Protected Mail and app passwords
Give each email application its own password so you can revoke access without changing your Webmail password.
Where to find it: Account > Security Settings > Protected Mail; mailbox details also expose the relevant controls.
Available to: The account user for their own account, root, and the owning reseller, subject to the assigned feature profile and installed services.
What this page does
Protected Mail separates interactive Webmail use from IMAP, POP3, and authenticated SMTP app access. App passwords are issued per mailbox and can be revoked without revealing or reusing an existing app password.
Before you start
Review the account two-factor authentication state shown by the page. Confirm the target mailbox and plan how each existing mail client will receive its new password. Keep the new value private; it is shown only once.
App password operation
Select the mailbox, enable the supported protection state, and create a clearly named app password for a particular client or device. Copy it at creation and enter it in that client. Existing values cannot be displayed again; revoke a lost value and create a replacement.
Review recent authentication events when a client cannot connect. Source-IP policies, mailbox login/send suspension, and server protections still apply. An app password does not bypass those controls.
How to use it
- Open Protected Mail and review the two-factor authentication status.
- Find the mailbox using search and inspect its protection/app-password state.
- Create a password for one device, save it securely, and test receiving and sending.
- Revoke old or unused passwords after confirming the replacement works.
Webmail two-factor mode
The Webmail two-factor mode can be off, account, or mailbox. Off disables only the Webmail step-up challenge; it does not turn off Protected Mail or its requirement for external clients to use app passwords. Account mode uses the account’s configured two-factor secret. Mailbox mode requires the mailbox’s own verified two-factor setup.
When updating through the API, omitting twofa_mode preserves the current mode. In bulk mailbox mode, every selected mailbox must already have the individual setup required by the operation. Review per-mailbox results rather than assuming all selected mailboxes changed.
Result and next check
The configured app can use the mailbox, revoked credentials no longer work, and Webmail remains available through its supported sign-in flow.
Theme color