Setup guide
What is an app password? Connect your mailbox in 30 seconds
An app password is a single-purpose password your email provider generates, so an app like InboxPilot can sign in over IMAP without ever seeing your real login. If you ever want to cut access, you delete the app password — your normal mailbox password stays untouched.
InboxPilot uses that access read-only first: scans never mark, archive, move, or delete anything. Cleanup happens only after you approve specific rules — and important mail like clients, payments, security alerts, and legal notices stays visible no matter what.
Gmail
Gmail rejects your normal password over IMAP. You need a free Google app password — it takes about 30 seconds once 2-Step Verification is on.
- Make sure 2-Step Verification is on for your Google account (myaccount.google.com/security). App passwords only exist when 2FA is enabled.
- Open myaccount.google.com/apppasswords in a browser.
- Name it “InboxPilot” and click Create.
- Copy the 16-character password Google shows you and paste it into the password field below — this replaces your normal Gmail password for InboxPilot only.
You can revoke the app password at any time without changing your real Gmail password.
Microsoft 365
Microsoft 365 / Outlook.com mailboxes use IMAP host outlook.office365.com. Depending on how your Microsoft account is configured, an app password or one-click sign-in will work.
- Work or school account: check whether app passwords are still allowed — many organizations disable them (“legacy authentication”).
- Personal Outlook.com: open account.microsoft.com/security → Advanced security options → App passwords (shown only if legacy auth is enabled).
- If no app-password option exists, your tenant requires modern OAuth sign-in instead — InboxPilot offers read-only one-click Microsoft sign-in where that is enabled.
- Paste the app password below and use your full email address as the username.
If IMAP login keeps failing with a correct app password, your organization has likely switched to OAuth-only sign-in.
iCloud
Your Apple ID password will always fail over iCloud IMAP — Apple requires an app-specific password for third-party apps. That is normal, not an error on your side.
- Sign in at account.apple.com with your Apple ID.
- Go to Sign-In and Security → App-Specific Passwords.
- Click the + button, name it “InboxPilot”, and copy the generated password (format: xxxx-xxxx-xxxx-xxxx).
- Paste it below and keep your full @icloud.com address as both email address and username.
App-specific passwords can be revoked separately, so your real Apple ID password never leaves your hands.
Custom IMAP
Independent providers (Fastmail, Zoho, Purelymail, self-hosted servers) issue app passwords from their web settings so you never share your real login.
- Fastmail: Settings → Privacy & Security → App passwords (app.fastmail.com/settings/security).
- Zoho: Security → App Passwords. For other providers, search “<your provider> app password IMAP”.
- Enter the IMAP host your provider documents — port 993 with SSL/TLS is the standard.
- Some hosts want a username different from your email address; your provider’s IMAP docs say which.
Have your app password?
Create a free account, paste it into the connect form, and run your first read-only scan in minutes.
Start free — read-only firstFree plan: 1 mailbox, daily digest. No card required. See pricing