
# Providers

| Provider | IMAP host | SMTP host | Works with fob-email |
| --- | --- | --- | --- |
| [Gmail and Google Workspace](#gmail-and-google-workspace) | `imap.gmail.com` | `smtp.gmail.com` | Yes, with an app password |
| [Yahoo Mail](#yahoo-mail) | `imap.mail.yahoo.com` | `smtp.mail.yahoo.com` | Yes, with an app password |
| [iCloud Mail](#icloud-mail) | `imap.mail.me.com` | `smtp.mail.me.com` | Yes, with an app-specific password and different usernames |
| [Fastmail](#fastmail) | `imap.fastmail.com` | `smtp.fastmail.com` | Yes, with an app password, on plans that include IMAP |
| [Outlook and Microsoft 365](#outlook-and-microsoft-365) | | | **No.** Requires OAuth |
| [Other providers](#other-providers) | Ask your provider | | If they accept a password over IMAP |

The provider is where your mailbox is **hosted**, not the app you read it in. Gmail read in the Outlook app is still Gmail. For a company address, ask your IT team who hosts it.

## Gmail and Google Workspace

1. Turn on **2-Step Verification** in your [Google Account](https://myaccount.google.com/security). App passwords don't appear without it.
2. Open [App passwords](https://myaccount.google.com/apppasswords), enter a name such as `fob-email`, and create it.
3. Copy the 16-character password. The spaces Google shows are optional.

<Screenshot alt="Google Account: the App passwords page with a new password named fob-email (value blurred)" />

```bash
fob-email config accounts add personal \
  --imap-host imap.gmail.com --imap-user you@gmail.com \
  --imap-pass "<app password>" --smtp-host smtp.gmail.com
```

- IMAP is always on for personal Gmail.
- **Google Workspace:** your administrator can turn off IMAP or app passwords for your domain. If the App passwords page isn't available or sign-in fails, ask them.
- App passwords are also unavailable on accounts in Advanced Protection, and on some accounts that use only security keys. See [Google's app-password help](https://support.google.com/mail/answer/185833).
- Changing your Google password revokes your app passwords. Create a new one and run `config accounts add` again.
- Gmail folders have paths like `[Gmail]/Sent Mail` and `[Gmail]/All Mail`. Quote them on the command line. `fob-email folders list` shows the exact names.

## Yahoo Mail

1. Open [Yahoo Account Security](https://login.yahoo.com/account/security).
2. Choose **Generate app password** (it may be labelled **Create app password**), name it `fob-email`, and copy the password.

```bash
fob-email config accounts add yahoo \
  --imap-host imap.mail.yahoo.com --imap-user you@yahoo.com \
  --imap-pass "<app password>" --smtp-host smtp.mail.yahoo.com
```

Yahoo requires your full email address as the username. See [Yahoo's IMAP settings](https://help.yahoo.com/kb/sln4075.html).

## iCloud Mail

1. Sign in at [account.apple.com](https://account.apple.com/). Your Apple Account needs two-factor authentication.
2. Under **Sign-In and Security**, choose **App-Specific Passwords**, create one named `fob-email`, and copy it.

iCloud uses **two different usernames**: the IMAP username is the part of your iCloud Mail address before the `@`, and the SMTP username is the full address. iCloud SMTP also uses port 587 with STARTTLS rather than 465.

```bash
fob-email config accounts add icloud \
  --imap-host imap.mail.me.com --imap-user you \
  --imap-pass "<app-specific password>" \
  --smtp-host smtp.mail.me.com --smtp-port 587 --no-smtp-secure \
  --smtp-user you@icloud.com
```

`--no-smtp-secure` means "don't start with TLS": the connection switches to TLS with STARTTLS instead. If the short IMAP username is rejected, Apple suggests trying the full address. Your Apple Account sign-in address can be different from your iCloud Mail address; use the mail address. See [Apple's iCloud Mail settings](https://support.apple.com/en-us/102525) and [app-specific passwords](https://support.apple.com/en-us/102654).

Changing your Apple Account password revokes app-specific passwords.

## Fastmail

1. In Fastmail, open **Settings → Privacy & Security**. Under **Connected apps & API tokens**, choose **Manage app passwords and access**, then **New app password**.
2. Keep the default access, **Mail, Contacts & Calendars**, which includes IMAP and SMTP. Copy the password.

```bash
fob-email config accounts add fastmail \
  --imap-host imap.fastmail.com --imap-user you@fastmail.com \
  --imap-pass "<app password>" --smtp-host smtp.fastmail.com
```

Fastmail's Basic plan doesn't include IMAP or SMTP, so it can't create app passwords. See [Fastmail's app passwords](https://www.fastmail.help/hc/en-us/articles/360058752854-App-passwords) and [server names and ports](https://www.fastmail.help/hc/en-us/articles/1500000278342-Server-names-and-ports).

## Outlook and Microsoft 365

**fob-email cannot connect to Outlook.com, Hotmail, Live or Microsoft 365 (Exchange Online) mailboxes.** Microsoft requires OAuth sign-in for IMAP on these services, and fob-email only supports passwords. An app password doesn't help.

- Outlook.com requires OAuth for IMAP. See [Microsoft's Outlook.com settings](https://support.microsoft.com/en-us/outlook/pop-imap-and-smtp-settings-for-outlook-com).
- Microsoft 365 has turned off password (Basic) authentication for IMAP. See [Microsoft's Exchange Online guidance](https://learn.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/deprecation-of-basic-authentication-exchange-online).

A company-run Exchange server may still accept passwords: ask your administrator for its IMAP settings.

## Other providers

Any IMAP server that accepts a username and password should work. From your provider's help pages (search for "IMAP settings" or "set up another email client"), you need:

- The IMAP host and port, and whether it uses SSL/TLS (the usual is port 993 with SSL/TLS)
- The SMTP host and port, if you want to send. Port 465 means SSL/TLS (the default); port 587 means STARTTLS, so add `--smtp-port 587 --no-smtp-secure`
- The username, usually your full address
- Whether you need an app password, which is common when two-factor sign-in is on

If your server doesn't use TLS on IMAP, add `--no-imap-tls` and the plain-text port your provider gives you. Only do this on a network you trust.
