
New mailCan be pushed with IDLEThe client checks on a schedule
Ports993 (TLS), 143995 (TLS), 110
Fit for sales toolsYes: several apps can read one mailboxPoor: one app downloading can hide mail from the others

Microsoft's own comparison makes the same point: POP3 was originally designed for use on one computer and supports only one-way sync. It adds that sent items cannot be synchronized using POP3, and that folders made on one device must be made again on every other device.

For anyone who reads email on a phone and a laptop, or connects a mailbox to a CRM, IMAP vs POP3 is not a close call. Multiple devices and multiple tools need one shared copy of the mailbox, and only IMAP provides it.

POP3 still has a place for a single device that must keep an offline archive, or for a server that only collects mail into another system. Gmail and Outlook.com both still offer POP3 servers alongside their IMAP servers.

SMTP vs IMAP: sending and reading

SMTP and IMAP are the two halves of an email account. SMTP (Simple Mail Transfer Protocol) takes a message from your app and delivers it toward the recipient. IMAP lets your app read the mailbox where incoming mail, and usually a copy of sent mail, is stored.

ComparedSMTPIMAP
JobSending (mail submission and relay)Reading and managing stored mail
Client ports587 with STARTTLS, 465 with implicit TLS993 with implicit TLS, 143 with STARTTLS
In a sales toolSends each step of the sequence from your addressDetects replies, bounces and auto-replies
If it failsEmails do not go outReplies are missed and follow-ups keep sending

The last row is the one that hurts. When IMAP breaks but SMTP still works, a sequencing tool can keep sending follow-ups to people who already replied, which is exactly the email a prospect remembers.

Where IMAP fits among the email protocols

IMAP runs over a reliable connection such as TCP, as RFC 9051 puts it, and RFC 8314 asks for that connection to be encrypted with TLS. Three email protocols share the work between email servers and the email clients that users run on their devices.

  • SMTP: email clients submit outgoing emails to their provider's server, normally on port 587, and email servers relay messages to each other over port 25, according to RFC 6409.
  • IMAP: email clients access emails stored on the provider's IMAP server, with support for folders, search and sync across multiple devices.
  • POP3: email clients download emails from the server to one device, usually for offline access.

An email service such as Gmail or Outlook.com runs servers for all three. Users rarely see them, except in the settings screen of an email client or a sales tool, where each server name, port and security option has to be entered correctly for email data to flow.

IMAP server vs MX records: two different jobs

People setting up a domain often confuse the IMAP server with the mail exchanger. They sit at opposite ends of the same mailbox. MX records are DNS entries that tell other mail servers where to deliver inbound mail for your domain; RFC 8314 mentions them only as the way to handle inbound mail.

The IMAP server is where your own apps go to read that mail once it has arrived. RFC 8314 recommends a different DNS record type, SRV records, to help email clients discover the right IMAP and submission servers automatically.

ComparedMX recordIMAP server
Who uses itOther mail servers sending to your domainYour email clients and connected tools
What it doesPoints inbound delivery to the right hostStores the mailbox and answers read requests
If it is wrongMail to your domain does not arriveMail arrives but your apps cannot read it

IMAP ports 143 and 993, and the other mail ports

RFC 9051 says an IMAP server listens on port 143, the cleartext port, or port 993, the implicit TLS port. On 993 the encrypted connection starts immediately. On 143 the connection starts unencrypted and the client must issue STARTTLS before signing in.

PortProtocolEncryptionUse it?
993IMAPImplicit TLS from the first byteYes, the standard choice
143IMAPCleartext, upgraded with STARTTLSOnly if 993 is unavailable
995POP3Implicit TLSOnly if you need POP3
110POP3CleartextAvoid
587SMTP submissionSTARTTLSYes, for sending
465SMTP submissionImplicit TLSYes, for sending

RFC 8314, titled Cleartext Considered Obsolete, recommends implicit TLS for mail access in preference to STARTTLS, and asks providers to deprecate cleartext access as soon as practicable. Gmail, Outlook.com and Yahoo Mail all publish port 993 with SSL/TLS for IMAP.

IMAP server examples: Gmail, Outlook.com and Yahoo Mail

An IMAP server address is a host name your app connects to. The three examples below come from each provider's own help pages, read on Oct 1, 2026. Check the page again before you rely on it, because providers change these settings.

ProviderIMAP serverOutgoing SMTP serverSign-in the provider names
Gmailimap.gmail.com, 993, SSLsmtp.gmail.com, 465 or 587"Sign in with Google"
Outlook.comoutlook.office365.com, 993, SSL/TLSsmtp-mail.outlook.com, 587, STARTTLSOAuth2/Modern Auth
Yahoo Mailimap.mail.yahoo.com, 993, SSLsmtp.mail.yahoo.com, 465 or 587Generated app password

For a company domain, the IMAP server is whatever the domain's mail host publishes. Check the mail host's own documentation or ask your administrator for the server name, port and sign-in method, rather than copying values from a forum post.

IMAP server settings for Gmail

Google publishes the server names in its developer documentation. For personal Gmail accounts, Google says that starting January 2025 the Enable IMAP and Disable IMAP choice is no longer available: IMAP access is always on.

SettingGmail value
IMAP serverimap.gmail.com, port 993, SSL required
SMTP serversmtp.gmail.com, port 465 (SSL) or 587 (TLS)
Sign-in"Sign in with Google" (OAuth 2.0); app password only as a fallback
Connection limitUp to 15 email clients at a time per account
Session lengthAbout 24 hours; with OAuth, about the life of the access token, usually 1 hour

Gmail no longer supports third-party apps that require your Google username and password. If a tool only offers a password field and "Username and password not accepted" appears, look for a "Sign in with Google" option instead.

Three Gmail details matter for sales tools. Sent messages are copied to the Sent folder automatically when a client sends through Gmail's SMTP, so a tool should not save a second copy. Google suggests limiting IMAP folders to 10,000 emails or fewer if a client crashes or syncs slowly.

The third is deletion. Google warns that if a client is set to save deleted messages in the Trash, anything deleted from that client is permanently deleted from Gmail after 30 days. A tool that "cleans up" processed replies can therefore remove them for good.

IMAP server settings for Outlook and Microsoft 365

For Outlook.com accounts, Microsoft lists the settings below and states that Outlook.com requires Modern Auth, meaning OAuth2. POP and IMAP access is disabled by default and has to be turned on under Settings, Mail, Forwarding and IMAP.

SettingOutlook.com value
IMAP serveroutlook.office365.com, port 993, SSL/TLS
SMTP serversmtp-mail.outlook.com, port 587, STARTTLS
UsernameYour email address
AuthenticationOAuth2 / Modern Auth

For work mailboxes on Exchange Online, Microsoft says Basic authentication is now disabled in all tenants, including for IMAP and POP, and that no one can re-enable it. Microsoft adds that this also prevents app passwords with apps that do not support two-step verification.

Developers whose apps read mail over IMAP can keep the protocol but must use Modern authentication, which is OAuth 2.0. In practice, a tool that connects to a Microsoft 365 mailbox by IMAP signs in through Microsoft's own page rather than storing your password.

Whether you may approve that tool yourself depends on your company. Microsoft Entra lets users consent to an app accessing their own mailbox by default, and lets administrators restrict that. Ask IT before you try, not after the connection fails.

App passwords and OAuth: how you sign in to an IMAP server

How the tool proves it may read your mailbox has changed more than the protocol itself. There are three ways, and the providers now push toward the last one.

PasswordYour normal account password

The old IMAP LOGIN. Gmail no longer supports apps that need it, and Exchange Online disabled Basic authentication. Treat any tool that asks for your real password as a warning sign.

App passwordA separate code for one app

Google's is a 16-digit passcode, available only with 2-Step Verification, and the option may be missing on work, school or Advanced Protection accounts. Google revokes app passwords when you change your account password.

OAuth 2.0"Sign in with Google" or Modern Auth

You sign in on the provider's page and approve specific permissions. The tool receives a token instead of your password, and you can remove its access from your account settings without changing your password.

Under the hoodSASL XOAUTH2

Both Google and Microsoft pass the OAuth token to the IMAP server through the AUTHENTICATE command using the XOAUTH2 mechanism.

Google's own guidance is blunt: app passwords are not recommended and are unnecessary in most cases. Use OAuth whenever the tool offers it, and treat an app password as the fallback for software that has no other option.

One OAuth detail is worth knowing. Microsoft notes that if you approve the offline_access scope, the app receives refresh tokens, which are long-lived and let it get new access tokens as old ones expire. A connected tool keeps access until you or an administrator revoke it.

Why sales tools connect to a mailbox via IMAP

A sales cadence only works if the tool knows who answered. The replies land in your inbox, not in the tool, so the tool needs to read the mailbox. That is the reason a sequencing tool or CRM asks for IMAP access, or for the provider's equivalent API access.

  • Reply detection: the tool matches incoming messages to the prospect and can stop the remaining steps, so nobody gets a follow-up after saying yes or no.
  • Bounce handling: email bounces come back to the mailbox as messages. Reading them lets a tool mark the address as bad before it sends again.
  • Auto-replies: out-of-office messages can be sorted so a vacation notice does not count as a real reply.
  • Activity logging: the CRM attaches the conversation to the right contact and account, so the next person sees the history.
  • Shared context: a manager or teammate sees the thread without being copied on every message.

This is why a broken connection is so costly in cold email. The emails keep going out, the replies are not seen, and the sequence follows up with people who already answered. The same applies to any multi-step outreach sequence.

What a sales tool can see with IMAP access

IMAP itself has no concept of "only sales email". Once an app is authenticated, it works with the mailboxes the account can open. The permission is the mailbox, and the tool's own settings decide what it actually processes.

With IMAP access, a tool canWhat to check
Read all messages and foldersWhether it processes only prospect threads or the whole inbox
Change flags, such as marking replies readWhether it changes what you see in your own inbox
Move and delete messagesWhether it files replies into folders or labels automatically
Store copies of messagesWhat it keeps, where, and for how long

On Microsoft 365, the IMAP permission a tool requests is named IMAP.AccessAsUser.All, which describes its reach accurately: access to the mailbox as the user. Read the consent screen before approving it, the same way you would read a contract before signing it.

What one CRM's documentation discloses

HubSpot's Knowledge Base is a useful example because it spells the access out. It says you can connect Gmail, Microsoft Outlook, Microsoft Exchange, or other email accounts using IMAP, so the CRM can send one-to-one emails, log emails and send sequences.

  • Over IMAP: HubSpot says it gets access only to the email address, password, server information, email metadata and message bodies.
  • Through the Gmail integration: HubSpot says it will be able to read, modify, create and send emails from the connected account, and that tracked correspondence is visible to other users in the HubSpot account.
  • With two-factor sign-in: the generic IMAP route asks for a third-party app password from your email provider.

Its IT requirements page adds two details that apply to any mailbox connection. HubSpot makes up to five concurrent connections to an IMAP inbox, two of them permanent for the inbox and the sent folder, and the IMAP and SMTP ports must be open and support encryption.

Those connections count toward provider limits such as Gmail's 15 email clients. HubSpot also offers a "Trust any certificate" checkbox for servers without a certificate signed by a certificate authority; this page's advice is to fix the certificate instead of ticking the box.

How to connect a mailbox to a CRM or sequencing tool

The steps below were written for this page and apply across tool categories, from a CRM to an outreach platform or an AI sales agent that sends on your behalf.

  1. Check that the tool is approved

    Use a tool your company has approved for mailbox access. On a work account, an administrator may need to approve the app first.

  2. Choose the OAuth option

    Pick "Sign in with Google" or "Sign in with Microsoft" instead of a manual IMAP form. The manual form is for providers that do not offer OAuth.

  3. Read the permissions

    On the consent screen, note whether the tool requests reading, sending, or both, and whether that matches what you need it to do.

  4. Use manual settings only if needed

    For other providers, enter the IMAP server name, port 993, SSL/TLS, your full email address and an app password if the provider issues one.

  5. Test with a real reply

    Send yourself a test step from the tool, reply to it from another address, and confirm the tool marks it as replied and stops the sequence.

Troubleshooting IMAP connection errors

ErrorLikely causeWhat to do
"Username and password not accepted" or "Invalid credentials"The provider no longer accepts password sign-inReconnect with OAuth, or an app password where allowed
Worked before, stopped after a password changeGoogle revokes app passwords on password changeCreate a new app password, or switch to OAuth
"Too many simultaneous connections"Too many clients reading one Gmail accountDisconnect unused devices and tools
Connection times outWrong port, or port 993 blocked on the networkCheck server name, port 993 and SSL/TLS
Outlook.com refuses IMAPPOP and IMAP access is disabled by defaultTurn it on under Forwarding and IMAP
Client slow or crashing on syncVery large foldersLimit IMAP folder size in Gmail settings

When a sales tool shows a disconnected mailbox, pause its sequences before fixing anything. Every hour of broken reply detection is another batch of follow-ups to people who may already have replied.

IMAP server or the provider's API

IMAP is a protocol, not a product. Gmail, Outlook.com, Exchange Online and Yahoo Mail all publish IMAP servers, which is why it works as the universal fallback. Some tools connect to Gmail or Microsoft 365 through the provider's own integration instead, which is a different permission with its own consent screen.

For the user, the difference is mostly invisible. What matters is the same in both cases: sign in with OAuth, read what the tool asks for, and know how to revoke it. For a B2B SaaS buyer, this is part of the security review.

IMAP server security for sales teams

  • Encrypt the connection: use port 993 with TLS. RFC 8314 recommends TLS 1.2 or later for all traffic between email clients and mail access servers.
  • Never share your real password: OAuth tokens and app passwords can be revoked on their own; your password protects everything else.
  • Review connected apps: remove tools you stopped using. In your Google Account, the linked apps page lets you remove an app's access, after which Google says it can no longer access your account.
  • Keep sending separate from reading: this page's advice is to grant send permission only to tools that must send, and to watch email deliverability before adding volume to a main mailbox.

Common mistakes with IMAP servers

  • Assuming IMAP sends email. It only reads; sending is SMTP or an API, and it needs its own setup.
  • Confusing the IMAP server with the MX record, and editing DNS when the real problem is a sign-in setting.
  • Using POP3 on a mailbox a sales tool also reads, so one app downloads replies the other never sees.
  • Typing your real password into a tool's IMAP form instead of using OAuth.
  • Ignoring a "mailbox disconnected" warning while sequences keep sending.
  • Saving sent messages twice in Gmail, once by the client and once by Gmail's SMTP.
  • Granting full mailbox access to a tool nobody on the team still uses.

Once the mailbox is connected, the next job is the messages themselves: a sales follow-up email template that stops the moment someone replies is the whole point of the connection.

In a sequence

Before a sales tool can read your work mailbox, someone usually approves it. The request below was written for this page: it names the tool category, the permissions and the reason, so an administrator can say yes quickly. More outreach messages are in the sales outreach hub.

Asking IT to approve a mailbox connection for a sales tool
Subject: Approval to connect my mailbox to {{toolCategory}}

Hi {{adminName}},

I would like to connect my work mailbox ({{emailAddress}}) to {{toolName}}, the {{toolCategory}} our team uses for {{purpose}}.

It asks for IMAP read access so it can detect replies and stop follow-ups, and {{sendPermission}} so it can send from my address.

It supports OAuth sign-in, so no password is stored in the tool. The permissions it requests are: {{scopes}}.

Could you approve the app, or tell me what you need to review first?

Thanks,
{{senderName}}
Backfires when

You send it before checking what the tool actually requests. If the scopes include full mailbox access and you only described reply detection, the admin will find the gap and say no.

Copy the exact permission list from the tool's consent screen into the request.

Frequently asked questions

What is an IMAP account?

An IMAP account is an email account that an app reaches through an IMAP server, using a server name, port 993 or 143, your email address and a sign-in method. The same mailbox can be an IMAP account in one app and webmail in a browser.

What is the IMAP server meaning in simple terms?

It is the computer that keeps your mailbox and answers requests from your email apps. Your phone, laptop and sales tools all ask the same IMAP server what is in the inbox, instead of each keeping its own copy.

What is the difference between IMAP vs POP3?

IMAP keeps mail on the server and syncs folders, read status and deletions across devices. POP3 downloads mail to one device and was designed so mail is normally deleted from the server after download. Use IMAP when more than one device or tool reads the mailbox.

What is the difference between SMTP vs IMAP?

SMTP sends mail: your app submits a message to an SMTP server, usually on port 587 or 465. IMAP reads mail that is already in your mailbox. An email account needs both, and a sales tool that sends and tracks replies usually uses both.

What port does IMAP use, 143 or 993?

Both are IMAP ports. Port 993 starts an encrypted TLS connection immediately. Port 143 starts in cleartext and must be upgraded with the STARTTLS command. RFC 8314 prefers implicit TLS, and Gmail, Outlook.com and Yahoo Mail all publish port 993.

What is the IMAP server for Gmail?

Gmail's IMAP server is imap.gmail.com on port 993 with SSL, according to Google's developer documentation. Outgoing mail uses smtp.gmail.com on port 465 or 587. Google recommends connecting with "Sign in with Google" rather than a password.

What are the IMAP settings for Outlook?

For Outlook.com, Microsoft lists outlook.office365.com, port 993, SSL/TLS encryption and OAuth2/Modern Auth sign-in. Outgoing mail uses smtp-mail.outlook.com on port 587 with STARTTLS. IMAP access must first be turned on in Outlook.com settings.

Do I need to enable IMAP in Gmail?

Not for a personal Gmail account. Google says that starting January 2025 the Enable IMAP and Disable IMAP choice is no longer available, and IMAP access is always on. Work accounts managed by an organization may not have access to these settings.

What is an app password and do I need one for IMAP?

Google describes an app password as a 16-digit passcode that lets a less secure app access your account. It requires 2-Step Verification. Google says app passwords are unnecessary in most cases; use "Sign in with Google" when the app offers it.

Why does my sales tool ask for IMAP access?

Sequencing tools and CRMs read the mailbox to detect replies, stop follow-ups when a prospect answers, sort bounces and out-of-office replies, and log conversations to the right contact. Without mailbox access, the tool cannot tell who replied from your own inbox.

Is it safe to connect my mailbox to a CRM through IMAP?

It is as safe as the tool and the permissions you grant. Prefer OAuth over a stored password, read the scopes on the consent screen, use a tool your company has approved, and remove access for tools you no longer use.

Why does my IMAP connection fail with invalid credentials?

Often because the provider no longer accepts a plain password. Gmail no longer supports apps that need your username and password, and Exchange Online disabled Basic authentication for IMAP. Reconnect with OAuth, or with an app password where the provider allows one.

How many apps can connect to Gmail by IMAP?

Google says you can add Gmail to up to 15 email clients at a time per account. Too many connections at once can cause a "Too many simultaneous connections" error, so disconnect tools and devices you no longer use.

What is the difference between an IMAP server and an Exchange server?

IMAP is a protocol, and many mail systems speak it, including Gmail and Exchange Online. Exchange also offers its own connection methods. A sales tool may connect to the same mailbox through IMAP or through the provider's own API.

Sources and reading
  1. IETF, RFC 9051 Internet Message Access Protocol (IMAP) Version 4rev2, for the definition of IMAP, ports 143 and 993, connection states, commands, system flags, special-use mailboxes, the LOGIN last-resort rule, the changes from IMAP4rev1 and the note that IMAP does not send mail, checked Oct 1, 2026.
  2. IETF, RFC 3501 Internet Message Access Protocol Version 4rev1, for the March 2003 date and the RFC 2060 predecessor, checked Oct 1, 2026.
  3. IETF, RFC 8314 Cleartext Considered Obsolete, for implicit TLS on port 993, port 995 for POP and port 465 for submission, TLS 1.2 or later, deprecating cleartext access, and MX and SRV records, checked Oct 1, 2026.
  4. IETF, RFC 1939 Post Office Protocol Version 3, for POP3 on port 110 and the download and delete model, checked Oct 1, 2026.
  5. IETF, RFC 6409 Message Submission for Mail, for port 587 as the submission port and port 25 for relay, checked Oct 1, 2026.
  6. Google, Gmail Help, Add Gmail to another email client, for IMAP always on from January 2025, Sign in with Google, label sync, the 15 client limit and the 10,000 message folder limit, checked Oct 1, 2026.
  7. Google, Gmail Help, Choose your IMAP email client settings for Gmail, for automatic Sent copies and the 30 day Trash deletion warning, checked Oct 1, 2026.
  8. Google for Developers, IMAP, POP, and SMTP, for the Gmail server names, ports, OAuth 2.0 with SASL XOAUTH2 and session lengths, checked Oct 1, 2026.
  9. Google Account Help, Sign in with app passwords, for what an app password is, when it is available and when it is revoked, checked Oct 1, 2026.
  10. Google Account Help, Manage links between your Google Account and apps from other developers, for removing a linked app's access, checked Oct 1, 2026.
  11. Microsoft Support, POP, IMAP, and SMTP settings for Outlook.com, for the Outlook.com server names, ports, Modern Auth requirement and enabling IMAP, checked Oct 1, 2026.
  12. Microsoft Support, What is the difference between POP and IMAP, for one-way POP3 sync, sent items and folders, checked Oct 1, 2026.
  13. Microsoft Learn, Deprecation of Basic authentication in Exchange Online, for Basic authentication disabled in all tenants for IMAP and POP and its effect on app passwords, checked Oct 1, 2026.
  14. Microsoft Learn, Authenticate an IMAP, POP or SMTP connection using OAuth, for the IMAP.AccessAsUser.All scope, offline_access refresh tokens and SASL XOAUTH2, checked Oct 1, 2026.
  15. Microsoft Learn, Configure how users consent to applications, for default user consent to mailbox access and admin restrictions, checked Oct 1, 2026.
  16. Yahoo Help, IMAP server settings for Yahoo Mail, for the Yahoo IMAP and SMTP servers, ports and app password, checked Oct 1, 2026.
  17. HubSpot Knowledge Base, Connect an individual work email, for the IMAP connection option and the access HubSpot discloses for IMAP and Gmail connections, checked Oct 1, 2026.
  18. HubSpot Knowledge Base, Technical requirements for connecting your inbox to HubSpot with IMAP, for concurrent connections, open encrypted ports and the certificate option, checked Oct 1, 2026.
  19. Tools are described as categories. No vendor is ranked, recommended or paid for placement; HubSpot is quoted only for what its own documentation discloses, and you should check each tool's own documentation for the permissions it requests.
Take the sequence with you

The 10-day cadence, five templates, one email.

Five touches across email, LinkedIn and phone, five templates with placeholders marked, and the first-30-days checklist. One email.

Build a LinkedIn or outreach tool? Jeluvi is read by the people who use them. See how partners appear on Jeluvi.