What you need to send
An app that sends email by itself signs in to your provider’s outgoing mail server, just like Apple Mail. It needs four settings:
- Server, such as
smtp.gmail.com - Port, usually 465 or 587
- Encryption: SSL/TLS belongs to port 465, STARTTLS to port 587
- User name, almost always your full email address
Then there is the password. With many large providers that is no longer your usual password but an app password you create for this one app. You can revoke it on its own at any time without changing your main password.
The settings of the large providers
| Provider | Server | Port and encryption | Password |
|---|---|---|---|
| Gmail, Google Workspace | smtp.gmail.com | 587 STARTTLS | App password |
| iCloud Mail | smtp.mail.me.com | 587 STARTTLS | App-specific password |
| Telekom Mail (t-online.de, magenta.de) | securesmtp.t-online.de | 465 SSL/TLS | Password for email programs |
| GMX | mail.gmx.net | 587 STARTTLS | Mailbox password, app password with two-factor protection |
| WEB.DE | smtp.web.de | 587 STARTTLS | Mailbox password, app password with two-factor protection |
| freenet Mail | mx.freenet.de | 587 STARTTLS | Mailbox password |
| Vodafone Mail (also Arcor, Kabel) | smtp.vodafonemail.de | 587 STARTTLS | Email password, not the MeinVodafone password |
| IONOS | smtp.ionos.de | 465 SSL/TLS | Mailbox password |
| STRATO | smtp.strato.de | 465 SSL/TLS | Mailbox password |
| Posteo | posteo.de | 587 STARTTLS | Mailbox password or app password |
| mailbox.org | smtp.mailbox.org | 465 SSL/TLS | Mailbox password, app password with two-factor protection |
| Yahoo Mail | smtp.mail.yahoo.com | 465 SSL/TLS | App password |
| Hetzner | mail.your-server.de | 587 STARTTLS | Mailbox password |
| Microsoft 365 | smtp.office365.com | 587 STARTTLS | Account password, if SMTP AUTH is on |
With every provider in the table, the user name is your full email address.
What you do at your provider first
Gmail and Google Workspace: Turn on 2-Step Verification in your Google Account. Only then can you create an app password at myaccount.google.com/apppasswords. Google shows it to you once, so copy it right away. With a company account, the admin may have turned app passwords off.
iCloud Mail: Sign in at account.apple.com and create an app-specific password under Sign-In and Security. Your account needs two-factor authentication for that.
Telekom Mail: Apps like Folnaro need a separate password for email programs. You set it in the Telekom customer center under Profil verwalten > Login-Daten > Weitere Passwörter, or in the E-Mail Center under Einstellungen > Passwörter. The server does not accept your login password.
GMX, WEB.DE and freenet: Access for email programs is off by default there. Turn on POP3 and IMAP in your mailbox settings, otherwise the server refuses sending too. If you have two-factor authentication on at GMX or WEB.DE, you also need an app password.
Microsoft 365: If your company uses security defaults, SMTP AUTH is switched off. The admin has to turn it on for your mailbox. Microsoft turns password sign-in off by default for existing company accounts at the end of 2026.
Outlook.com, Hotmail and Live: Since 16 September 2024, Microsoft no longer accepts a password from other programs, only signing in through the browser. Folnaro cannot send through it directly. With such an address you hand every email to Apple Mail.
Your own domain with a host
If your address uses your own domain, such as hello@yourstudio.com, the server comes from your host. With IONOS and STRATO the settings in the table apply, and you sign in with your address and mailbox password. At ALL-INKL.COM every account has its own server; you find its name and your mailbox login in KAS under email. With other hosts the server is in the customer area, usually under email, mailbox or SMTP.
Many domains also publish their server settings themselves, through an autoconfig file or DNS records. Apps like Thunderbird and Folnaro read them, so you do not have to look anything up.
If the test fails
- Sign-in refused: usually the app password is missing, or at GMX, WEB.DE and freenet the POP3 and IMAP switch.
- Server not found: check the server name for typos.
- Timeout: port and encryption often do not match. 465 belongs to SSL/TLS, 587 to STARTTLS.
- Sender refused: most providers only send from addresses that belong to your mailbox or are set up there as an alias.