Mail App Passwords for Your Devices

Give each mail app or phone its own password, see when it was last used, and switch off a lost device without changing your mailbox password.

Article details

Type, difficulty, plans, and last updated info.

▼
Type
Guide
Difficulty
Beginner
Plans
Nano · Starter · Pro · Agency
Last updated
Oct 6, 2026

An app password is a separate password for a mail app or device that connects to your mailbox. Give Outlook on your laptop one password and your phone another. If you lose the phone, revoke its password without changing the mailbox password or updating Outlook.

App passwords are available on every plan that has mailboxes. They work for email, calendar, and contacts apps. Your mailbox password still opens webmail, and your dashboard has its own sign-in.

Why use a separate password for each device?

Mailbox two-factor authentication protects webmail sign-in only. Outlook, Apple Mail, Thunderbird, calendar and contacts apps, and classic webmail never ask for the second-factor code. Turning on 2FA alone does not add that second step to a mail app.

App passwords let you manage those connections separately. Use a name that tells you where a password belongs, such as Outlook on the office PC or Calendar on my iPhone. When a device is retired or a password is exposed, you can stop that connection while the mailbox password stays the same.

A password is not restricted to the app named in its label. The name helps you recognize it; keep the secret private just as you would any password. Creating a different one for each app or device makes the list useful when you need to revoke one.

The two mail app sign-in modes

Each regular mailbox has a Mail app sign-in setting:

Mode What to enter in a mail app
App passwords only (Recommended) An app password. Mail apps refuse the mailbox password, which keeps working in webmail.
Mailbox password or app passwords Either the mailbox password or an app password. You can start using separate device passwords before requiring them.

Existing mailboxes keep Mailbox password or app passwords at rollout. Their saved mailbox password continues to work until someone changes the mode.

In the dashboard, open Mailboxes > the mailbox > Security tab > Mail app sign-in. An administrator with permission to set the mailbox password can change the mode in either direction. Requiring app passwords asks for confirmation and signs out mail apps that used the mailbox password. Prepare an app password for each device before making that change. Apps with valid app passwords reconnect on their own.

In the mailbox list, a small key icon beside the address marks a mailbox in App passwords only; hover over it, or tap it on a phone, to see what it means. The list also has a filter and a bulk action to require app passwords or allow the mailbox password again. Platform system mailboxes always keep accepting their mailbox password.

In webmail, the mailbox user can switch to App passwords only, but switching back requires an account administrator. When enabling mailbox 2FA, Also require app passwords for mail apps is selected by default. Leave it selected to require separate passwords for those connections.

The account default for new mailboxes

The account owner controls Account settings > New mailboxes > Mail apps need app passwords. This Recommended setting is on by default. It applies to mailboxes created from then on, including dashboard creation, bulk creation, invites, the API, and AI agents.

Changing this default never switches existing mailboxes. Use their Security tab or the mailbox list's bulk action for that. When creating a single mailbox in the dashboard, the Mail apps use a separate password switch lets you choose differently for that mailbox.

The first app password comes with the mailbox

When you create a mailbox in App passwords only in the dashboard, its first app password is created with it. The Mailbox created card shows the email address, the Password for webmail and the Password for Outlook and phones, each with a copy button, so there is no second step before setting up a mail app. Bulk creation puts it in the downloaded file's app_password column, and the setup wizard shows it on its last step. Integrations get it on request: see Mail App Passwords via API and MCP.

It is an ordinary app password named Created with the mailbox: it appears in the list, and you can replace or revoke it like any other. No notice email is sent for it, because the mailbox is new and its creator was just shown the password. It is shown once, like every app password. A mailbox invite's setup page tells the new owner to create one in webmail.

Create an app password in the dashboard

  1. Open Mailboxes and select the regular mailbox.
  2. Open the Security tab.
  3. Find App passwords and click Create app password.
  4. Give it a recognizable name, up to 64 characters.
  5. Copy the generated password into the app you are setting up.

Anyone allowed to set the mailbox password can manage app passwords: the account owner, authorized admins, and a White Label client role with that permission. A member with read-only access can see the list but cannot create, replace, or revoke passwords.

The password is 16 lowercase letters, displayed in four groups of four. It is shown once. Spaces and capital letters do not matter when entering it, so you can paste the grouped version into the app. Save it in a password manager if you need to keep a copy; the list cannot reveal it later.

Create an app password in webmail

  1. Sign in to webmail with your mailbox password, plus a code if mailbox 2FA is on.
  2. Open Settings > App passwords.
  3. Create a password with a name for the app or device.
  4. Enter your mailbox password when asked, then copy the new app password into the app.

Webmail asks for your mailbox password before creating or replacing an app password. After that check, it does not ask again for 15 minutes. An app password cannot be used for this check or to open the new webmail.

You can also start from Apps & devices, either the dashboard mailbox tab or Settings > Apps & devices in webmail. It shows which password the mailbox accepts and offers a Create an app password button for App passwords only. Its guided setup steps use the right password wording for the selected mailbox. See Connect TrekMail to Any Email App.

The creation email notice

Every new or replaced app password sends an email to the mailbox and to its recovery email, if one is set. The one exception is the first app password created together with a new mailbox. The notice names the app password so you can recognize the connection. It does not contain the secret. If you did not expect it, open the app-password list and revoke the named password.

Enter it in your mail, calendar, or contacts app

Keep the full mailbox address as the username. Put the app password in the field the app calls Password. It replaces the mailbox password for that connection; it is not a 2FA code.

Copy your mail server names from Apps & devices. The secure email ports are IMAP 993 with SSL/TLS, and SMTP 465 with SSL/TLS or 587 with STARTTLS. Use the same device's app password for incoming and outgoing mail. For the full connection reference, see IMAP & SMTP Settings.

Outlook

Enter the app password when Outlook asks for the mailbox password during setup. In manual IMAP setup, use it for both incoming and outgoing authentication. If Outlook keeps prompting, check that both saved passwords were updated. Follow the steps for your version in Connect Outlook.

Apple Mail

Open Apps & devices > Apple Mail to download the configuration profile. The profile never contains a password. macOS or iOS asks for it during installation; enter an app password for App passwords only. Manual setup uses the app password for both IMAP and SMTP. See Connect Apple Mail.

Thunderbird

Use the app password when adding an existing mail account. If you are updating an account, check the saved incoming and outgoing credentials so Thunderbird does not keep retrying an old password. The Thunderbird guide covers setup and saved-password troubleshooting.

iPhone, iPad, and Android

Create a separate password for the phone or tablet. Enter it in the mail account's incoming and outgoing password fields. This also applies when reading your mailbox in the Gmail app on Android: the password belongs to your mailbox here, rather than your Google account. See iOS and Android Mail Apps and Connect Gmail.

Calendar and contacts apps

CalDAV and CardDAV accept app passwords too, and require one in App passwords only mode. You can create a separate password for calendar and contacts sync, then enter it with your full mailbox address at the DAV address ending in /dav/.

Use the instructions for Apple Calendar and Contacts, iPhone and iPad, Android with DAVx5, or Thunderbird calendar and contacts. Mail app passwords also work for ManageSieve connections.

When the mailbox password is refused

An app that tries the mailbox password in App passwords only mode may show this exact error:

Sign-in failed. This mailbox accepts app passwords only: create one in webmail under Settings > App passwords.

Some apps show only password incorrect. Check the mode in Apps & devices, create an app password, and enter it in the failing app. If receiving works but sending fails, check the outgoing password too. Keep using the mailbox password to sign in to webmail.

When a device signs in with the correct mailbox password in App passwords only mode, we also email the mailbox, its recovery address, and the account owner. The email shows the device’s IP address and what it was used for, and is sent at most once a day per device. If you do not recognise the device, change the mailbox password.

Review, replace, or revoke a password

The list shows each password's name, when and where it was created, and its last use: time in UTC, protocol, and IP address. A mailbox can have 25 active app passwords. Revoked entries remain listed for 90 days and do not use an active slot. The list shows ten entries a page, active ones first; the arrows below it move between pages. Of the revoked entries, the 100 most recent are shown.

Choose Replace when the device should keep access but needs a new secret. The replacement keeps the name. The old password stops immediately, and apps using it are signed out until you enter the replacement. Copy the new password before closing its display.

Choose Revoke when a device should lose access. That password stops working and the app is signed out. Other devices using their own valid app passwords reconnect on their own. Revocation cannot be undone; create a new password if you later reconnect the device.

Every event that revokes app passwords

Event What stops working
Replace an app password The old secret for that entry. Enter the replacement in its app.
Revoke an app password That entry's secret.
An account admin sets a new mailbox password in the dashboard, API, or an AI agent All app passwords. This counts as a password reset.
The mailbox user changes their own password in webmail All app passwords only if they select Also revoke all app passwords, which is off by default.
Mailbox password reset or recovery All app passwords.
Mailbox sign-in is suspended All app passwords. Restoring sign-in does not restore them.
Mailbox is converted to a shared mailbox All app passwords.
Mailbox moves to Recently deleted All app passwords. Restoring the mailbox does not bring them back.

After access is available again, create new passwords for affected devices. Changing the mail app sign-in mode is a separate action: it changes which credentials are accepted rather than revoking the app-password list.

What app passwords do not affect

Webmail keeps using the mailbox password. The unified All inboxes view, the Message API with message tokens, migrations into the mailbox, mail rules and filters, and forwarding do not need an app password because of this feature. Separate actions such as suspending sign-in or resetting a password can still affect access; this list describes changing the mail app mode or managing an individual app password.

Shared mailboxes have no app passwords and no mail app sign-in mode of their own. Members open them using their own mailbox credentials, so create the app password on the regular member mailbox. See Shared Mailboxes in Mail Apps.

Classic webmail is the exception among browser mail clients: it signs in with an app password when the mailbox is in App passwords only. It never asks for a 2FA code. The new webmail and dashboard cannot be opened with an app password.

White Label mailboxes

The same feature works on branded hosts. Use the branded webmail and mail server addresses supplied for your mailbox. The credential is called an app password on White Label pages; its creation, replacement, and revocation work the same way.

Frequently asked questions

I lost the password. Can I see it again?

No. It is shown once. Use Replace on an active entry and put the new password into its app, or create a new entry and revoke the unused one. A revoked entry cannot be brought back.

Why did a device stop working after a password reset?

A reset or recovery revokes every app password, as does an admin setting a new mailbox password. Create a new one for each device and update its saved credentials. A normal change you make yourself in webmail keeps app passwords unless you select Also revoke all app passwords.

Why not just use the mailbox password?

It works in Mailbox password or app passwords, but sharing it across devices makes an individual connection harder to remove. A separate password lets you revoke one device without changing the mailbox password. In App passwords only, mail apps refuse the mailbox password entirely.

Is this the Gmail, Yahoo, or iCloud app password used for migrations?

No. A migration or Connected accounts setup may ask for an app password from Gmail, Yahoo, iCloud, AOL, or Outlook.com. That password belongs to the other provider and lets TrekMail connect to that external account. Create the password described on this page for apps connecting to your mailbox here. Migrations into that mailbox do not require one.

Related security and automation guides

Related articles

Jump to nearby guides that continue the workflow.

Sign in to TrekMail

Access your dashboard, mailboxes and DNS.

12 characters passwords match

Reset email sent

If an account exists for this email, we've sent password reset instructions.

By continuing, you agree to TrekMail's Terms and Privacy Policy.