German paid mail host with server-side PGP encryption and strict sender address checks.
Search for your email provider
Outgoing mail (SMTP)
SMTP server
smtp.mailbox.org
Port. STARTTLS
587
Port. SSL/TLS
465
Security
SSL/TLS on 465 (recommended) or STARTTLS on 587.
Incoming mail (IMAP)
IMAP server
imap.mailbox.org
Port. SSL/TLS
993
Port. STARTTLS
143
Incoming mail (POP3)
POP3 server
pop3.mailbox.org
Port. SSL/TLS
995
Port. STARTTLS
110
Sending limits & login
Daily send limit
Per-plan limits; mailbox.org is built for personal and business mail, not bulk.
Authentication
Sign in with your full mailbox.org address and mailbox password.
App password
If two-factor authentication is on, create an app-specific password under Settings > Password and Security.
German privacy-focused provider with optional PGP encryption at the server.
Sending cold email? EmailChaser manages inboxes, warmup and deliverability for you.
Try EmailChaser freeFind the SMTP, IMAP and POP3 server settings for any email provider. Free, with no signup, every field copies with one click.
mailbox.org is a paid German provider, and a new unpaid trial account can only send ten emails a day and only to other mailbox.org addresses. Its signature feature is the encrypted mailbox, where a server-side rule PGP-encrypts every incoming message with your key, so a mail client without that key shows scrambled text. Sending is locked to addresses registered on your account.
For incoming mail, use the IMAP server imap.mailbox.org on port 993, or POP3 at pop3.mailbox.org on port 995. Pick the exact values from the tool above and copy them straight into your mail client.
Checked against mailbox.org's own documentation: kb.mailbox.org. Ports and limits change, so check there too if something will not connect.
One card with every server and port on it. Right click to save it, or share the page and this is the preview people see.

Wrong credentials, not a wrong port, are the usual reason a mailbox.org connection fails. These are the exact values to type.
Your main mailbox.org email address, for example max.mustermann@mailbox.org
Your mailbox password. If two-factor authentication is switched on, an Application Password instead.
The exact path through mailbox.org's own settings, in order.
Pay for the account before connecting a client
An unpaid, newly registered test account is limited to 10 emails a day and to mailbox.org addresses only. Anything to the outside world is refused.
Create an Application Password if 2FA is on
Go to All settings | Security | Application Passwords, add a password, give it a label such as My phone, and click Add new password. Copy it straight away because it is not shown again.
Register every address you will send from
Add aliases under All settings > E-mail Addresses > E-mail Aliases, or verify an outside address under E-mail addresses > Alternative senders, which emails you an activation link that expires after 15 minutes.
Enter the incoming server
IMAP imap.mailbox.org port 993 with SSL/TLS, or POP3 pop3.mailbox.org port 995 with SSL/TLS. Username is your main email address.
Enter the outgoing server
SMTP smtp.mailbox.org port 465 with SSL/TLS, or port 587 with STARTTLS. Tick Outgoing server requires authentication.
Every mail client asks for the same handful of fields. Here they are with mailbox.org's values already in place.
Account settings: mailbox.org
Server
smtp.mailbox.orgPort
465Encryption
SSL/TLSAuthentication
RequiredUsername
Your main mailbox.org email address, for example max.mustermann@mailbox.orgPassword
Your mailbox password. If two-factor authentication is switched on, an Application Password instead.Server
imap.mailbox.orgPort
993Encryption
SSL/TLSAn illustration of the fields, not a screenshot of any one app. Field names differ slightly between Outlook, Apple Mail and Thunderbird; the values do not.
The outgoing server dialog with mailbox.org's details entered. Outlook and Apple Mail ask for the same four things under slightly different names.

SSL/TLS on 465 (recommended) or STARTTLS on 587.
STARTTLS
Starts as a plain connection, then upgrades to an encrypted one. The modern standard for sending.
SSL/TLS
Encrypted from the first byte. Widely supported and a good choice when 587 is blocked.
Plain SMTP
Meant for server-to-server relay. Home networks and cloud hosts block it, so do not use it to send from a client.
The failures people actually hit with mailbox.org, and what fixes each one.
You are sending from an address mailbox.org does not have on your account. Register it under All settings > E-mail Addresses > E-mail Aliases, or verify it under E-mail addresses > Alternative senders.
The account is still an unpaid test account, which may only send to mailbox.org addresses. Pay for the plan and the restriction lifts.
Once 2FA is active, logins from third-party programs only work with an Application Password from All settings | Security | Application Passwords. The mailbox password no longer works there.
The encrypted mailbox is switched on, so incoming mail is encrypted to your key on the server. Download your key pair from mailbox.org and import it into the client's PGP setup, or turn the encrypted mailbox off.
mailbox.org's POP3 host carries a 3: pop3.mailbox.org, port 995 with SSL/TLS.
The cap is not a plain counter: mailbox.org scores account age and recent volume, and accounts that spike suddenly can be blocked at roughly 5,000.
Per day
10,000 emails on a regular private account; unpaid test accounts are capped at 10
Max attachment
100 MB per email
Outlook
Do not try to set Outlook up as an Exchange account. mailbox.org says ActiveSync is for mobile devices only and that syncing it with a Windows PC or Mac is officially not possible, so use IMAP for mail plus the CalDav Synchronizer plugin for calendar and contacts.
Per-plan limits; mailbox.org is built for personal and business mail, not bulk. Sign in with your full mailbox.org address and mailbox password.
Those caps make single-mailbox sending fine for personal mail but a poor fit for cold outreach at volume. Emailchaser spreads sending across warmed inboxes and manages deliverability, so you can scale without burning mailbox.org accounts.
Setting up more than one mailbox? These sit in the same category as mailbox.org.
What are mailbox.org's SMTP settings?
mailbox.org's outgoing (SMTP) server is smtp.mailbox.org. Use port 587 (STARTTLS) or 465 (SSL/TLS). SSL/TLS on 465 (recommended) or STARTTLS on 587. Sign in with your full email address and password (or app password).
What is mailbox.org's IMAP or POP3 server?
mailbox.org's incoming IMAP server is imap.mailbox.org on port 993 (SSL/TLS). If you prefer POP3, use pop3.mailbox.org on port 995.
Which port should I use for mailbox.org?
Use port 587 with STARTTLS wherever it's offered, it's the modern standard for authenticated sending. Port 465 with SSL/TLS is a solid alternative. Avoid port 25, which most networks block for client sending. mailbox.org's recommended value is above.
Why won't my mailbox.org SMTP connection work?
Check authentication first: Sign in with your full mailbox.org address and mailbox password. If two-factor authentication is on, create an app-specific password under Settings > Password and Security. Then confirm the host, port and security method match exactly, a 587/SSL or 465/STARTTLS mismatch will fail to connect.
Can I send bulk or cold email through mailbox.org?
Not at scale. Per-plan limits; mailbox.org is built for personal and business mail, not bulk. Providers throttle bursts to fight spam, so pushing cold email through one mailbox hits limits and wrecks deliverability. High-volume outreach belongs on dedicated infrastructure that spreads sending across warmed inboxes, which is what Emailchaser does.
Can I keep IMAP working after switching on two-factor authentication?
Yes, but only through an Application Password. Create one under All settings | Security | Application Passwords, label it for that device, and paste it into the mail client in place of your mailbox password. The same password will not log you in to the web interface.
Why does mailbox.org reject the sender address I picked?
mailbox.org checks that the From address belongs to your account, to stop address spoofing. It has to be your main address, a registered alias, or an outside address verified under Alternative senders. Otherwise delivery fails with a 553 error that names your real address.
Does the encrypted mailbox break my email app?
It does not stop the app connecting, but new inbox messages arrive as PGP ciphertext. To read them outside the web interface you have to download your key pair from mailbox.org and import it into the client's PGP tool. mailbox.org notes that messages in the Sent folder are currently not stored encrypted.
Ready to 10x your pipeline?
Send your first cold email campaign today.
Start my free trialAddress: 151 Calle de San Francisco San Juan, Puerto Rico
Email: support@emailchaser.com
Product
Cold Email SoftwareAutopilotEmail FinderCampaignsSales CRMLead FinderEmail AccountsEmail WarmupEmail VerifierCold Email APIMCP ServerAPI documentationWho it's for
FreelancersFoundersSales teamsMarketing agenciesRecruitment agenciesLead generation agenciesComparisons
Best cold email softwareInstantly alternativesSmartlead alternativesInstantly vs EmailchaserSmartlead vs EmailchaserHunter vs EmailchaserFree tools
All free toolsBulk Email VerifierDeliverability TestEmail Header AnalyzerSMTP Settings FinderCold Email TemplatesBoolean Search BuilderAudience Size CalculatorName SplitterCompany Email FormatSpam Word CheckerInternational
Cold email (ES)Cold email (FR)Cold email (DE)Cold email (IT)Cold email (PT)Verifica email (IT)© Copyright 2026 Emailchaser