Blog/ Apple Mail & iCloud

How to Create an App-Specific Password for iCloud Mail

Nafiul HasanNafiul Hasan· 10 min read
iCloud Mail app-specific password generator on account.apple.com — setup guide for connecting iCloud to third-party email clients

The short answer

Sign in to account.apple.com, go to Sign-In and Security, and select App-Specific Passwords. Enter a label, click Create, then copy the 16-character code immediately — Apple shows it only once. To revoke, return to the same screen and select the X next to any listed password. Two-factor authentication must be enabled first.

How to create an iCloud Mail app-specific password, troubleshoot common rejections, and revoke access without changing your Apple Account password.

On this page
  1. 01Before you start
  2. 02How to create an app-specific password for iCloud Mail
  3. 03Where to enter the password on common mail clients
  4. 04What to do when an app-specific password is rejected
  5. 05A faster way to keep iCloud Mail connected

iCloud Mail works with any IMAP-capable email client, but Apple requires third-party apps to authenticate with a separate 16-character credential rather than your main Apple Account password. This credential is called an app-specific password. Knowing how to create an app specific password for iCloud Mail is the first step to connecting Thunderbird, Outlook, Spark, or any other IMAP client to your iCloud mailbox.

The generator lives at account.apple.com, in the Sign-In and Security section. Apple has moved this account management page several times over the years — appleid.apple.com redirects correctly to account.apple.com now, so older guides that cite the previous address still work, but account.apple.com is the current home. Two-factor authentication must be active on your Apple Account before the App-Specific Passwords option appears at all.

Before you start#

Two-factor authentication is a hard prerequisite. Apple does not display the App-Specific Passwords option unless 2FA is already enabled on the account. If yours is not on, enable it first. On an iPhone or iPad, open Settings, tap your name at the top, then select Sign-In and Security. On a Mac, open System Settings, click your Apple Account name, then select Sign-In and Security.

You will also need access to a trusted device — your iPhone, iPad, or another signed-in Mac — to approve your sign-in to account.apple.com if you are working from an unfamiliar browser or a shared computer. Have one within reach before you start. Once you are signed in, generating a password takes under a minute.

Apple rebranded Apple ID to Apple Account in 2024. Both names refer to the same thing: the same account, the same credentials, the same security settings. If you see either name in an interface or in a guide, they are interchangeable.

What an app-specific password cannot do

An app-specific password cannot be used to sign into account.apple.com, change your Apple Account settings, make App Store purchases, or approve two-factor authentication prompts. It is a limited credential scoped to mail, calendar, and contacts access for one app — nothing beyond that.

How to create an app-specific password for iCloud Mail#

Have your mail client open in a separate window before you begin. Apple shows the password exactly once, and the window it appears in has no copy-later option — close it prematurely and you will need to start over.

  1. 1

    Sign in to account.apple.com

    Open account.apple.com in a browser and enter your Apple Account email address and main password. Apple will send a six-digit verification code to one of your trusted devices. Enter the code when prompted to complete the sign-in.

  2. 2

    Navigate to Sign-In and Security

    On the main account page, find the Sign-In and Security section. On a wider screen it appears as a card in the left column; on a narrower screen it is in the main content area. Select it to see your security options.

  3. 3

    Open App-Specific Passwords

    Select App-Specific Passwords from the Sign-In and Security options. Apple shows a list of your currently active credentials, each identified by the label you assigned when you created it. The page also shows how many active passwords you have out of the 25 allowed.

  4. 4

    Generate a new password

    Select the plus icon or the Generate an app-specific password link. Apple asks you to name this password. Type a short label that identifies the app you are connecting — for example, Thunderbird, Outlook, or AI Emaily. The label exists only for your reference; it has no effect on authentication.

  5. 5

    Copy the password before closing the dialog

    Apple displays the password as four groups of four lowercase letters separated by hyphens: xxxx-xxxx-xxxx-xxxx. That is 16 letters and 3 hyphens for 19 characters total. Copy it immediately. Once you close this dialog, Apple does not store or redisplay the full credential. If you lose it, you have to generate a new one and update your client.

  6. 6

    Paste it into your mail client's password field

    Open your mail client, go to its account settings for the iCloud or IMAP account, and find the password field. Paste the app-specific password exactly as copied — hyphens included. This credential takes the place of your main Apple Account password for this single connection.

  7. 7

    Save the settings and verify the connection

    Save the account settings and trigger a manual sync, or send a short test message. If mail loads and sending succeeds, the setup is complete. If authentication still fails, work through the troubleshooting section below before generating another password.

Where to enter the password on common mail clients#

The app-specific password goes in the IMAP password field — the same slot where a normal Apple Account password would go. Server and port settings must be correct before the password can work; an incorrect hostname produces the same authentication error as a wrong password, so confirm both before troubleshooting the credential itself.

Your iCloud username is your full email address. Apple supports three sending domains — @icloud.com, @me.com, and @mac.com — all routed to the same mailbox. Use whichever address you signed up with; it is the one Apple expects in the username field.

Apple Mail on Apple devices handles iCloud authentication through the operating system rather than through a manually entered IMAP password. You only need an app-specific password in Apple Mail if it explicitly asks you to re-authenticate and rejects your standard Apple Account credentials — typically after a security event or an account recovery.

Mail clientPath to the password fieldIMAP and SMTP settings
ThunderbirdAccount Settings, then Server Settings, then PasswordIMAP: imap.mail.me.com, port 993, SSL/TLS
Outlook for WindowsFile, Account Settings, select the account, Change, then PasswordIMAP: imap.mail.me.com, port 993, SSL. SMTP: smtp.mail.me.com, port 587, STARTTLS
Outlook for MacOutlook menu, Preferences, Accounts, select the iCloud account, password fieldIMAP: imap.mail.me.com, port 993, SSL. SMTP: smtp.mail.me.com, port 587, STARTTLS
SparkSettings, Accounts, select the iCloud account, edit credentialsIMAP: imap.mail.me.com, port 993, SSL/TLS
AI EmailyAdd account, select iCloud, paste the app password when promptedPre-filled automatically during setup
Any generic IMAP clientAccount setup wizard, IMAP password fieldIMAP: imap.mail.me.com, port 993, SSL. SMTP: smtp.mail.me.com, port 587, STARTTLS

What to do when an app-specific password is rejected#

Most rejections trace to one of five causes. The most common is a whitespace error — a space before or after the pasted credential that is invisible in a masked password field but stops authentication outright. Before trying anything else, re-copy the password from Apple's dialog and paste it into a plain-text editor first to confirm it is exactly 19 characters with nothing extra on either side.

The second most common cause is automatic revocation. Apple revokes every active app-specific password the moment you change or reset your Apple Account password — even a voluntary change made for security reasons triggers this with no warning. If mail stopped syncing within a day or two of a password update, this is almost certainly the reason. You need to generate a new app-specific password for each affected client before sync resumes.

SymptomMost likely causeFix
Password rejected immediately after pastingSpace before or after the pasted credentialRe-copy from Apple's dialog and verify in a plain-text editor before pasting again
Incorrect password error on a freshly generated credentialUsername mismatch — the client is signed into a different Apple Account than the one used on account.apple.comConfirm the username in the client exactly matches the Apple Account email used to generate the password
Can receive mail but sending failsSMTP server, port, or SMTP password field is misconfiguredSet SMTP to smtp.mail.me.com, port 587, STARTTLS; use the same app-specific password for both IMAP and SMTP
Mail synced fine, then silently stoppedApple Account password was changed or reset, automatically revoking all app-specific passwordsGenerate a new app-specific password at account.apple.com and update it in every connected client
Cannot generate a new password — limit reached25 active app-specific passwords already exist on the accountSign into account.apple.com, revoke any unused credentials, then generate a new one

Password changes revoke everything immediately

Any change to your Apple Account password — including a planned security update — immediately revokes every active app-specific password across all connected clients. Each client will stop syncing without notice. Plan to regenerate and update credentials in every connected app whenever you change your main Apple Account password.

A faster way to keep iCloud Mail connected#

The steps above work for any IMAP-capable client. The limitation of the manual approach is that you have to notice when the connection drops — which usually happens silently, a day or two after the Apple Account password change that caused it, when you realize expected mail never arrived.

We build AI Emaily, an AI-native email client that connects iCloud Mail over IMAP and handles the credential step as part of account setup. When you add an iCloud account, AI Emaily walks you through generating the app-specific password and stores it securely. If the connection breaks because your Apple Account password changed or you manually revoked the credential, AI Emaily flags the disconnection immediately rather than silently stalling your inbox. The agent layer — triage, drafting, and autonomous follow-up tracking — runs on top of the same authenticated IMAP connection, so nothing in the pipeline operates without a live mailbox behind it.

Frequently asked

Nafiul Hasan

Written by

Nafiul Hasan

Nafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.

EntrepreneurAI Automation System BuilderAI EnthusiastBuilds AI Enterprise Solutions10+ years experience
More from Nafiul
Ready when you are

Connect iCloud Mail to AI Emaily

AI Emaily walks through the app-specific password setup with you and keeps the connection live automatically.

  • 7-day free trial
  • Cancel anytime
  • Every provider