Mailbox.org is a German paid email service (Heinlein Support GmbH) that supports standard IMAP, POP3, and SMTP across every plan starting from 1 EUR/month. The account can host addresses under @mailbox.org, a Mailbox.org-owned alias domain (over 100 available including @secure.mailbox.org, @privacyrequired.com, @vivaldi.net), or a fully custom domain. Standard mail clients work out of the box. The one setup nuance in 2026 is optional PGP-at-rest encryption for incoming mail, a Mailbox.org differentiator that adds complexity if enabled.
Setup context
Standard protocolsGerman privacy law
Mailbox.org uses standard IMAP, POP3, and SMTP: any mail client works. Optional server-side PGP encryption at rest is available and configured under Settings then Encryption; if enabled it does not change the client-side settings below but adds a PGP passphrase step during initial webmail login. Hosted in Berlin, subject to German data protection law (BDSG) and GDPR.
Quick reference: Mailbox.org server settings
All three protocols use SSL/TLS and full-address authentication. Custom domain mailboxes hosted at Mailbox.org use the same server hostnames as @mailbox.org addresses.
| Protocol | Server | Port | Encryption | Auth |
|---|---|---|---|---|
| SMTP | smtp.mailbox.org | 465 or 587 | SSL/TLS or STARTTLS | Full address + password |
| IMAP | imap.mailbox.org | 993 | SSL/TLS | Full address + password |
| POP3 | pop3.mailbox.org | 995 | SSL/TLS | Full address + password |
Mailbox.org SMTP settings
Mailbox.org SMTP uses smtp.mailbox.org on port 465 with implicit SSL/TLS or port 587 with STARTTLS. Authenticate with the full email address (native or custom domain) and the account password. If two-factor authentication is enabled, an app-specific password must be generated in the Mailbox.org web interface under Settings then Two-Factor Authentication.
Send limits vary by plan: Standard (1 EUR/month) permits 500 outgoing messages per day and up to 100 recipients per message. Premium (3 EUR/month) increases this and adds features like calendar sharing. Business plans have configurable higher limits. Cold-outreach volumes should use a dedicated relay like Mailgun or Postmark.
Mailbox.org IMAP settings
Mailbox.org IMAP uses imap.mailbox.org on port 993 with SSL/TLS. Same full-address username; same account password (or app password under 2FA). Mailbox.org supports IMAP folder hierarchy, message flags, server-side search, and message ID stability across sessions.
Storage per plan: 2 GB on Light (1 EUR/month), 10 GB on Standard, 25 GB on Premium, custom on Business. Files uploaded to Mailbox.org Cloud (the built-in Nextcloud-based file storage) count against the mail quota, so heavy attachment users should account for both.
Mailbox.org POP3 settings
Mailbox.org POP3 uses pop3.mailbox.org on port 995 with SSL/TLS. POP3 downloads messages and (by default) removes them from the server. Enable “leave copy on server” in the mail client for multi-device use, or use IMAP instead. There is no unencrypted or STARTTLS variant for POP3; only implicit SSL on 995.
POP3 is fully supported by Mailbox.org and works reliably for single-device or archival use cases. For everyday multi-device access, IMAP is the safer choice.
PGP encryption at rest (optional)
Mailbox.org offers a distinctive feature: server-side PGP encryption of incoming mail. When enabled, every message received is encrypted with the user’s PGP public key before being written to disk. The private key is stored on Mailbox.org’s servers but is itself encrypted with the account password, so a database breach exposes only encrypted-blob mail. This is optional and adds a passphrase step to webmail login; IMAP and SMTP client settings remain unchanged. Configure under Settings then Encryption.
IMAP, POP3 and SMTP Integration into Gmail

Configure Gmail with external IMAP/POP3/SMTP to send/receive emails from your custom domain through Gmail’s interface. Perfect for professionals managing multiple accounts in one place.
- Google Account β Security β App passwords (2-Step Verification must be enabled).
- Generate App Password for “Mail” β copy 16-character password.
- Gmail β Settings β See all settings β Forwarding and POP/IMAP.
- Enable IMAP β Save Changes.
- Incoming (IMAP):
[IMAP SERVER]:993 SSL| Outgoing (SMTP):[SMTP SERVER]:587 STARTTLS. - Use your full email + App Password (not regular password) for authentication.
β Gmail Result: Send/receive custom domain email directly in Gmail interface with full search/folder integration.
WordPress SMTP Plugin Configuration (WP Mail SMTP + MailPoet)


Configure SMTP in WordPress to fix email delivery issues and prevent spam folder placement. WP Mail SMTP and MailPoet ensure reliable transactional emails, contact forms, and newsletters deliver successfully.
- Install and activate WP Mail SMTP or MailPoet plugin from your WordPress dashboard.
- Navigate to WP Mail SMTP β Settings or MailPoet β Settings β Sending tab.
- Select “Other SMTP” as your mailer method from the dropdown.
- Enter SMTP settings with Port
587and STARTTLS encryption (when available). - Input your full email address and password in the authentication fields.
- Click Save Settings and send a test email to verify the configuration works.
β Result: WordPress contact forms, user registrations, and newsletter emails now deliver reliably via your SMTP server.
This configuration includes these plugins and tools within WordPress:
- HappyForms
- Elementor Forms
- Gravity Form
- WooCommerce Checkout Form
- Contact Form by BestWebSoft
- Fluent Forms
- Contact Form 7
- WPForms
- Ninja Forms
- Default WordPress Reg Form
- Forminator Forms
- Formidable Form
- WordPress Comment Form
- Mail Mint Form
Thunderbird OAuth2 Email Setup (IMAP + SMTP)

Secure IMAP & SMTP using OAuth2 token authentication in Thunderbird. This modern method eliminates password storage for enhanced security.
- Open Thunderbird β Account Settings β Account Actions β Add Mail Account.
- Enter your email address and click Continue to begin setup.
- Select IMAP protocol and choose OAuth2 authentication method.
- Thunderbird opens a browser window β log in to your provider β Grant access permissions.
- Automatic configuration applies: Incoming: use the IMAP server address from the settings table above, port 993, SSL
- Click Done β Thunderbird begins syncing folders and emails immediately.
OAuth2 advantage: Token-based authentication enhances security over traditional password methods while maintaining full functionality.
Outlook IMAP, POP3 & SMTP Setup (Auto + Manual)

Outlook configuration supports both automatic server detection and manual IMAP/POP3/SMTP settings for complete control over your email setup.
π Auto Setup (Recommended):
- Go to File β Add Account β Enter your email address + password.
- Outlook automatically detects IMAP, POP3, and SMTP server settings.
- Click Connect β setup completes in approximately 30 seconds.
βοΈ Manual Setup (Advanced Users):
- Authentication: Use your full email address + password for both servers
BlueMail Two-Factor Authentication + OAuth2 Setup
BlueMail security setup combines OAuth2 authentication with two-factor authentication (2FA) for maximum account protection.
- Open BlueMail β Account Settings β Security β Enable Two-Factor Authentication.
- Link your phone number or authenticator app for 2FA verification codes.
- Add email account β Choose OAuth2 or manual server configuration.
- Enter server details from the table above
- Complete login with 2FA code β enhanced security layer activated.
Apple Mail IMAP Configuration (iCloud + Manual)

Setup IMAP in Apple Mail for seamless synchronization across Mac, iPhone, and iPad devices with full folder support.
- Open Apple Mail β Mail β Add Account β Other Mail Account.
- Enter your name, email address, and password β click Continue.
- Select IMAP account type β Incoming server.
- Next: Outgoing server
- Click Sign In β Mail verifies settings and begins folder synchronization.
iOS Mail App Setup (iPhone/iPad)

iPhone/iPad Mail configuration syncs IMAP folders across all Apple devices with native push notifications.
- Go to Settings β Mail β Accounts β Add Account β Other.
- Enter name, email, password β Next.
- Account Type: IMAP β Incoming:
[IMAP SERVER]Port993SSL. - Enter your outgoing SMTP server and port.
- Next β Save β iOS verifies and syncs immediately.
Push enabled automatically: new emails appear instantly on Lock Screen.
Android Mail App Configuration

Android Gmail/Email app setup works with any IMAP/SMTP provider for native device integration.
- Go to: Settings β Accounts β Add Account β Email (or Gmail app).
- Enter email + password β Next.
- Account Type: IMAP
- Outgoing server details β Require authentication.
- Next β Sign In β Android syncs contacts/calendar if enabled.
Sync interval: 15min default (battery optimized) – change in Account Sync settings.
eM Client Manual IMAP & POP3 Sync Configuration

Configure your email settings on eM Client with either automatic setup or through precise IMAP/POP3 server settings for reliable email synchronization and full folder support.
- Click New Account β Mail
Authentication requires full email address + password for both incoming and outgoing servers.Click Next β Finish β Send/Receive All Folders to begin synchronization.
Mailbird OAuth2 IMAP & SMTP Integration

Secure Mailbird setup using OAuth2 authentication eliminates password storage while providing full IMAP/SMTP functionality.
- Mailbird β Add Account β Enter your email address to begin.
- Choose Manual Setup β OAuth2 authentication method from options.
- Browser opens your provider’s login page β enter credentials β Authorize Mailbird.
- Mailbird receives access token and automatically configures IMAP/SMTP servers.
- Setup completes β full email synchronization begins automatically.
Mailspring OAuth2 IMAP Configuration

Mailspring OAuth2 setup provides secure email access without storing passwords directly in the application.
- Add new email account β Select Custom IMAP configuration option.
- Incoming
IMAP SERVERand outgoingSMTP SERVER. - Mailspring prompts OAuth2 authorization via browser window for secure login.
- Log into your provider account and grant Mailspring access permissions.
- Mailspring automatically manages authentication tokens β seamless email access established.
Postbox Manual IMAP Synchronization

Postbox IMAP setup with manual synchronization control for precise email folder management and immediate updates.
- Add IMAP account β Enter IMAP Server details.
- Outgoing SMTP with full email authentication.
- Postbox connects and displays folder structure automatically.
- Right-click any folder β Get Messages for immediate manual synchronization.
- Manual sync updates local mailbox instantly with server changes (read status, deletions, organization).
SendBlaster SMTP Configuration (Bulk Email)

Bulk email SMTP configuration in SendBlaster requires precise server authentication for reliable campaign delivery.
- Open SendBlaster β Settings β SMTP Configuration section.
- Enter SMTP Server and Port: do not forget to Enable TLS encryption.
- Authentication: Your full email address + password (required).
- Click Test Connection β verify green success indicator appears.
- Save settings β SendBlaster ready for bulk email campaigns and newsletters.
MailJerry IMAP Real-Time Synchronization

MailJerry IMAP setup enables real-time access to email folders stored on your provider’s server across all devices.
- Incoming Server and encryption required.
- Authentication: Full email address + password for secure connection.
- Enable real-time folder synchronization settings in MailJerry preferences.
- Folders update instantly with new messages, read status, and deletions across devices.
Clean.email OAuth2 Synchronization Setup

Clean.email OAuth2 setup provides secure mailbox access without sharing passwords directly with the application.
- Add new account β Select OAuth2 authorization method.
- Your provider opens login portal β enter credentials securely.
- Grant Clean.email permissions for email read/write access.
- OAuth2 token enables real-time message management, filtering, and organization.
- Setup complete β Clean.email maintains secure, ongoing mailbox synchronization.
Common IMAP/POP3/SMTP Troubleshooting
- Authentication failed: Always use your complete email address, never just the username portion.
- Port blocked by ISP: Try alternative SMTP port as fallback.
- SSL certificate errors: Ensure certificate validation is enabled in client settings.
- Slow or no IMAP sync: Check folder subscriptions and enable all folders in client settings.
More Popular Email Settings Guides
| Guide | Region | Type |
|---|---|---|
| T-Online.de SMTP Settings | π©πͺ Germany | ISP |
| Fibertel.com.ar Webmail | π¦π· Argentina | ISP |
| QQ Mail SMTP Server | π¨π³ China | Global |
| Volny Mail Settings | π¨πΏ Czech Republic | ISP |
| Freemail.hu IMAP Settings | ππΊ Hungary | Regional |
| Etisalat/EIM Mail Settings | π¦πͺ UAE | ISP |
| Hotmail IMAP Settings | π Global | Global |
| 126.com IMAP Server Settings | π¨π³ China | Regional |
| Waoo Mail SMTP/IMAP | π©π° Denmark | ISP |
| GMX SMTP Server Settings | π Global | Global |
| 163.com IMAP Server Settings | π¨π³ China | Regional |
| Webmail.co.za IMAP Settings | πΏπ¦ South Africa | Regional |
Frequently asked questions
.smtp-faq-v2 { border: 1px solid #e5e7eb; border-radius: 10px; background: #fafafa; margin: 0 0 10px; padding: 0; transition: all 0.15s ease; overflow: hidden; } .smtp-faq-v2:hover { border-color: #d1d5db; background: #f5f5f5; } .smtp-faq-v2[open] { border-color: #0F6E56; background: #f4fbf7; box-shadow: 0 2px 12px rgba(15,110,86,0.08); } .smtp-faq-v2 > summary { cursor: pointer; padding: 16px 20px; font-weight: 600; color: #171717; font-size: 1rem; line-height: 1.4; list-style: none; display: flex; justify-content: space-between; align-items: flex-start; gap: 14px; user-select: none; } .smtp-faq-v2 > summary::-webkit-details-marker { display: none; } .smtp-faq-v2 > summary::marker { display: none; content: “”; } .smtp-faq-v2 > summary::after { content: “”; width: 10px; height: 10px; border-right: 2px solid #0F6E56; border-bottom: 2px solid #0F6E56; transform: rotate(45deg); flex-shrink: 0; margin-top: 6px; transition: transform 0.2s ease; } .smtp-faq-v2[open] > summary::after { transform: rotate(-135deg); margin-top: 10px; } .smtp-faq-v2 > *:not(summary) { padding: 0 20px 18px; color: #404040; line-height: 1.65; font-size: 0.95rem; margin: 0; } .smtp-faq-v2 > p:first-of-type { padding-top: 4px; } .smtp-faq-v2 a { color: #0F6E56; text-decoration: underline; }Does Mailbox.org offer a free plan?
No. Mailbox.org is paid-only, from 1 EUR/month on the Light plan with a 30-day free trial. There has never been a permanent free tier. The 1 EUR entry price is one of the lowest in the paid privacy email market.
What alias domains does Mailbox.org offer?
Over 100 alias domains are available, including @secure.mailbox.org, @privacyrequired.com, @vivaldi.net (Vivaldi Browser partnership), @jpberlin.de, @otago.de, and many themed domains. The list is in the Mailbox.org dashboard under Settings then Aliases. Aliases share the same mailbox and quota as the primary @mailbox.org address.
Do I need an app password for Mailbox.org?
Only if two-factor authentication is enabled on the account. 2FA is optional at Mailbox.org (unlike Fastmail, where it is the default). If 2FA is on, generate an app-specific password under Settings then Two-Factor Authentication and use it in mail clients. If 2FA is off, the account password works directly.
Can I use a custom domain with Mailbox.org?
Yes on Standard (1 EUR/month) and above. Configure the domain in the Mailbox.org dashboard, follow the DNS setup (MX, SPF, DKIM, DMARC), and provision addresses. Custom domain mailboxes use imap.mailbox.org, smtp.mailbox.org, pop3.mailbox.org just like native @mailbox.org addresses.
How does Mailbox.org compare to Posteo?
Both are German privacy providers at 1 EUR/month. Posteo is flat 1 EUR/month with no tiers and no custom domains, plus anonymous signup (no name required). Mailbox.org has plan tiers (1/3 EUR/month), custom domain support, a broader alias domain list, and integrated cloud storage. Mailbox.org is the fuller product; Posteo is simpler and more anonymous.
What is Mailbox.org’s PGP encryption at rest feature?
An optional feature where incoming mail is encrypted with the user’s PGP public key before being written to Mailbox.org’s servers. This means a database breach would expose encrypted-only mail. The private key is stored server-side but is itself encrypted with the account password. When enabled, webmail login prompts for an additional passphrase. IMAP and SMTP client settings do not change. This is a Mailbox.org differentiator versus most other providers.
Where is Mailbox.org webmail?
Webmail is at login.mailbox.org. The interface is a hosted OX App Suite (Open-Xchange) with mail, calendar, contacts, tasks, and cloud storage. Log in with the full email address and account password (plus 2FA code if enabled, plus PGP passphrase if PGP-at-rest is on).
About this guide
These Mailbox.org server settings were verified against Mailbox.org’s official documentation at kb.mailbox.org in July 2026. Hostnames and ports have been stable since Mailbox.org launched in 2014. Alias domain list is refreshed periodically; check the dashboard for the current set. SMTPedia re-verifies each provider quarterly.
About the Author

Alaa Β· LinkedIn
Email infrastructure specialist with 8+ years of hands-on experience in SMTP, deliverability, and email verification. Iβve configured and troubleshot mail systems across Postfix, Exchange, and cloud relays, managed IP reputation and warmup campaigns, and built verification pipelines processing millions of addresses. My work spans DNS authentication (SPF, DKIM, DMARC, BIMI), bounce handling, blocklist monitoring, and compliance frameworks including CAN-SPAM and GDPR. I write every article on SMTPedia to give email professionals, developers, and marketers the accurate, RFC-grounded reference they need.
About SMTPedia
SMTPedia is an independent email industry reference covering SMTP, IMAP, POP3, email deliverability, marketing platforms, DNS authentication, and email verification. Every article is researched from official provider documentation, IETF RFCs, and industry best practices. Settings and configurations are verified quarterly.
We are cited as a source by ChatGPT, Microsoft Copilot, and thousands of email professionals worldwide. Learn more about our editorial process.

