Documentation

DocumentationConnecting your AccountsTwo-factor authentication and app passwords

Two-factor authentication and app passwords

Gmail, Office 365, and Outlook.com accounts sign in through your browser, so two-factor prompts happen there and Mailspring never needs your password. For providers that use a plain IMAP password, Mailspring can’t answer a two-factor challenge itself — instead you use an app password. Some providers require an app password for every email client, whether or not you use two-factor authentication.

What is an app password?

An app password is a password generated specifically for use with a third-party application. Using an app password is more secure than using your regular account password.

What are the security benefits of using app passwords?

If you use an app password, you don’t have to give your regular password to third-party applications. This reduces the risk of your regular password being stolen by malware. Additionally, app passwords are generated with many random characters, which makes it more difficult for malware programs to guess the password. In the unlikely case that an app password is successfully stolen by malware, you can easily revoke access by deleting the app password. Your other passwords will still be safe, so you don’t have to go through the trouble of changing your password everywhere.

Which providers require an app password?

Some providers always require an app password, while others only require an app password if you’ve enabled two-factor authentication (2FA). As we discover which providers have these requirements, we will list them here, but there may be others that are not currently listed.

Providers that require an app password with 2FA:

  • iCloud

Providers that always require an app password:

Gmail and Microsoft accounts don't need app passwords. Mailspring signs in to Google and Microsoft (Office 365, Outlook.com, Hotmail, Live) using OAuth in your browser, which works with two-factor authentication out of the box.

How do I generate an app password for my provider?

iCloud

  1. Go to https://appleid.apple.com/
  2. Click Security, then Edit. Create an app password. This is the password you should use with Mailspring.
  3. In Mailspring, connect an iCloud account and use this password instead of your regular password when prompted.

You can read more about this process from Apple here: Using app-specific passwords - Apple Support

Fastmail

  1. Open the Settings → Password & Security screen. Log in if prompted.
  2. Enter your password at the top in order to be able to edit the settings.
  3. Scroll down to the App Passwords section and click the New App Password button.
  4. In the Device drop-down, choose custom and enter “Mailspring”.
  5. Make sure the “Access” drop-down has Mail, Contacts & Calendars selected
  6. Click Generate Password and copy the shown password
  7. In Mailspring, connect a Fastmail account with IMAP and use this password instead of your regular password.

Other services

How to Update Your Password

If you’ve already connected an account, go to Preferences > Accounts, and select the account you want to change the password for. Click Update Connection Settings... In the window that pops up, enter the new password in the Password field.

You may need to quit and restart Mailspring in some cases to see the change take effect.

Can’t find what you’re looking for?

Ask in the Mailspring community — the team and other users are there to help.

Visit the Community