Google Workspace SMTP Settings
Paid Gmail on your own domain, where an admin decides whether mail apps may connect
Search for your email provider
Outgoing mail (SMTP)
SMTP server
smtp.gmail.com
Port. STARTTLS
587
Port. SSL/TLS
465
Security
STARTTLS on 587 (recommended) or SSL/TLS on 465. SMTP relay uses smtp-relay.gmail.com.
Incoming mail (IMAP)
IMAP server
imap.gmail.com
Port. SSL/TLS
993
Incoming mail (POP3)
POP3 server
pop.gmail.com
Port. SSL/TLS
995
Sending limits & login
Daily send limit
About 2,000 messages per day (external recipients); up to 10,000 via smtp-relay.gmail.com.
Authentication
Requires an app password with 2-Step Verification, or an admin must enable SMTP relay for the domain.
App password
Create an app password at myaccount.google.com/apppasswords.
Uses the same servers as Gmail. For bulk/app sending, admins usually configure the SMTP relay service (smtp-relay.gmail.com).
Sending cold email? EmailChaser manages inboxes, warmup and deliverability for you.
Try EmailChaser freeFind the SMTP, IMAP and POP3 server settings for any email provider. Free, with no signup, every field copies with one click.
Google Workspace SMTP, IMAP and POP3 settings
Google Workspace is the paid version of Gmail that runs on your own domain and answers to an admin console. Whether any mail client can connect at all is decided there, under Apps, Google Workspace, Gmail, End User Access, and it can be set for one department only. Workspace also gets an SMTP relay host that authenticates by IP address instead of a password, which personal Gmail never offers.
For incoming mail, use the IMAP server imap.gmail.com on port 993, or POP3 at pop.gmail.com on port 995. Pick the exact values from the tool above and copy them straight into your mail client.
Checked against Google Workspace's own documentation: knowledge.workspace.google.com. Ports and limits change, so check there too if something will not connect.
Google Workspace settings at a glance
One card with every server and port on it. Right click to save it, or share the page and this is the preview people see.

What to enter as your Google Workspace username and password
Wrong credentials, not a wrong port, are the usual reason a Google Workspace connection fails. These are the exact values to type.
The user's full Workspace address, for example you@yourdomain.com
A 16 character app password on that account, or an OAuth token when the client can do Sign in with Google
Get your app passwordHow to set up Google Workspace in a mail client
The exact path through Google Workspace's own settings, in order.
- 1
Admin turns on IMAP or POP for the users
In the Admin console go to Menu, Apps, Google Workspace, Gmail, End User Access, scroll to POP and IMAP access, and tick Enable IMAP access for all users. Select an organizational unit first if you want it for one team only.
- 2
Decide whether app passwords are allowed
In the same IMAP section, Allow any mail client accepts app passwords, while Restrict which mail clients users can use (OAuth mail clients only) refuses anything whose OAuth client ID is not on your list.
- 3
User creates an app password
With 2-Step Verification on for that user, they generate a 16 character code at https://myaccount.google.com/apppasswords.
- 4
Point the client at Google's servers
Outgoing smtp.gmail.com port 587 with TLS or 465 with SSL, incoming imap.gmail.com port 993 with SSL, signing in with the full Workspace address.
- 5
For a printer, app or high volume sender, use the relay
Admin console, Apps, Google Workspace, Gmail, Routing, then configure SMTP relay service and send to smtp-relay.gmail.com, authenticating by allowlisted IP address rather than a password.
What Google Workspace looks like filled in
Every mail client asks for the same handful of fields. Here they are with Google Workspace's values already in place.
Account settings: Google Workspace
Server
smtp.gmail.comPort
587Encryption
STARTTLSAuthentication
RequiredUsername
The user's full Workspace address, for example you@yourdomain.comPassword
A 16 character app password on that account, or an OAuth token when the client can do Sign in with GoogleServer
imap.gmail.comPort
993Encryption
SSL/TLSAn illustration of the fields, not a screenshot of any one app. Field names differ slightly between Outlook, Apple Mail and Thunderbird; the values do not.
Google Workspace SMTP settings in Thunderbird
The outgoing server dialog with Google Workspace's details entered. Outlook and Apple Mail ask for the same four things under slightly different names.

Which port should you use for Google Workspace?
STARTTLS on 587 (recommended) or SSL/TLS on 465. SMTP relay uses smtp-relay.gmail.com.
STARTTLS
Starts as a plain connection, then upgrades to an encrypted one. The modern standard for sending.
SSL/TLS
Encrypted from the first byte. Widely supported and a good choice when 587 is blocked.
Plain SMTP
Meant for server-to-server relay. Home networks and cloud hosts block it, so do not use it to send from a client.
Why your Google Workspace connection is failing
The failures people actually hit with Google Workspace, and what fixes each one.
The POP and IMAP setting is applied per organizational unit and can be managed by group. Check End User Access while the user's own organizational unit is selected, not the top level.
The admin has probably chosen Restrict which mail clients users can use (OAuth mail clients only), which only lets through clients whose OAuth client ID is listed. Switch to Allow any mail client or add that client ID.
2-Step Verification has to be on for that user, and an admin cannot both require a security key as the only second step and allow app passwords. Change the 2-Step Verification policy or move the app to Sign in with Google.
The relay's Allowed senders choice decides this. Only registered Apps users in my domains blocks it, while Only addresses in my domains lets an address such as noreply@yourdomain.com through.
Google caps a POP or IMAP user's SMTP message at 100 recipients, and the relay at 100 recipients per SMTP transaction. Split the send into smaller batches.
Google Workspace sending limits
External recipients are capped separately at 3,000 a day. The SMTP relay service is counted on its own, at 10,000 messages per user per 24 hours and 4.6 million recipients per organization per 24 hours.
Per day
2,000 messages per user, 1,500 for mail merge, 500 on a trial account
Recipients per message
100 recipients per message when a POP or IMAP user sends through SMTP, against 2,000 per message from the Gmail interface
Max attachment
25 MB on Business, Education and Enterprise Standard, up to 50 MB on Enterprise Plus in the web interface
Google Workspace servers by region and plan
Google Workspace does not use one set of hostnames everywhere. Match the row to your account.
| Region or plan | SMTP | IMAP | POP3 |
|---|---|---|---|
| Standard mail client access, any plan | smtp.gmail.com, port 587 with TLS or 465 with SSL | imap.gmail.com, port 993, SSL | pop.gmail.com, port 995, SSL |
| SMTP relay service, Workspace only, authenticates by IP address | smtp-relay.gmail.com, port 25, 465 or 587 | Not applicable | Not applicable |
| Restricted Gmail SMTP, delivers only to Gmail and Workspace addresses | aspmx.l.google.com, port 25, no sign-in required | Not applicable | Not applicable |
Sending cold email through Google Workspace
About 2,000 messages per day (external recipients); up to 10,000 via smtp-relay.gmail.com. Requires an app password with 2-Step Verification, or an admin must enable SMTP relay for the domain.
Those caps make single-mailbox sending fine for personal mail but a poor fit for cold outreach at volume. Emailchaser spreads sending across warmed inboxes and manages deliverability, so you can scale without burning Google Workspace accounts.
A new Google Workspace mailbox also starts with no sending history, and hitting the cap above on its first day is what gets it filtered. Warm the mailbox up first so its daily volume climbs gradually toward that limit rather than starting at it. Emailchaser includes that ramp on every plan.
Other business email and web hosting
Setting up more than one mailbox? These sit in the same category as Google Workspace.
Common questions about Google Workspace SMTP settings
What are Google Workspace's SMTP settings?
Google Workspace's outgoing (SMTP) server is smtp.gmail.com. Use port 587 (STARTTLS) or 465 (SSL/TLS). STARTTLS on 587 (recommended) or SSL/TLS on 465. SMTP relay uses smtp-relay.gmail.com. Sign in with your full email address and password (or app password).
What is Google Workspace's IMAP or POP3 server?
Google Workspace's incoming IMAP server is imap.gmail.com on port 993 (SSL/TLS). If you prefer POP3, use pop.gmail.com on port 995.
Which port should I use for Google Workspace?
Use port 587 with STARTTLS wherever it's offered, it's the modern standard for authenticated sending. Port 465 with SSL/TLS is a solid alternative. Avoid port 25, which most networks block for client sending. Google Workspace's recommended value is above.
Why won't my Google Workspace SMTP connection work?
Check authentication first: Requires an app password with 2-Step Verification, or an admin must enable SMTP relay for the domain. Create an app password at myaccount.google.com/apppasswords. Then confirm the host, port and security method match exactly, a 587/SSL or 465/STARTTLS mismatch will fail to connect.
Can I send bulk or cold email through Google Workspace?
Not at scale. About 2,000 messages per day (external recipients); up to 10,000 via smtp-relay.gmail.com. Providers throttle bursts to fight spam, so pushing cold email through one mailbox hits limits and wrecks deliverability. High-volume outreach belongs on dedicated infrastructure that spreads sending across warmed inboxes, which is what Emailchaser does.
What changed for Workspace accounts on 1 May 2025?
Google stopped supporting less secure apps, so an app or device can no longer sign in with only a username and password. Clients must use OAuth, which Google presents as Sign in with Google. Where a client cannot do that, Google's own guidance is to create and use an app password instead.
Should our printer or app use smtp.gmail.com or smtp-relay.gmail.com?
Use smtp.gmail.com when the device can sign in as one mailbox and the volume is modest, since it is capped at 2,000 messages a day. Use smtp-relay.gmail.com when the device cannot hold credentials or needs more room, because it authenticates by IP address and allows 10,000 messages per user per day.
Why can my personal Gmail create an app password but our staff cannot?
Workspace accounts sit under admin policy. If 2-Step Verification is not enforced for that user, or if the admin requires a security key as the only second step, no app password can be created. Ask the admin to adjust the 2-Step Verification policy or to allow the client over OAuth.
Ready to 10x your pipeline?
Send your first cold email campaign today.
Start my free trial