Blog/ Other providers

Proton Mail Bridge Setup: Connect Proton to a Desktop Client

Nafiul HasanNafiul Hasan· 11 min read
Proton Mail Bridge setup guide showing how to connect an encrypted Proton Mail account to a desktop email client via localhost IMAP and SMTP

The short answer

Install Proton Mail Bridge on your Mac, Windows PC, or Linux machine, sign in with your Proton credentials, then configure your email client with the localhost IMAP and SMTP credentials Bridge generates. Bridge requires a paid Proton Mail plan and runs on desktop only — it does not work on mobile.

How to set up Proton Mail Bridge on Windows, macOS, and Linux, with exact IMAP and SMTP credentials for Thunderbird, Outlook, and Apple Mail.

On this page
  1. 01Before you start
  2. 02How to install and set up Proton Mail Bridge
  3. 03How to configure Thunderbird, Outlook, and Apple Mail
  4. 04What to do when Bridge does not connect
  5. 05A faster way to handle email volume

Proton Mail encrypts your messages before they leave your device, which means there is no public IMAP server you can point Thunderbird, Outlook, or Apple Mail at — the data on Proton servers is ciphertext, not readable mail. Proton Mail Bridge solves that by running a small application on your computer. It authenticates with Proton, decrypts incoming mail locally, then re-exposes it as a standard IMAP and SMTP server on 127.0.0.1. Your email client connects to that localhost address, and the decrypted messages never leave your machine.

The result is Proton's end-to-end encryption intact, with a desktop client of your choice. This guide covers the full setup: downloading and installing Bridge, signing in, reading the credentials it generates, and configuring each of the three major desktop clients. It also covers what to do when the connection breaks and one important limitation you should understand before you start.

How to set up Proton Mail Bridge is the single question this guide answers, in order, for every supported platform. If you are troubleshooting an existing install rather than starting fresh, jump to the fifth section.

Before you start#

Two requirements must be in place before Bridge will work. First, Proton Mail Bridge is only available on a paid Proton plan — Proton Mail Plus, Proton Unlimited, or a Business plan. A Proton Mail Free account does not include Bridge. If you try to sign in to Bridge on a free account, it will prompt you to upgrade before proceeding.

Second, Bridge is a desktop-only application. As of mid-2026, it runs on 64-bit Windows 10 (version 22H2 or later) and Windows 11, macOS 15 (Sequoia) and macOS 26 (Tahoe), and 64-bit Linux via DEB, RPM, and PKGBUILD packages. It is not available on iOS or Android. On macOS, Bridge supports both Apple Silicon (M-series) and Intel processors. Other ARM devices are not supported.

Check that your operating system is on the supported list before downloading. Bridge may install on older OS versions, but Proton provides full technical support only for the versions above, and newer Bridge releases may drop older systems without notice.

Free-plan users cannot use Bridge

Proton Mail Bridge is gated at the account level — a paid Proton plan is required. Proton Mail Free does not include it, and there is no workaround. If you are on the free tier and encounter IMAP setup instructions elsewhere, those will not work for a standard Proton account without Bridge. You will need to upgrade your Proton plan first.

How to install and set up Proton Mail Bridge#

The install process is the same across all three platforms at a high level: download, install, sign in, choose an address mode, then read the credentials Bridge generates. The per-platform packaging differs, and Apple Mail has one extra step involving a local certificate, but the credentials and port numbers are always in the same place inside the Bridge interface.

  1. 1

    Download Bridge from proton.me/mail/bridge

    Go to proton.me/mail/bridge and download the installer for your operating system. Windows gets a 64-bit .exe installer. macOS gets a .dmg (both Apple Silicon and Intel). Linux users can choose DEB packages for Ubuntu-based distributions, RPM for Fedora, or PKGBUILD for Arch-based systems. Download only from the official Proton site — third-party packages are not vetted by Proton.

  2. 2

    Install and sign in with your Proton account

    Run the installer on Windows, drag Bridge to Applications on macOS, or install via your package manager on Linux. Launch Bridge, then sign in with your Proton Mail email address and your Proton account password. This is the only point in the process that uses your actual Proton password. Every credential you will enter into your email client is generated separately by Bridge.

  3. 3

    Choose combined or split address mode

    Bridge offers two modes. Combined mode (the default) presents all your Proton addresses as a single IMAP account — one inbox, any address selectable when composing. Split mode creates a separate IMAP account for each address, giving you distinct inboxes in your email client. Combined mode is right for most users. Split mode is useful only if you need per-address inbox separation inside your client.

  4. 4

    Open Mailbox details and copy your credentials

    Click your account in the Bridge sidebar. The Mailbox details panel shows everything your email client needs. Note the following values: IMAP host 127.0.0.1, IMAP port 1143 with STARTTLS or 993 with SSL, SMTP host 127.0.0.1, SMTP port 1025 with STARTTLS or 465 with SSL, and a long generated password. Copy that password. It is what you will paste into your email client — not your Proton account password.

  5. 5

    Enable Bridge to launch automatically at login

    Open Bridge settings and turn on the option to start Bridge when your computer starts. Bridge must be running on your machine at all times for your email client to sync or send. If Bridge is closed, your client will report a connection error even though your credentials are correct. Auto-launch removes that dependency and prevents the most common cause of intermittent sync failures.

The Bridge password is not your Proton account password

Bridge generates its own IMAP and SMTP password separately from your Proton login credentials. Entering your actual Proton password into your email client configuration will fail authentication. Copy the generated password from Bridge's Mailbox details panel and paste it directly. If you ever need to reset it, you can do so from Bridge settings without affecting your Proton account login.

How to configure Thunderbird, Outlook, and Apple Mail#

Once Bridge is running and you have your IMAP and SMTP credentials from the Mailbox details panel, the remaining steps depend on which email client you are configuring. The core inputs are the same everywhere: host 127.0.0.1, the port pair you chose, your full Proton email address as the username, and the Bridge-generated password. Each client has one platform-specific step that causes most of the connection failures.

The table below maps each client to its required setup step and the most common mistake. Read your client's row before you add the account — the gotchas in the final column are what the error messages almost never explain clearly.

Diagram showing Proton Mail Bridge sitting between the encrypted Proton Mail cloud and a local desktop email client, decrypting messages locally and serving them over 127.0.0.1 IMAP and SMTP
Bridge decrypts mail locally and re-exposes it over 127.0.0.1, so any standard IMAP client can connect without accessing Proton's encrypted server directly.
Email clientSupported platformsKey setup stepMost common mistake
Mozilla ThunderbirdWindows, macOS, LinuxDisable Account Hub before adding the account: Menu > Settings > General, uncheck Create accounts in the new Account Hub. Then add via Menu > New Account > Email and enter the Bridge-generated password when prompted.Two certificate prompts appear — one for IMAP and a separate one when you send your first message for SMTP. Both require manual confirmation. Dismissing the SMTP prompt causes outgoing mail to fail while incoming mail works fine.
Microsoft OutlookWindows, macOSAdd a new account via File > Add Account, select advanced options, and choose to set up the account manually as IMAP. Enter 127.0.0.1 as both the incoming and outgoing server address, then set the port numbers and encryption method from your Bridge Mailbox details.Outlook sometimes detects the email domain and offers to autoconfigure using its own server settings instead. Dismiss that suggestion and enter the 127.0.0.1 values from Bridge by hand. Auto-detected settings will not connect to a local Bridge process.
Apple MailmacOS onlyBridge prompts you to install a local security certificate via macOS System Preferences. Open System Preferences, find the downloaded Proton profile under Downloaded, double-click it, and click Install twice to confirm. Apple Mail will then begin downloading your messages automatically.The certificate profile appears unsigned in macOS settings — that is expected behavior for a self-signed local certificate. If you skip or dismiss the certificate install, Apple Mail cannot open an encrypted connection to Bridge. Return to Bridge, click Configure for Apple Mail, and reinstall the certificate.
Any other IMAP clientWindows, macOS, LinuxUse 127.0.0.1 for both the incoming (IMAP) and outgoing (SMTP) server. Username is your full Proton email address. Password is the Bridge-generated credential. Use STARTTLS on ports 1143 and 1025, or SSL on ports 993 and 465.Bridge creates a localhost-only server. It is only reachable from the same machine it runs on. A hosted email client or one running on a different device cannot reach 127.0.0.1 over a network — the connection will time out.

What to do when Bridge does not connect#

Most Bridge connection failures come down to a small set of causes, and the error message your email client displays is often misleading. A generic authentication failure can mean a wrong password, a missing certificate confirmation, or Bridge simply not running. Work through the possibilities below in order — the first two account for the majority of reported issues.

  • Bridge is not running. Your email client cannot reach 127.0.0.1 if Bridge is closed. Open Bridge, sign in if prompted, and wait for the connected status indicator before retrying. A connection refused error rather than an authentication error is the clearest signal that Bridge itself is the problem.
  • Wrong password entered in the client. The Bridge-generated password is long and random — it is easy to mistype or to accidentally enter your Proton account password instead. Open Bridge, click your account, and copy the password from the Mailbox details panel. Paste it directly into your client settings, replacing whatever is there.
  • Certificate not confirmed in Thunderbird or Apple Mail. Both clients prompt you to accept a self-signed certificate during initial setup, and the prompts are easy to dismiss by accident. In Thunderbird, go to account settings and look for a security exception to add manually. In Apple Mail, return to Bridge and reinstall the certificate through System Preferences.
  • Port conflict on 1143 or 1025. If another application is already listening on the same port, Bridge cannot bind to it. Bridge settings let you change the IMAP and SMTP listening ports. If you change either port, update the matching port in your email client configuration to reflect the new value.
  • Bridge has lost its session with Proton. After a Proton account password change, a long period of inactivity, or a system hibernate, Bridge may lose its authenticated session and stop syncing without a clear error. Open Bridge, sign out of your account, then sign back in. Your email client will reconnect once Bridge re-authenticates.

A faster way to handle email volume#

Bridge solves one specific problem: getting your Proton Mail into a traditional IMAP client. If what you are actually solving for is inbox volume — too much to triage, replies falling behind, follow-ups missed — that is a different job with a different tool.

AI Emaily is an AI-native email client that handles triage, drafting, and follow-ups across Gmail, Outlook, iCloud, and standard IMAP accounts, with no local install required. It does not connect through Bridge — Bridge is localhost-only and AI Emaily is a hosted service, so the two do not overlap. For Proton Mail specifically, the connection works differently from Bridge; the integration is documented at /docs/connect-proton. For every other provider in that list, there is no Bridge step at all.

We build AI Emaily. If managing email volume is the angle you want to explore, you can start a 7-day free trial at /pricing.

Frequently asked

Nafiul Hasan

Written by

Nafiul Hasan

Nafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.

EntrepreneurAI Automation System BuilderAI EnthusiastBuilds AI Enterprise Solutions10+ years experience
More from Nafiul
Ready when you are

Connect any inbox and let AI handle the heavy lifting

AI Emaily connects to Gmail, Outlook, iCloud, and standard IMAP accounts. Triage, drafts, and follow-ups on Autopilot — with undo and a full audit trail. Start your 7-day free trial.

  • 7-day free trial
  • Cancel anytime
  • Every provider