# Email clients

> Set up a ZoPanel mailbox in Outlook, Thunderbird, Apple Mail, the Gmail app or any IMAP/POP3 client, with the exact servers, ports and encryption, and fix common errors.

Source: https://zopanel.net/docs/email-clients  
Updated: 2026-10-09

Every mailbox on a ZoPanel server works with any standard mail app over IMAP or POP3 for incoming mail and SMTP for sending. This page lists the exact settings, explains which apps can configure themselves, and walks through Outlook, Thunderbird, Apple Mail and the Gmail app. To create mailboxes first, see [Email](/docs/email).

## Before you start

You need:

- The **mailbox address** and its **password**. The password is shown once when the mailbox is created. If it is lost, change it with the key icon in the mailbox list on **Email** → the domain.
- The **server name**. Use the mail hostname that was set when the mail server was installed, such as `mail.example.com`. Automatic setup and the iPhone/Mac profile use this name.
- The domain's [DNS records](/docs/email#enable-email-for-a-domain) published, so that other servers can deliver mail to you.

**Important:** the mail services use the panel's certificate (**Settings → Panel domain & SSL**). That certificate names the panel domain and, when it points to the server, the mail hostname, so mail apps connecting to either name see no warning. Until the panel has a Let's Encrypt certificate, every mail app shows a certificate warning.

There are no app passwords. Mail apps sign in with the mailbox password itself, and [two-factor authentication](/docs/two-factor) applies to panel logins only, not to mailboxes.

## Server settings

The username is always the **full email address**, for example `anna@example.com`. Sign-in always requires encryption, and the authentication method is a normal password (not "Secure Password Authentication", NTLM or OAuth).

| Service | Server | Port | Encryption |
| --- | --- | --- | --- |
| IMAP (recommended) | mail hostname | 993 | SSL/TLS |
| IMAP | mail hostname | 143 | STARTTLS |
| POP3 | mail hostname | 995 | SSL/TLS |
| POP3 | mail hostname | 110 | STARTTLS |
| SMTP (sending) | mail hostname | 465 | SSL/TLS |
| SMTP (sending) | mail hostname | 587 | STARTTLS |

- **IMAP** keeps mail on the server and syncs folders (Inbox, Sent, Drafts, Junk, Trash) across all your devices. Use it unless you have a reason not to.
- **POP3** downloads the inbox to one device. Other folders are not synced.
- Outgoing mail always needs a login (**My outgoing server requires authentication**, using the same username and password). Port 25 is for server-to-server delivery and is not for mail apps.
- A message can be at most 50 MB, including attachments. Attachments grow by about a third when they are encoded, so keep attachments under about 35 MB.

The domain page on **Email** shows these values in the **Email client settings** card: **IMAP (SSL)**, **SMTP (STARTTLS / SSL)**, **POP3 (SSL)** and **Calendars & contacts**. The card shows the mail hostname as the server name.

## Automatic setup

ZoPanel answers the lookups that mail apps make when you type an address:

| App | What ZoPanel serves | Settings returned |
| --- | --- | --- |
| Thunderbird (and apps that use its format) | `https://example.com/.well-known/autoconfig/mail/config-v1.1.xml` | IMAP 993 SSL, POP3 995 SSL, SMTP 465 SSL |
| Outlook | `https://example.com/autodiscover/autodiscover.xml` | IMAP 993 SSL, SMTP 465 SSL |
| iPhone, iPad, Mac | a configuration profile you download from the panel | IMAP 993 SSL, SMTP 465 SSL |

The first two answers are served by **the domain's website**. They only work when the website for `example.com` is hosted on this server and the domain points to it. Every website on the server serves them once the mail server is installed. Outlook does not always use this lookup; if it cannot find the settings, enter them by hand.

## Outlook

### Outlook for Windows (classic)

1. Choose **File → Add Account**.
2. Enter the email address, open **Advanced options**, tick **Let me set up my account manually** and click **Connect**.
3. Choose **IMAP**.
4. **Incoming mail**: server = mail hostname, port `993`, encryption method **SSL/TLS**.
5. **Outgoing mail**: server = mail hostname, port `465`, encryption method **SSL/TLS**.
6. Leave **Require logon using Secure Password Authentication (SPA)** off in both sections, click **Next** and enter the mailbox password.

### New Outlook for Windows

1. Open **Settings → Accounts → Email accounts → Add account**.
2. Enter the email address and continue. If Outlook does not find the settings, choose **IMAP**.
3. Enter the password, open the advanced settings and fill in the IMAP server (port `993`, **SSL/TLS**) and the SMTP server (port `465`, **SSL/TLS**), with the full address as the username for both.

**Note:** the new Outlook synchronises non-Microsoft accounts through Microsoft's cloud, so the connections to your server come from Microsoft's addresses, not from your computer. Keep this in mind if you use [country blocking](/docs/geoblock) on all ports.

### Outlook for Mac

1. Choose **Outlook → Settings → Accounts**, click **+** and **New Account**.
2. Enter the email address. If Outlook asks for the provider, choose **IMAP/POP**.
3. Choose type **IMAP**, then enter the username (full address), password, the incoming server with port `993` and SSL on, and the outgoing server with port `465` and SSL on.
4. Click **Add Account**.

## Thunderbird

1. Open the menu **≡ → New Account → Email** (or **Account Settings → Account Actions → Add Mail Account**).
2. Enter your name, the email address and the password, then click **Continue**.
3. If the domain's website is on this server, Thunderbird finds the settings by itself. Choose **IMAP** and click **Done**.
4. Otherwise click **Configure manually** and enter the values from [Server settings](#server-settings), with **Authentication** set to **Normal password**.

## Apple Mail (iPhone, iPad and Mac)

### With the configuration profile

1. In the panel, open **Email** → the domain, and click the phone icon **iPhone / Mac profile (sets up this mailbox)** on the mailbox's row. You must be signed in to the panel in that browser, so on an iPhone open the panel in Safari, or download the file on a Mac and send it to the phone with AirDrop.
2. On iPhone or iPad, open **Settings**, tap **Profile Downloaded** and then **Install**. On a Mac, open **System Settings** and install it from **Profiles** (type "Profiles" in the search field).
3. Enter the mailbox password when asked. The password is not stored in the file.

The profile is not signed, so iOS and macOS show it as unverified. That is expected. Removing the profile removes the account.

### Manually

1. On iPhone or iPad, open **Settings → Mail → Accounts → Add Account → Other → Add Mail Account** (on recent iOS versions, Mail is under **Settings → Apps**). On a Mac, open **Mail → Add Account → Other Mail Account**.
2. Enter the name, email address and password.
3. Choose **IMAP** and enter the mail hostname as both **Incoming Mail Server** and **Outgoing Mail Server**, with the full address as the username for both.
4. Save. To check the ports, open the account's **Advanced** settings: IMAP `993` with SSL, and under **Outgoing Mail Server** (SMTP) port `465` with SSL.

## Gmail app on Android

1. Open the Gmail app, tap your profile picture and choose **Add another account → Other**.
2. Enter the email address and tap **Manual setup**.
3. Choose **Personal (IMAP)** and enter the password.
4. **Incoming server settings**: username = full address, server = mail hostname. If asked, port `993` with **SSL/TLS**.
5. **Outgoing server settings**: keep **Require sign-in** on, username = full address, SMTP server = mail hostname. If asked, port `465` with **SSL/TLS**.
6. Choose the sync options and finish.

Other Android mail apps use the same values.

## Sending from websites and scripts

Applications send mail through this server with PHP `mail()` or an SMTP login on port 587 (STARTTLS) or 465 (SSL/TLS) with a mailbox address and password. Direct connections from websites to other servers on port 25 are blocked, and every account has an hourly sending limit. See [Mail rules and limits](/docs/mail-rules#sending-limits).

## Troubleshooting

**Authentication failed / wrong password**

- The username must be the full address, not just the part before `@`.
- Reset the password with the key icon on the mailbox's row and enter the new one on every device. Devices that keep trying the old password count as failed logins.
- After 5 failed logins within 10 minutes, Fail2ban bans the client's IP for 1 hour (IMAP, POP3 and SMTP alike). An administrator can lift the ban with **Unban** on the **Security** page and can add the office IP under **Trusted addresses (fail2ban)**.
- Mailboxes of a suspended hosting account cannot sign in until the account is unsuspended.

**Certificate warning (name does not match, or untrusted)**

- Before **Settings → Panel domain & SSL** is set up, the server uses a self-signed certificate. Ask the administrator to set it up.
- If the warning says the name does not match, the app connects with a name that is not on the panel certificate. Use the mail hostname (or the panel domain) as the server name. If the mail hostname itself is refused, it did not point to the server when the certificate was issued: ask the administrator to click **Issue certificate** again in **Settings → Panel domain & SSL** once it does.

**Cannot connect at all (timeout)**

- Check that the mail hostname resolves to the server.
- Some office, hotel and mobile networks block mail ports. Try another network, or IMAP 993 and SMTP 465 instead of 143 and 587.
- If the administrator blocks countries on all ports, connections from those countries are dropped. See [Country blocking](/docs/geoblock).

**Sending fails: "Sender address rejected: not owned by user"**

You can only send as the mailbox you signed in with. Forwarder and mailing list addresses cannot be used as the From address over SMTP. Create a mailbox for the address you want to send from.

**Sending fails: "Sending limit reached (N recipients per hour), try again later"**

The hosting account reached its hourly limit. Wait until older messages leave the one-hour window, or ask the administrator about the limit. If you did not send that much mail, a website on the account may be sending spam.

**Mail is accepted but never arrives at Gmail, Outlook.com and others**

The administrator sees a warning on **Email** when the VPS provider blocks outgoing port 25. Until the provider opens it, or an **Outgoing mail relay (smarthost)** is configured, mail to other servers stays in the queue. Run **Mail delivery check** on the domain to find missing DNS records. See [Email](/docs/email).

**Mailbox full**

When a mailbox reaches its **Quota (MB)** (with a 10% grace margin), new messages are refused and senders get a bounce. Delete old mail and empty Trash and Junk, or raise the quota with the key icon. The **Usage** column shows how much space is used.

## Related

- [Email](/docs/email)
- [Mail rules and limits](/docs/mail-rules)
- [Webmail, calendars and contacts](/docs/webmail-calendar)
- [Panel settings](/docs/panel-settings)
- [Country blocking](/docs/geoblock)
- [Thunderbird: automatic account configuration](https://wiki.mozilla.org/Thunderbird:Autoconfiguration)
