Mail clients

Set up any mail app.

The Ledger Mail speaks IMAP, SMTP, JMAP and ManageSieve, so every mail client already knows how to talk to it. Most of them will configure themselves from your address alone — here are the settings, and the steps, for the ones that ask.

Server settings

One host name for everything. The username is always your full address, and the password is an app password.

Incoming and outgoing
ServiceHostPortEncryption
IMAP (incoming)mail.theledgermail.com993SSL/TLS
IMAP (alternative)mail.theledgermail.com143STARTTLS
SMTP (outgoing)mail.theledgermail.com465SSL/TLS — implicit
SMTP (alternative)mail.theledgermail.com587STARTTLS
ManageSieve (filters)mail.theledgermail.com4190STARTTLS
Credentials
FieldValue
UsernameYour full address, e.g. you@theledgermail.com — not just the part before the @
PasswordAn app password created in Settings, never your account password
AuthenticationNormal password (the client sends it over the encrypted connection)

Use 993 and 465 where your client lets you choose. Both wrap the connection in TLS from the first byte, so there is no unencrypted moment at the start; 143 and 587 upgrade with STARTTLS and work just as well where a client insists on them.

Use an app password, not your account password

A separate credential per device, each one revocable on its own.

Mail clients store the password they are given, on the device, for as long as the account exists. So give each one its own credential instead: an app password is a long random secret that opens the mailbox over IMAP, SMTP and JMAP, and nothing else. Revoke it and that device stops working — every other device, and your own sign-in, carry on.

An app password also gets past two-factor authentication, which a mail client has no way to answer.

  1. Sign in to the web app and open Settings, under Mail apps.
  2. Create an app password and label it after the device — “iPhone”, “Thunderbird on the laptop”.
  3. Copy it straight into the mail client. It is shown once and stored nowhere, so if you lose it, make another and revoke the old one.

An app password is the whole mailbox.

Unlike an API token it carries no scopes: anything holding it can read and send all of your mail. That is what a mail client needs — but it is why you give one per device, and revoke the ones you no longer use. If you want scoped access for a script instead, create an API token.

Automatic setup

Most clients will not ask you for any of the settings above.

Auto-configuration is already published for the domain, so Thunderbird, Apple Mail, most Android clients and Outlook look up the settings from your address and fill in the rest. Type your full address and your app password, and let the client do the work — the settings table is there for the clients that still ask, and for checking what a client has chosen.

What clients look up
Client familyDocument
Thunderbird and most Linux clientshttps://autoconfig.theledgermail.com/mail/config-v1.1.xml
Outlookhttps://autodiscover.theledgermail.com/autodiscover/autodiscover.xml

Thunderbird

The quickest of the lot: it finds the settings itself.

  1. Choose Account Settings → Account Actions → Add Mail Account.
  2. Enter your name, your full Ledger Mail address and your app password, then choose Continue.
  3. Thunderbird finds the configuration and offers IMAP. Check that it shows mail.theledgermail.com on port 993 for incoming and 465 for outgoing, then choose Done.
  4. If it did not find anything, choose Configure manually and type the settings from the table above.

Apple Mail on a Mac

  1. Open Mail → Settings → Accounts, press + and choose Other Mail Account.
  2. Enter your name, your full address and your app password, then Sign In.
  3. If macOS cannot verify the account on its own, it shows the server fields. Set Account Type to IMAP, and both Incoming Mail Server and Outgoing Mail Server to mail.theledgermail.com.
  4. Afterwards, in Server Settings, turn off “Automatically manage connection settings” if you want to confirm the ports read 993 and 465 with TLS.

iPhone and iPad

  1. Open Settings → Apps → Mail → Mail Accounts → Add Account and choose Other, then Add Mail Account.
  2. Fill in your name, your full address, your app password and a description, then Next.
  3. Choose the IMAP tab. Under both Incoming Mail Server and Outgoing Mail Server, set the host name to mail.theledgermail.com and use your full address as the user name — iOS labels the outgoing fields optional, but fill them in, or sending will fail.
  4. Save. iOS negotiates TLS on 993 and 465 by itself; you can confirm it afterwards under Advanced.

Android

Gmail, K-9 Mail / Thunderbird for Android, FairEmail and the manufacturer's own app all work the same way.

  1. In your mail app, add an account and choose Other or Personal (IMAP) — not a provider from the list.
  2. Enter your full address, then your app password.
  3. If the app asks which protocol, choose IMAP. For the incoming server use mail.theledgermail.com, port 993, SSL/TLS; for outgoing, mail.theledgermail.com, port 465, SSL/TLS, with sign-in required.
  4. Check that the user name is the whole address, including the domain. This is the single most common reason an Android setup fails.

Outlook

  1. Choose File → Add Account (or Settings → Accounts in new Outlook) and type your full Ledger Mail address.
  2. If Outlook asks for the account type, choose IMAP.
  3. Enter your app password when prompted. Autodiscover supplies the rest.
  4. If it asks for servers, use mail.theledgermail.com for both — incoming 993 with SSL/TLS, outgoing 465 with SSL/TLS.

Outlook may keep asking for the password.

That usually means the account password was typed rather than an app password, or the user name was entered without the domain. Both fixes are the same: full address, app password.

JMAP and ManageSieve

For clients that speak something newer than IMAP, and for server-side filtering.

JMAP

JMAP is available on the same host. Point a JMAP client at the session resource and authenticate with your address and an app password; the session tells the client everything else, including the account id to use.

Session resource
https://mail.theledgermail.com/jmap/session

This is the same protocol The Ledger Mail's own web app runs on. If you would rather write against a plain REST surface, the HTTP API sits in front of it with scoped tokens.

ManageSieve

Server-side filters are edited over ManageSieve on mail.theledgermail.com:4190, with the same address and app password. Rules written there run on the server as mail arrives, so they apply before any client has fetched anything — useful when you read the same mailbox on several devices.

If it will not connect

Common causes
What you seeWhat it usually is
The password is rejected, over and overThe account password was used instead of an app password, or two-factor is on. Create an app password in Settings.
Incoming works, sending does notThe outgoing server was left blank or without sign-in. Set it to the same host, port 465, and require authentication.
Authentication fails on every attemptThe user name is missing the domain. It must be the whole address.
A certificate warningThe host name is misspelled. It is mail.theledgermail.com for both incoming and outgoing, and the certificate is issued for exactly that name.
Nothing connects at all, suddenlyToo many failed sign-ins from one address can get it blocked for a while. Fix the password in every client, then wait before trying again.

Still stuck? Tell us what the client says — the exact error helps.