Connect a mail app

Use your EVERJUST mailbox in the mail app you already have: Apple Mail, Outlook, Thunderbird, the Gmail app, Samsung Email or any other app that takes IMAP and SMTP settings. What you read and send there is the same mail you see in the webmail. Folders, read and starred marks and replies stay in step, and what you send is filed in Sent.

Each device gets its own app password. It is a separate password that works only in mail apps, it is shown once, and you can remove it at any time. It is never your sign in password. Open Mail, click Settings, then Connect a mail app. Apple Mail installs a profile in a few taps. Every other app takes the same eight settings, which the page lets you copy.

Not every app has been tried on every device

Apps change their screens, and we have not run every mail app on every device, so a step in your app can be worded differently from the steps below. If an app will not connect, see If something does not work, or write to company@everjust.co.

Who can use it

  • Anyone with a mailbox, for a mailbox they own or share. A mail administrator can limit it to mail administrators, or turn it off for everyone, under Settings → Mail → Policy. See For administrators.
  • It is on unless an administrator switched it off. The feature switch is mail.imap, under Settings → Mail → Features. While it is off, Connect a mail app is not in Settings.
  • One mailbox for each password. A password opens the mailbox that was open when you made it. To add a shared mailbox, open it first. See Shared mailboxes.

Set up an app

  1. Open Mail, click Settings at the bottom of the sidebar, then Connect a mail app. You can also reach it from Settings → Connections, under Other ways to connect. The link ends with #mail-settings/connect.
  2. The page is titled Add this mailbox to your devices and names the mailbox it adds. To add a different mailbox, open that one first.
  3. Pick your app. The page puts the apps most likely to work on your device first. Each has a badge: One tap for Apple Mail, Just your address for Thunderbird when its settings can be found automatically, and Copy and paste for the rest.
  4. For Apple Mail, click Add to Apple Mail and follow Apple Mail. For any other app, click Create a password for and the app's name. The page shows the eight settings your app asks for, each with a copy button, and a Copy all button. The password line holds your new app password.
  5. Copy the password now. It is shown once. Click I have copied it when you are done. If you lose it, remove that device and make a new one.
  6. Enter the settings in your app, using the steps below.

The app password

An app password belongs to one person, one mailbox and one device. It is how a mail app proves it may open the mailbox, and it works nowhere else: it does not sign you in to your workspace.

  • Shown once. It has the shape xxxx-xxxx-xxxx-xxxx-xxxx: twenty lowercase letters and digits in five groups of four. Type it with or without the hyphens. EVERJUST keeps only a scrambled copy, so it cannot show it again.
  • Treat it like a key. Anyone who has it can read and send mail as you in that mailbox. Keep it private and remove any device you do not recognise.
  • Named for the app and the device. A label such as Apple Mail on iPhone or iPad comes from the app you picked and the browser you are using, so a phone set up from a laptop carries the laptop's name.
  • Limits. You can keep 10 at a time, unless your administrator sets another number, and make 5 in an hour.
  • No expiry, unless your administrator sets one. The exception is the password inside an Apple profile that nobody installs: it stops working after 24 hours. The first time an app signs in with it, it becomes permanent, or lasts as long as your administrator's longest life allows.
  • Wrong guesses are slowed down. Ten wrong passwords for one address from one internet connection within 15 minutes block that sign in for 15 minutes. There are wider limits for a whole connection, and for one address tried from many.
  • You get an email when one is made. The subject is A new app password was added to your mailbox. It names the device and the app, gives the time in UTC and the network address the request came from, and says how to remove it. It goes out only when one of your mailboxes can send.

Server settings

IMAP is how an app reads your mail, and SMTP is how it sends. Every app asks for the same eight values. Use these exact names, even when your address is on your own domain.

Setting Value
Incoming server (IMAP) imap.everjust.app
Incoming port 993
Incoming security SSL/TLS
Outgoing server (SMTP) smtp.everjust.app
Outgoing port 465
Outgoing security SSL/TLS
Username (both) Your full address, such as you@yourcompany.com
Password (both) The app password, not your sign in password
  • Authentication. If an app asks for a method, choose Normal password (also called Plain or Login). The connection is encrypted before the password is sent.
  • If your network blocks port 465, send on port 587 with STARTTLS instead. Everything else stays the same.
  • Encrypted only. Connections use TLS 1.2 or newer. There is no unencrypted port: no port 143, no port 25, and no POP.

Apple Mail

The profile is the one setup that needs no typing. It carries the account and a new app password, so one install adds the mailbox. EVERJUST creates the password when the profile downloads, and the download works once: click Add to Apple Mail again to add another device.

iPhone and iPad

  1. Tap Add to Apple Mail. When your device asks to allow a configuration profile, tap Allow.
  2. Open Settings and tap Profile Downloaded near the top. If you do not see it, open General, then VPN & Device Management.
  3. Tap Install, enter your passcode, and tap Install again. Your mailbox appears in Mail.

Mac

  1. Click Add to Apple Mail. The profile downloads.
  2. Open System Settings and choose Profiles (search for it if you cannot see it). Select EVERJUST Mail.
  3. Click Install and confirm. Your mailbox appears in Mail.

The install screen says Not Signed

EVERJUST does not sign the profile yet, so Apple shows Not Signed: it cannot name who made the profile. The profile is called EVERJUST Mail with your address, and its organization is EVERJUST.APP. Check both, then continue.

  • The link lasts five minutes. If it says the link was already used or has expired, click Add to Apple Mail again.
  • Installing again replaces the account. The profile has a fixed identity for each mailbox, so a second install updates the account and does not add another. Removing the profile from the device removes the account from Mail.
  • The file holds the password. Install it right away and delete the downloaded file. If you never install it, the password stops working after 24 hours.

Thunderbird

Thunderbird looks for its settings on your address's domain. When it can find them, you type your address and the app password, and it fills in the servers.

  1. On Connect a mail app, choose Thunderbird, create a password and copy it.
  2. In Thunderbird, choose Account Settings, then Add Mail Account.
  3. Type your name, your email address and the app password. If the card said Just your address, Thunderbird finds the servers by itself. If it asks, choose IMAP, then Done.
  4. If Thunderbird finds nothing, or the card said Copy and paste, choose Configure manually. Enter the values from the table above, choose SSL/TLS for both, then Done.

The setup service answers at autoconfig.everjust.app, and Thunderbird asks for it at autoconfig. followed by the part of your address after the @. For an address on your own domain it is found only when that domain publishes the autoconfig record that points to EVERJUST. Without it, use Configure manually. Thunderbird on Android takes the same settings.

Outlook

Outlook will not detect these settings by itself. EVERJUST answers its Autodiscover request at autodiscover.everjust.app, but current versions of Outlook mostly ignore that answer for an IMAP account, so plan on entering the settings.

  1. In Outlook, choose Add account and type your email address.
  2. When Outlook asks what kind of account it is, choose IMAP, or choose Advanced setup and then IMAP.
  3. Enter the values from the table above. Use the app password, not your sign in password. Leave secure password authentication (SPA) off.

Gmail app, Samsung Email and other apps

Gmail app (iPhone and Android). Gmail on the web is not offered here.

  1. Open the Gmail app, tap your picture, then Add another account.
  2. Choose Other, type your email address, and choose Personal (IMAP).
  3. Enter the app password, then the values from the table above.

Samsung Email.

  1. Open Samsung Email and choose Add account.
  2. Type your email address and the app password, then choose Manual setup and IMAP.
  3. Enter the values from the table above.

Any other app. Choose Another app on the page. Add an account, choose IMAP (not POP) if it asks, and enter the values with SSL/TLS for both servers. Use your full email address as the username and the app password as the password.

Your devices

Every password you make is listed under Your devices on the Connect a mail app page, with its name, when it was Added and when it was Last used (with the app's name when the app tells us), or Never used, and the one mailbox it opens. Read only marks a password that cannot send or change mail, and Not used for 60 days is a reminder to remove one you no longer need.

  • Remove a device and confirm. That app is signed out within seconds and its password stops working. You can add the app again later.
  • Remove every device signs out every mail app at once. It appears when you have more than one.
  • If you leave the company or lose your access to Mail, your passwords stop working with it.

Shared mailboxes

A shared mailbox is its own account in your app, with its own password.

  1. Open the shared mailbox from the account switcher at the top of the Mail sidebar.
  2. Go to Settings → Connect a mail app. The page names the shared address.
  3. Make a password and add the mailbox to your app, with the shared address as the username.

Every member can make a password for the mailbox. Access follows membership: a person who is removed from it can no longer use their password for it. See Shared team inboxes.

What syncs and what does not

In your app What happens
Folders Inbox, Sent, Drafts, Spam, Archive and Trash show up, and so do your own folders. Spam is marked as the Junk folder, so an app can show it under that name.
New mail It appears within a few seconds while the app keeps its connection open, and on the app's next check otherwise.
Read, starred and replied Read, starred (Flagged) and Answered marks stay in step with the webmail, both ways.
Moving mail Moving a message to another folder in the app moves it in the webmail, and the other way round.
Deleting An app that deletes a message moves it to Trash. Deleting it from Trash in an app removes it for good, with its attachments.
Sending Mail you send from an app is filed in Sent, so the webmail shows it. An app that also saves its own copy in Sent does not make a second one.
Your own folders An app can create, rename and delete folders at the top of a mailbox. Deleting one moves its messages to Archive first, and a folder with more than 1000 messages cannot be deleted from an app.

What does not carry over:

  • Labels. IMAP has no labels, so an app shows your folders and not your labels.
  • Drafts. The Drafts folder is read only in an app. The app keeps its own drafts on the device, and drafts you save in the webmail are not listed in it.
  • Other flags. Only Seen, Flagged and Answered are stored. Colored flags and keywords are accepted by the app and not kept.
  • Message source. An app sees each message as the platform rebuilds it from what it stored. The usual headers are there. The original headers of a received message, such as its authentication results, are not.
  • Contacts and calendars. Connect a mail app is mail only.
  • Sign in with Google or Microsoft. The mailbox uses app passwords only. Choose the password option in your app.

Sending from an app

Mail you send from an app goes through the same checks as the webmail. Your sending domain must be verified, addresses on the suppression list are skipped, and a copy lands in Sent. See Compose & send.

  • The From address is the mailbox the password belongs to. Another address, including an alias, is refused.
  • Reply-To is not carried. Replies go to the mailbox you sent from, whatever your app sets.
  • Signed or encrypted messages are refused. The platform rebuilds every message, so an S/MIME or PGP signature could not survive.
  • A message is refused with the reason, and never sent without an attachment.
  • Limits. 25 MB for a message, 100 recipients on a message, 300 messages an hour from a mailbox, and 1000 messages and 5000 recipients a day for each person. They are counted from what the mail server accepted, so moving or deleting the Sent copies does not reset them. When you reach one, the app is told to wait.

For administrators

Switch it off or on. Under Settings → Mail → Features, the switch is mail.imap. Off, Connect a mail app leaves Settings and every connected app is signed out on its next request. The passwords are not deleted: they stop working while the feature is off, and work again when it is back on.

Set the rules. Settings → Mail → Policy has a group named Connect a mail app.

Setting Choices Starts as
Who may connect a mail app Everyone with a mailbox, Mail administrators only, or Nobody Everyone with a mailbox
Most device passwords per person 1 to 100 10
Connected apps are read only On or off Off
Device passwords expire after (days) 0 to 3650, where 0 means they do not expire 0

A change applies to the next password someone makes. A password that already exists keeps its limits and keeps working until it is removed. With Connected apps are read only on, a new password can read mail only: the app is refused when it sends, marks mail read or starred, moves or deletes mail, or creates a folder. A person who may not connect sees a sentence instead of the app cards, such as "Your administrator has turned off connecting mail apps." Settings → Who can do what shows the rule, read only, as Connect a mail app (device passwords). Every change to the policy is recorded.

See and remove everyone's passwords. On Settings → Connect a mail app, a mail administrator has Everyone's devices. Show everyone's devices lists every person's passwords with the person, the app, when it was added and last used, and its mailbox, 100 at a time. Remove ends one, for a person who left or a device that was lost, and the app is signed out within seconds. A password also ends when its person is archived or loses the Mail role.

An AI agent cannot create or read an app password, whatever its role. People make them in the webmail. See Mail administration & deliverability for the other mail switches.

If something does not work

You see What it means What to do
Authentication failed, or the app keeps asking for the password The app has your sign in password, a typo, or a password you removed. Use your full address as the username and the app password as the password. Check Your devices, or make a new password.
Authentication failed with the right password Repeated wrong passwords blocked sign in for 15 minutes. A blocked sign in gets the same answer as a wrong password. Wait 15 minutes, then try again.
A certificate warning, or the name does not match The app built the server name from your domain, such as imap.yourcompany.com. Use imap.everjust.app and smtp.everjust.app exactly.
Cannot connect, or the connection times out A network or firewall blocks the port, or the port or the security is wrong. Use 993 for IMAP and 465 for SMTP, both with SSL/TLS. If your network blocks 465, use 587 with STARTTLS. Try another network to see whether yours is the cause.
The app signs out, or says your session ended The password was removed or expired, your access changed, or an administrator switched Connect a mail app off. Look in Your devices and make a new password, or ask a mail administrator.
A folder is missing A label is not a folder, the app has not refreshed its folder list, or you made the password for a different mailbox. Refresh the folder list in the app. Your labels stay in the webmail. A password opens one mailbox, so add each mailbox, shared ones too, as its own account.
The app reads but cannot send, move or delete The password is read only because of the workspace policy. Ask an administrator to switch off Connected apps are read only, then make a new password.
You cannot send as that address The From address is not the mailbox the password belongs to. Set From to the mailbox address. An alias cannot send.
Sending is refused for size, recipients or a wait You passed a limit in Sending from an app. Wait, or split the message, then send again.
You already have 10 app passwords, or too many were made in the last hour You reached the cap, or the number your administrator set, or 5 an hour. Remove a device you no longer use under Your devices, or try again later.
Connect a mail app is not in Settings, or a sentence replaces the app cards The feature or the workspace policy is off for you. Ask a mail administrator.

Last reviewed: 2026-10-02

Need a hand with this? company@everjust.co — a human answers.