How to Create an App-Specific Password for iCloud Mail

The short answer
Sign in to account.apple.com, go to Sign-In and Security, and select App-Specific Passwords. Enter a label, click Create, then copy the 16-character code immediately — Apple shows it only once. To revoke, return to the same screen and select the X next to any listed password. Two-factor authentication must be enabled first.
How to create an iCloud Mail app-specific password, troubleshoot common rejections, and revoke access without changing your Apple Account password.
On this page
iCloud Mail works with any IMAP-capable email client, but Apple requires third-party apps to authenticate with a separate 16-character credential rather than your main Apple Account password. This credential is called an app-specific password. Knowing how to create an app specific password for iCloud Mail is the first step to connecting Thunderbird, Outlook, Spark, or any other IMAP client to your iCloud mailbox.
The generator lives at account.apple.com, in the Sign-In and Security section. Apple has moved this account management page several times over the years — appleid.apple.com redirects correctly to account.apple.com now, so older guides that cite the previous address still work, but account.apple.com is the current home. Two-factor authentication must be active on your Apple Account before the App-Specific Passwords option appears at all.
Before you start#
Two-factor authentication is a hard prerequisite. Apple does not display the App-Specific Passwords option unless 2FA is already enabled on the account. If yours is not on, enable it first. On an iPhone or iPad, open Settings, tap your name at the top, then select Sign-In and Security. On a Mac, open System Settings, click your Apple Account name, then select Sign-In and Security.
You will also need access to a trusted device — your iPhone, iPad, or another signed-in Mac — to approve your sign-in to account.apple.com if you are working from an unfamiliar browser or a shared computer. Have one within reach before you start. Once you are signed in, generating a password takes under a minute.
Apple rebranded Apple ID to Apple Account in 2024. Both names refer to the same thing: the same account, the same credentials, the same security settings. If you see either name in an interface or in a guide, they are interchangeable.
What an app-specific password cannot do
How to create an app-specific password for iCloud Mail#
Have your mail client open in a separate window before you begin. Apple shows the password exactly once, and the window it appears in has no copy-later option — close it prematurely and you will need to start over.
- 1
Sign in to account.apple.com
Open account.apple.com in a browser and enter your Apple Account email address and main password. Apple will send a six-digit verification code to one of your trusted devices. Enter the code when prompted to complete the sign-in.
- 2
Navigate to Sign-In and Security
On the main account page, find the Sign-In and Security section. On a wider screen it appears as a card in the left column; on a narrower screen it is in the main content area. Select it to see your security options.
- 3
Open App-Specific Passwords
Select App-Specific Passwords from the Sign-In and Security options. Apple shows a list of your currently active credentials, each identified by the label you assigned when you created it. The page also shows how many active passwords you have out of the 25 allowed.
- 4
Generate a new password
Select the plus icon or the Generate an app-specific password link. Apple asks you to name this password. Type a short label that identifies the app you are connecting — for example, Thunderbird, Outlook, or AI Emaily. The label exists only for your reference; it has no effect on authentication.
- 5
Copy the password before closing the dialog
Apple displays the password as four groups of four lowercase letters separated by hyphens: xxxx-xxxx-xxxx-xxxx. That is 16 letters and 3 hyphens for 19 characters total. Copy it immediately. Once you close this dialog, Apple does not store or redisplay the full credential. If you lose it, you have to generate a new one and update your client.
- 6
Paste it into your mail client's password field
Open your mail client, go to its account settings for the iCloud or IMAP account, and find the password field. Paste the app-specific password exactly as copied — hyphens included. This credential takes the place of your main Apple Account password for this single connection.
- 7
Save the settings and verify the connection
Save the account settings and trigger a manual sync, or send a short test message. If mail loads and sending succeeds, the setup is complete. If authentication still fails, work through the troubleshooting section below before generating another password.
Where to enter the password on common mail clients#
The app-specific password goes in the IMAP password field — the same slot where a normal Apple Account password would go. Server and port settings must be correct before the password can work; an incorrect hostname produces the same authentication error as a wrong password, so confirm both before troubleshooting the credential itself.
Your iCloud username is your full email address. Apple supports three sending domains — @icloud.com, @me.com, and @mac.com — all routed to the same mailbox. Use whichever address you signed up with; it is the one Apple expects in the username field.
Apple Mail on Apple devices handles iCloud authentication through the operating system rather than through a manually entered IMAP password. You only need an app-specific password in Apple Mail if it explicitly asks you to re-authenticate and rejects your standard Apple Account credentials — typically after a security event or an account recovery.
| Mail client | Path to the password field | IMAP and SMTP settings |
|---|---|---|
| Thunderbird | Account Settings, then Server Settings, then Password | IMAP: imap.mail.me.com, port 993, SSL/TLS |
| Outlook for Windows | File, Account Settings, select the account, Change, then Password | IMAP: imap.mail.me.com, port 993, SSL. SMTP: smtp.mail.me.com, port 587, STARTTLS |
| Outlook for Mac | Outlook menu, Preferences, Accounts, select the iCloud account, password field | IMAP: imap.mail.me.com, port 993, SSL. SMTP: smtp.mail.me.com, port 587, STARTTLS |
| Spark | Settings, Accounts, select the iCloud account, edit credentials | IMAP: imap.mail.me.com, port 993, SSL/TLS |
| AI Emaily | Add account, select iCloud, paste the app password when prompted | Pre-filled automatically during setup |
| Any generic IMAP client | Account setup wizard, IMAP password field | IMAP: imap.mail.me.com, port 993, SSL. SMTP: smtp.mail.me.com, port 587, STARTTLS |
What to do when an app-specific password is rejected#
Most rejections trace to one of five causes. The most common is a whitespace error — a space before or after the pasted credential that is invisible in a masked password field but stops authentication outright. Before trying anything else, re-copy the password from Apple's dialog and paste it into a plain-text editor first to confirm it is exactly 19 characters with nothing extra on either side.
The second most common cause is automatic revocation. Apple revokes every active app-specific password the moment you change or reset your Apple Account password — even a voluntary change made for security reasons triggers this with no warning. If mail stopped syncing within a day or two of a password update, this is almost certainly the reason. You need to generate a new app-specific password for each affected client before sync resumes.
| Symptom | Most likely cause | Fix |
|---|---|---|
| Password rejected immediately after pasting | Space before or after the pasted credential | Re-copy from Apple's dialog and verify in a plain-text editor before pasting again |
| Incorrect password error on a freshly generated credential | Username mismatch — the client is signed into a different Apple Account than the one used on account.apple.com | Confirm the username in the client exactly matches the Apple Account email used to generate the password |
| Can receive mail but sending fails | SMTP server, port, or SMTP password field is misconfigured | Set SMTP to smtp.mail.me.com, port 587, STARTTLS; use the same app-specific password for both IMAP and SMTP |
| Mail synced fine, then silently stopped | Apple Account password was changed or reset, automatically revoking all app-specific passwords | Generate a new app-specific password at account.apple.com and update it in every connected client |
| Cannot generate a new password — limit reached | 25 active app-specific passwords already exist on the account | Sign into account.apple.com, revoke any unused credentials, then generate a new one |
Password changes revoke everything immediately
A faster way to keep iCloud Mail connected#
The steps above work for any IMAP-capable client. The limitation of the manual approach is that you have to notice when the connection drops — which usually happens silently, a day or two after the Apple Account password change that caused it, when you realize expected mail never arrived.
We build AI Emaily, an AI-native email client that connects iCloud Mail over IMAP and handles the credential step as part of account setup. When you add an iCloud account, AI Emaily walks you through generating the app-specific password and stores it securely. If the connection breaks because your Apple Account password changed or you manually revoked the credential, AI Emaily flags the disconnection immediately rather than silently stalling your inbox. The agent layer — triage, drafting, and autonomous follow-up tracking — runs on top of the same authenticated IMAP connection, so nothing in the pipeline operates without a live mailbox behind it.
Frequently asked
See it in AI Emaily
Sources

Written by
Nafiul HasanNafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.