Proton Mail Bridge Won't Connect: The Real Causes

The short answer
Proton Bridge almost always fails for one of three reasons: you typed your regular Proton password instead of the Bridge-generated one, another program is already using Bridge's local ports (1143/1025), or antivirus or a firewall is blocking its loopback connection. Restart Bridge, copy the Bridge password fresh, and allowlist Bridge in your security software before re-adding the account.
Proton Mail Bridge not connecting? Fix the password, port, and firewall causes that explain most failures.
On this page
- 01What causes Proton Bridge connection failures?
- 02Fix 1: regenerate and re-enter the Bridge password
- 03Fix 2: resolve a local port conflict
- 04Fix 3: stop antivirus or a firewall from blocking Bridge
- 05Two causes that aren't on the checklist above
- 06How do I tell which cause I actually have?
- 07Preventing Proton Bridge from disconnecting again
Proton Mail Bridge not connecting almost never means Proton's servers are down. Bridge is a small local application that runs on your computer, decrypts your mail, and hands it to your email client over a private IMAP/SMTP connection on 127.0.0.1 — your own machine talking to itself. When that handshake fails, the cause is nearly always local: the wrong password, a blocked port, or software on your device getting in the way.
This matters because the error messages are misleading. Outlook, Apple Mail and Thunderbird all report bridge failures as generic "can't connect to server" or "login failed" errors, which sends people straight to resetting their Proton account password — the one thing that's usually not broken. The three causes below cover the overwhelming majority of Bridge connection failures, in the order they're worth checking.
What causes Proton Bridge connection failures?#
Four things break a Bridge connection often enough to be worth a table: the wrong password, a port collision, security software, and network-level blocking. Check them in this order — the first two account for most support tickets.
| Cause | How to confirm it | Fix |
|---|---|---|
| Wrong password entered | Client shows "invalid credentials" or "authentication failed" even though your Proton login works fine in the browser | Open Bridge, copy the Bridge-specific password again, paste it fresh into the client |
| Local port already in use | Bridge shows a "port already occupied" warning, or the client can reach the server but never authenticates | Let Bridge pick new ports, or close the other app (another mail client, a VPN, a dev server) holding 1143/1025 |
| Antivirus or firewall blocking localhost traffic | Connection works right after a fresh install, then stops after a security-software update or scan | Allowlist the Bridge executable and its updates folder in both antivirus and firewall |
| Corporate or ISP network blocking Proton | Bridge itself can't sync (spinning/red icon) even before the client is involved, often only on office Wi-Fi | Allowlist mail-api.proton.me and ports 443/80, or enable Alternative Routing in Bridge's advanced settings |
Fix 1: regenerate and re-enter the Bridge password#
Proton Bridge issues a unique password for each mailbox you connect. It is generated locally, is different from your normal Proton login password, and never leaves your device. If you type your regular Proton password into Outlook, Apple Mail or Thunderbird instead, the connection fails with what looks like a login error — because it is one, just not the one you think.
This is the single most common cause of "Proton Bridge not connecting," and it's easy to fix once you know what's actually wrong.
- 1
Open Bridge and select the account
In the Bridge app, click the mailbox you're setting up in your email client.
- 2
Copy the Bridge password, not your Proton password
Bridge shows a generated password for that account. Click to copy it — don't retype it, it's long and easy to mistype.
- 3
Remove the account from your email client
Delete the existing account entry rather than editing it. A stale, half-configured account is a common source of repeat failures.
- 4
Re-add the account using the copied password
Use the IMAP/SMTP host and port Bridge displays, and paste the Bridge password when prompted for credentials.
- 5
If it still fails, generate a new Bridge password
Bridge lets you regenerate the mailbox password from its settings. Do this once, then repeat the steps above with the new one.
Fix 2: resolve a local port conflict#
Bridge defaults to port 1143 for IMAP and 1025 for SMTP, both on localhost. Those ports aren't reserved system-wide, so any other program that grabs them first — a second mail client, a local dev server, some VPN software — will keep Bridge from binding to them, and your email client won't be able to reach it.
- 1
Check for the port warning in Bridge
Bridge surfaces an "IMAP or SMTP port error" or "port already occupied" message when this happens. If you see it, you've found the cause.
- 2
Quit other software that might hold the port
Close other mail clients, local servers, or VPN clients one at a time and retry the connection after each.
- 3
Let Bridge use different ports
In Bridge's advanced settings, change the IMAP/SMTP ports it listens on, then update the port field in your email client's account settings to match.
- 4
Restart Bridge after any port change
Bridge needs a restart to actually rebind to the new ports — a settings change alone doesn't take effect on the running process.
Fix 3: stop antivirus or a firewall from blocking Bridge#
Because Bridge's whole design routes mail through a local loopback connection, security software that inspects local traffic can mistake it for something suspicious and quietly drop the connection — often right after a security-software update, with no error that points at the real cause. Part of why this happens: Bridge secures that loopback hop with a self-signed TLS certificate it generates during setup, and some antivirus and firewall tools flag traffic encrypted with a certificate they don't recognize.
- 1
Allowlist the Bridge executable in your antivirus
Add an exception for the Bridge program path (on Windows, typically C:\Program Files\Proton AG\Proton Mail Bridge\proton-bridge.exe).
- 2
Allowlist the updates folder too
Bridge updates itself in place, and the updated binary lives in a separate updates folder — on Windows, %AppData%\Roaming\protonmail\bridge-v3\updates — that needs the same exception or the block comes back after the next update.
- 3
Add a firewall exception
On Windows, search the Start menu for "Allow an app through Windows Firewall," find or add proton-bridge.exe, and check the box for whichever network type (private/public) matches your current connection — a mismatch here silently fails.
- 4
On a corporate network, involve IT
A network-level firewall may block Proton's servers outright, independent of anything on your machine. Ask IT to allowlist mail-api.proton.me and the IP range 185.70.40.0/22 on ports 443 and 80.
The Bridge password only ever lives on your device
Two causes that aren't on the checklist above#
Two failure modes fall outside the password/port/security-software checklist because no amount of re-entering credentials or allowlisting fixes them — one is a client incompatibility, the other is an OS-level permission issue.
New Outlook for Windows (the rebuilt version Microsoft is rolling out to replace classic Outlook) has changes that Proton describes as making it "technically incompatible" with Bridge. If you're troubleshooting a Bridge connection specifically in new Outlook and nothing above resolves it, that incompatibility is the likely reason, not a misconfiguration you haven't found yet. Classic Outlook, Thunderbird, Apple Mail and other standard IMAP/SMTP clients still work with Bridge normally.
On macOS, a "cannot access keychain" message means Bridge couldn't reach the encryption key it needs from your Mac's keychain to decrypt local mail — it has nothing to do with your Proton or Bridge password. Restart Bridge and enter your Mac login password when macOS prompts for keychain access; that re-authorization is usually all it takes.
Both of these look like the three causes above until you check them
How do I tell which cause I actually have?#
The fastest diagnostic is where the failure shows up. If Bridge itself looks healthy — green status, mailbox syncing — and only the email client can't connect, it's almost always the password or the port. If Bridge itself shows a red or spinning status before the client is even involved, it's a network or security-software problem upstream of Bridge.
A second useful signal: timing. A connection that worked yesterday and stopped today, with no changes on your end, points at antivirus or firewall software that updated itself. A connection that never worked from a fresh install points at the password or a port already claimed by something else running at startup.

Preventing Proton Bridge from disconnecting again#
Once it's working, keep it working with a few habits: don't retype the Bridge password from memory when re-adding an account — always copy it fresh. Keep Bridge and your antivirus's allowlist in sync after any update to either. And if you use a VPN, check Bridge's Alternative Routing setting — running both at once is a common source of intermittent disconnects that look like a flaky Proton connection but are actually two routing layers fighting each other.
It's also worth remembering that Bridge is a paid-plan feature — it's not available on Proton's free tier, and it only runs as a desktop application on macOS, Windows and Linux. There's no mobile or hosted-webmail version, so any email client that isn't running on the same desktop as Bridge simply can't reach it, no matter how the credentials are configured.
If you've worked through every cause above and Bridge still won't connect, use its built-in reporting option rather than guessing further. Bridge can package the diagnostic logs Proton's support team actually needs and submit them directly, which is faster and more reliable than describing the symptom from memory in a support ticket.
The reason Bridge feels fragile is that it adds a whole extra local hop — decrypt, relay, re-authenticate — between your inbox and your client, and any one of password, port or security software can break that hop independently. AI Emaily connects to Proton, Gmail, Outlook and IMAP accounts directly over each provider's native protocol, so there's no local relay process to keep running, no port to collide, and nothing for antivirus to flag. We build AI Emaily.
Frequently asked
Keep reading
Sources

Written by
Nafiul HasanNafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.