Web

Outlook Email Setup: IMAP and SMTP for Business Email

Talha Aslan 19 min read 3 views

How do you do an Outlook email setup with IMAP and SMTP?

An Outlook email setup connects a business address (such as info@example.com) to the Outlook app. For a mailbox at your hosting company, you enter the address, the password, an incoming IMAP server and an outgoing SMTP server. For a Microsoft 365 mailbox, you type only the address and let Microsoft handle sign-in.

This guide is for site owners, ecommerce managers and developers who run a custom domain. First, we show you how to tell your account type. Then we walk through desktop and mobile setup, and finally we list the errors you will meet most often, in the order you should check them.

We are a digital marketing and web team, not a hosting company. So our explanations rest on Microsoft's page on adding an email account to Outlook, the cPanel mail client documentation and RFC 8314. When your provider gives you a server name or port, that value always wins.

We do not cover DNS records such as MX, SPF, DKIM and DMARC here. For that side, read our business email with a custom domain guide.

What do you need before you start your Outlook email setup?

The setup takes only a few minutes, but missing details can cost you hours. So gather everything first. Your hosting panel or your provider's welcome email should give you the values below.

  • The full email address, for example info@example.com.
  • The mailbox password. If an admin gave you a temporary one, sign in to webmail first and change it.
  • The name of the incoming server and its IMAP port.
  • Also the outgoing server name and its SMTP port.
  • Finally, the encryption type: SSL/TLS or STARTTLS.

Also find out where the mailbox lives. If it sits at your hosting company, you use IMAP and SMTP. If you use Microsoft 365 or Google Workspace, the method differs, and the next sections explain how.

Check the mailbox quota in your hosting panel as well. A full mailbox stops receiving new mail, so the setup looks broken even when every Outlook value is right. Clear old messages or ask your provider for more space.

Finally, store the password in a password manager. If you need a strong one, our password generator can create it.

What is the difference between a hosting mailbox and a Microsoft 365 mailbox?

Both account types look the same inside Outlook, but they work differently behind the scenes. A hosting mailbox connects to the mail service for your domain. A Microsoft 365 mailbox lives in Microsoft's Exchange Online service. Therefore the setup path differs too.

FeatureHosting mailboxMicrosoft 365 mailbox
Who runs itYour hosting providerMicrosoft (Exchange Online)
Adding it to OutlookAddress, password and IMAP/SMTP valuesAddress and Microsoft sign-in
AuthenticationPassword; sometimes an app passwordModern authentication (OAuth 2.0)
Who gives you the settingsThe hosting providerYour Microsoft 365 admin
Who to ask when it failsHosting supportYour Microsoft 365 admin

According to Microsoft's Exchange Online documentation, Outlook for Windows reaches an Exchange mailbox over MAPI/HTTP, not IMAP. So do not try to add a Microsoft 365 mailbox by hand as an IMAP account.

How does the Outlook email setup work on a desktop, step by step?

Microsoft's page describes the manual route for classic Outlook like this: choose File, then Add Account. Type your address, open Advanced options and tick the box that lets you set up your account manually. Then pick IMAP as the account type.

  1. Open Outlook and choose Add Account from the File menu.
  2. Type your full email address.
  3. Open Advanced options and tick the manual setup box.
  4. Select Connect, then choose IMAP as the account type.
  5. Enter the incoming and outgoing server names, ports and encryption type.
  6. Type your password and wait for the connection test to finish.

The new Outlook and classic Outlook use different screens. If your screen shows other labels, enter the same values in the matching fields. Menu names can also change between versions.

What is the difference between IMAP and POP3?

IMAP keeps your mail on the server and syncs it across devices. POP3 downloads mail to one device. The cPanel documentation explains it this way: if you use the POP3 port, your mail client downloads all messages and then removes them from the server. So IMAP suits anyone with more than one device.

ComparisonIMAPPOP3
Where the mail staysOn the serverUsually on the device that downloaded it
Several devicesWorks well, folders syncAwkward, one device takes the mail
Server quotaCan fill up, needs cleanupFills up more slowly
BackupA copy stays on the serverYou keep the backup yourself
Secure port993 (SSL/TLS)995 (SSL/TLS)

In short, choose IMAP for a shared mailbox or for a phone plus a laptop. Otherwise, use POP3 only when your provider asks for it.

Which ports and encryption settings should you choose?

RFC 8314 recommends implicit TLS for mail access, which starts encryption right away. That means port 993 for IMAP and port 995 for POP3. For sending, both 465 (implicit TLS) and 587 (STARTTLS) are valid. The standard also says there is no significant security difference between the two when implementations are correct.

The cPanel "Set Up Mail Client" page also strongly recommends the secure SSL/TLS setting. It lists IMAP 993, POP3 995 and SMTP 465 for SSL/TLS. Meanwhile, it marks the plain-text settings as not recommended.

SettingExample valueNote
Incoming server (IMAP)mail.example.comYour provider gives the real name
IMAP port and encryption993, SSL/TLSRFC 8314 recommendation
Outgoing server (SMTP)mail.example.comOften the same name at hosting companies
SMTP port and encryption465 SSL/TLS or 587 STARTTLSPick what your provider supports
Usernameinfo@example.comUsually the full address

However, treat these values as examples. Use the value your hosting provider gives you.

The port and the encryption type must also match. For example, if you try port 465 with STARTTLS, or port 587 with implicit TLS, the connection fails. Follow the pairing in your provider's guide exactly.

What should you type in the username and password fields?

The cPanel documentation uses the complete email address as the username. So you type "info@example.com", not just "info". Some providers use another username format, so follow your welcome email.

One common mistake is a trailing space when you copy the password. Caps lock and keyboard layout also cause trouble. Test the password in webmail first. If you can sign in there, the password is right and the problem sits in your Outlook settings.

The outgoing server needs authentication too. Some setup screens copy the incoming details to the outgoing server, but not all do. So check the outgoing authentication option in the account settings.

How do you add a Microsoft 365 account to Outlook?

For a Microsoft 365 mailbox, you do not enter server names or ports. In Outlook, choose File, then Add Account, and type your address. Then sign in through the Microsoft window that appears. If your organization uses multi-factor authentication, then you approve the prompt there.

Microsoft says Basic authentication is now disabled in Exchange Online, including for POP and IMAP. The same page also states that Microsoft has no plan for Outlook clients to support OAuth for POP and IMAP. So the manual IMAP route rarely works for a Microsoft 365 account.

After setup, your mailbox syncs from Microsoft's servers. Therefore the mail settings in your hosting panel do not affect this account. If your domain's MX record points to Microsoft, your mail already lives there. When you are unsure which service you use, ask your admin or your domain provider.

If the account will not add, do not keep changing settings yourself. A policy on the admin side is the usual cause, such as conditional access or a device rule. In that case, write to your Microsoft 365 admin.

What are modern authentication and app passwords?

Modern authentication uses OAuth 2.0 and short-lived access tokens instead of giving your password to the mail app. Microsoft's documentation says these tokens have a limited lifetime and apply only to the app and resource they were issued for. As a result, a stolen token cannot be reused elsewhere.

An app password is a different thing. Microsoft describes it as a randomly generated, one-time-use password that gives temporary access to your online accounts. Some providers, such as Gmail and iCloud, may require it, and so may IMAP accounts. Instead of your normal password, you get it from the website of the provider that hosts your account.

Your hosting provider decides whether your mailbox needs an app password. Many hosts accept the normal mailbox password, but that is not a rule. To be sure, read the provider's help page.

How does the Outlook email setup work on a phone?

The Outlook mobile app follows a similar flow. Open the app, choose Add Account and type your address. If the app recognizes the account, it finishes the remaining steps itself. If it does not, it asks for server details, and the name of that screen varies by version.

For manual entry, use the same values as on the desktop. That means 993 with SSL/TLS for IMAP, and the port and encryption type your provider gives for SMTP. Typos are also easier on a phone. So copy the server name from your welcome email and paste it.

Check notification settings afterward. If both Outlook and the phone's built-in mail app open the same mailbox, you will see each message twice. Using only one app keeps things simpler.

Webmail in a browser is another option. If you only need to read a few messages, it works well. Besides, it keeps your password off the device.

Is manual setup still needed when automatic configuration exists?

Some providers offer automatic configuration for mail clients. The cPanel documentation mentions downloadable configuration scripts for the clients it lists in its "Mail Client Automatic Configuration Scripts" section. Windows Live Mail, iOS and macOS Mail appear as examples there.

If your hosting panel does not list Outlook, you set it up by hand. That is not a bad thing, because manual setup lets you see every value, so you know which field to check when something breaks.

Even when automatic setup exists, check the result. For example, it may pick POP3 when you wanted IMAP. So review the protocol type and the ports in the account properties.

In a company, however, your admin may push a central policy. In that case you may not need to type your own values. If you are unsure, ask your admin.

How do you use a shared mailbox (info@) in a team?

The simplest way to share one address is to add the same IMAP mailbox to several people's Outlook. IMAP keeps mail on the server, so everyone sees the same messages. For example, when one person marks a message as read, that status often shows up for the others too.

However, this method has limits. It is hard to track who replied to which message. In addition, you share one password among several people. When someone leaves, you must change the password and update every device.

  • Do not share the password in chat apps; use a password manager.
  • Put the replying person's name in the signature to reduce double replies.
  • When the team grows, consider a system with a shared inbox.

Forwarding and catch-all addresses are separate topics, and we do not cover them here.

How do you keep your old mail when you move to Outlook?

First, find out where your mail lives now. If your old program uses IMAP, the mail already sits on the server, and you only add the same account to Outlook. If it uses POP3, the mail may exist only on that computer. In that case, back it up before you move anything.

You can move old POP3 mail into a new IMAP account. Use the import option in Outlook, or drag folders between two accounts. However, large archives take a long time and can fill the quota.

Take these three steps before you move anything.

  1. Copy the old program's data file to an external drive.
  2. Confirm the mailbox quota has enough space.
  3. Try a small folder first, then move the rest.

Also, do not uninstall the old program until the move is done. Watch the new setup for a few days to confirm it runs well.

What do you do when you get an authentication error?

An authentication error means the server did not accept your address or password. For SMTP, RFC 4954 defines code 535 as "authentication credentials invalid" and code 530 as "authentication required". Most of the time, the cause is a value you typed.

  1. Try the password in webmail. If you cannot sign in, reset it.
  2. Confirm the username is the full email address.
  3. Check that authentication is on for the outgoing server.
  4. Make sure the port and encryption type match; 993 with STARTTLS fails.
  5. If the password has special characters, test with a temporary simple one.
  6. If it still fails, write to your provider's support team.

Also write down the full error text after each try. The code and the server name help support solve the problem faster. When you take a screenshot, make sure your password does not show.

Some servers block your IP address for a while after many failed attempts. That is a security measure, and only the provider can lift it. So wait, then open a support ticket.

Why can you receive mail but not send it?

If receiving works and sending fails, the problem usually sits in the outgoing server settings. Your incoming details are right, so you only review the SMTP side. Three causes stand out: authentication is off for the outgoing server, the port and encryption do not match, or the provider blocks the connection from your network. Some internet providers also restrict certain outgoing ports.

Sending can look successful while the recipient rejects the message. In that case, the bounce notice shows a sender rejection. The cause is often that the sender domain cannot be verified. For example, an SPF, DKIM or DMARC record may be missing or wrong.

That is a DNS setting for your domain, not an Outlook setting. You can inspect the records with our DNS lookup tool. To fix them, follow the business email guide and ask your hosting provider.

In addition, the "from" address and the signed-in account should match. If you write another address as the sender, some servers refuse the message.

What does a certificate warning mean and what should you do?

If Outlook warns that the server certificate is not trusted, or shows a name mismatch, the server name you connect to does not match the name on the certificate. RFC 8314 requires clients to validate the server certificate. So clicking "Yes" to move past the warning is not a good fix.

The usual cause is this: you type your domain (example.com) as the server name, but the certificate covers "mail.example.com". Using the name your provider gave you often clears the warning. If the certificate has expired or is installed wrongly, only the provider can fix it.

The warning is common because the mail server name often differs from the website name. Your website may have a valid SSL certificate while the mail server certificate is a separate matter. So do not assume the mail certificate is fine just because the site opens without errors.

Technical readers can instead view the certificate from the command line. The command below lists the certificate chain for an example server.

openssl s_client -connect mail.example.com:993 -servername mail.example.com

To inspect a website certificate, use our SSL checker. We explain the certificate basics in what is an SSL certificate.

Why do sent items and folders stop syncing?

On an IMAP account, Outlook maps the inbox, sent items, drafts and deleted items to folders on the server. When that mapping breaks, you see a sent message on only one device. The cause is usually a wrong folder mapping or a local "Sent" folder that Outlook created.

First, check which folder Outlook uses for sent items in the account settings. If it does not match the server's "Sent" folder, your messages pile up elsewhere. The deleted items folder also counts toward your quota, so empty it regularly.

Work through sync problems in this order.

  • Check folder names and contents in webmail.
  • Turn off offline mode in Outlook.
  • Refresh the folder list and start a manual sync.
  • If the problem stays, remove the account and add it again; the mail stays on the server.

Before you remove the account, make sure you do not use POP3. Mail downloaded with POP3 may exist only in a local file.

How do you test your Outlook email setup?

After setup, test three things: receiving, sending and syncing. First, send a message to your own address. Then ask someone to reply from another address, such as your personal account. That way you see both directions.

  • Does the message arrive in the inbox?
  • Does your sent folder also show in webmail?
  • When you delete a message, does it disappear in webmail too?
  • Does your message land in the recipient's inbox or in spam?

The last point matters. A message that lands in spam can signal a gap in your domain's DNS records. In that case, look at the domain side again.

To check a domain's mail records, you can also run this command in a terminal.

nslookup -type=MX example.com

What should you watch when several devices use IMAP?

With IMAP, the original copy of your mail stays on the server. So when the mailbox quota fills up, new messages stop arriving. Therefore, archive or delete old messages regularly. Your hosting panel shows the quota.

You also see the same folder structure on every device. A message you move on one device moves on the others too. That is convenient, but it also means an accidental delete takes effect everywhere. We suggest you archive important threads separately.

Backing up local Outlook data and server mail is a separate topic. For the general backup logic, see our website backup strategy guide.

The server also keeps your sent items and drafts. That is why you see them again after you switch devices, and why moving to a new computer is easy.

Which security habits matter for your Outlook email setup?

First, turn on encryption from the start. Pick 993 for IMAP and 465 or 587 for SMTP with an encrypted connection. On unencrypted ports, your password travels in a readable form. RFC 8314 also advises providers to drop cleartext access as soon as practicable.

Second, use a strong and unique password. For example, do not reuse it across mail and other services. A leak at one service then becomes a way into your mailbox. Many services send their password reset to your mailbox, so it is one of your most valuable accounts.

Third, watch for phishing. If a message asks for your password, do not open the link. Go straight to your panel instead. For a wider view of data security, read our website data security and encryption guide.

Next, protect your device too. Lock your computer and phone, because Outlook stores your password on the device. If a device is lost or stolen, change the mailbox password right away. That way, a lost device does not become an open door to your mail.

Finally, remove the account from old devices you no longer use. Likewise, close a departing employee's mailbox by changing its password.

When should you not do the setup yourself?

Knowing which jobs you can do and which belong to your provider protects both your time and your mail security. In the cases below, contact your provider or admin.

  • You do not know the server name or ports and have no welcome email.
  • The certificate has expired or the name mismatch sits on the server side.
  • A conditional access or MFA policy blocks adding a Microsoft 365 account.
  • Recipients reject your messages or send them to spam, because that depends on DNS records.
  • The server has blocked your IP address.

Your hosting provider can do these jobs. So a short ticket with the exact error message is often the fastest fix. Support quality is also a reason to choose hosting carefully, so read how to choose web hosting.

Which mistakes do you see most often during setup?

Setup errors are usually simple, and they show up when you enter values. The list below puts the points you should check in order.

  • Typing only "info" as the username instead of the full address.
  • Leaving encryption set to "None" while the IMAP port is 993.
  • Not turning on authentication for the outgoing server.
  • Typing the domain name instead of the mail server name.
  • Trying to add a Microsoft 365 mailbox by hand as IMAP.
  • Adding a space when you copy the password.

Besides, this list is not a statistic; it is a practical order of checks. Still, if you hunt for the error in this order, you will find it more easily.

What is a quick checklist for your Outlook email setup?

The list below gathers the steps to review before you finish. When you tick every item, you can expect the account to work well.

  1. Decide the account type: a hosting mailbox or Microsoft 365.
  2. Get the server name, port and encryption from your provider.
  3. Test the password in webmail.
  4. Choose IMAP and set encryption to SSL/TLS.
  5. Turn on authentication for the outgoing server.
  6. Send a test message to yourself and to an outside address.
  7. Do not click past a certificate warning; find the cause.
  8. Set up your phone with the same values, or use webmail.

Then, if sending problems continue, look at your domain's mail records. We support infrastructure decisions, from domain choice to DNS settings, within our web design service, and you can write to us on the contact page.

What should you do in the end for business email in Outlook?

In short, separate the account type first. For a hosting mailbox, start with IMAP, port 993 and SSL/TLS, and use your provider's 465 or 587 value for sending. For a Microsoft 365 account, type your address and finish the Microsoft sign-in.

If you get an error, test the password in webmail, then check the username, port and encryption. Do not click past a certificate warning. If you see a sender rejection, look at your domain records.

Business email is one of your brand's most visible touchpoints. So it pays to set it up correctly once and share a short note with your team. In that note, list the server names, the ports and the support contact, but never the password.

The values in this article are examples that rest on official documents. For provider-specific settings, always use the value your provider gives you. This information is not legal or corporate security advice.

Frequently Asked Questions

Should you choose IMAP or POP3 in Outlook?
In most cases, choose IMAP. IMAP keeps your mail on the server and syncs folders across all your devices. POP3 downloads messages to one device and, according to the cPanel documentation, then removes them from the server. If you use a phone and a computer together, POP3 causes trouble. Stay with IMAP unless your provider asks for POP3.
Which port does Outlook use for business email?
Use the value your provider gives you. As an example, RFC 8314 recommends port 993 for IMAP, port 995 for POP3 and implicit TLS. For sending, 465 (implicit TLS) and 587 (STARTTLS) are both valid. Server names and ports can vary by provider, so rely on the details in your welcome email.
Can you add a Microsoft 365 account to Outlook with IMAP?
Usually you do not need to, and it often fails. Microsoft says Basic authentication is disabled in Exchange Online, including for POP and IMAP. Outlook for Windows connects to an Exchange mailbox over MAPI/HTTP. So type only your address and finish the Microsoft sign-in. If the account will not add, contact your Microsoft 365 admin.
Why does Outlook show an authentication error?
It appears when the server does not accept your address or password. In the SMTP standard, code 535 means invalid credentials and code 530 means authentication is required. First, test the password in webmail. Then check that the username is the full email address and that the port and encryption type match.
Can you click past an Outlook certificate warning?
We advise against it, because the warning points to a real mismatch. It means the server name you connect to does not match the certificate, or that the certificate is invalid. RFC 8314 requires clients to validate certificates. First, retry with the server name your provider gave you. If the warning stays, only your provider can fix the certificate.
What is an app password, and does every account need one?
An app password is a randomly generated, one-time-use password that gives temporary access to your online account. According to Microsoft, some providers such as Gmail and iCloud, and some IMAP accounts, may require one. Not every account does. Check your provider's help page to learn whether your hosting mailbox needs it, or ask support.
  • Outlook
  • business email
  • IMAP
  • SMTP
  • Microsoft 365
  • hosting
  • email settings
Share:
Talha Aslan

Google Partner digital marketing expert. Hands-on with SEO, Google Ads, web design and e-commerce projects since 2012; every post here comes from that experience.

Next project

Let's talk about your project.

Your brief goes straight to Talha Aslan and team: strategy led by Talha, delivery by an experienced team. The first consultation is free; we listen and come back with a clear roadmap.