Blog/ Head-to-head comparisons

Proton Mail vs Fastmail for IMAP Access: Bridge or Native?

Nafiul HasanNafiul Hasan· 15 min read
Diagram comparing Proton Mail vs Fastmail for IMAP access: Proton routes a desktop mail client through a local Proton Bridge app, while Fastmail connects to a standard IMAP server directly

The short answer

Fastmail is easier. It speaks IMAP natively, so Apple Mail, Outlook or Thunderbird connect with a hostname, a port and an app password. Proton Mail exposes no direct IMAP at all; you must run Proton Bridge, a paid-plan-only desktop app that decrypts mail locally. Bridge has no mobile version, so third-party phone clients are out.

Proton Mail vs Fastmail for IMAP access: Fastmail speaks IMAP natively, Proton needs the paid-only Bridge app — and that difference decides mobile.

On this page
  1. 01The verdict up front
  2. 02At a glance: how each one connects
  3. 03Why Proton needs a bridge at all
  4. 04Where Fastmail wins
  5. 05What JMAP actually buys you over IMAP
  6. 06Where Proton wins, and it is the dimension most people came for
  7. 07Can you use Proton Mail in Apple Mail on iPhone?
  8. 08Multi-device reality: what setup actually looks like
  9. 09Pricing model, without the numbers
  10. 10Who each one is genuinely for
  11. 11A third option, honestly
  12. 12The short version

If you have already decided that you want a private mailbox and you also want to read it in Apple Mail, Outlook or Thunderbird, then Proton Mail vs Fastmail for IMAP access is not a question about features. It is a question about one architectural decision each company made years ago, and everything you will experience as setup friction follows from it.

Fastmail runs an ordinary IMAP server. Your client connects to it the way a client has connected to a mail server since the 1990s: hostname, port, username, password. Proton Mail does not run one you can reach. Your mail sits encrypted in a form the server cannot read, so there is nothing to hand a remote client, and the workaround is a local program called Proton Bridge that decrypts on your own machine and serves IMAP to software running beside it.

That single difference decides the rest of this comparison. It decides whether your phone can use a third-party mail app. It decides whether a mail client on a second laptop needs its own setup. It decides whether a cloud service can sync your mailbox at all. This post scores only client access. If you want the custom-domain or business-team comparison, those are separate questions with different winners.

The verdict up front#

For connecting a desktop email client, Fastmail wins, and it is not close. Native IMAP means any client that has ever spoken the protocol works, on any operating system, with no extra software running in the background. Proton requires Bridge, Bridge requires a paid plan, and Bridge only exists for desktop.

For keeping your mail unreadable to the provider, Proton wins, and it is also not close. That is not a consolation prize — it is the actual reason Bridge exists. Proton cannot serve you a plaintext IMAP stream because Proton does not hold your mail in a form it could serve. The setup burden is the encryption model showing through, not an arbitrary restriction.

So the honest verdict is conditional. If the requirement is a desktop client, pick Fastmail. If the requirement is end-to-end encrypted storage and you can live inside Proton's own apps most of the time, pick Proton and treat Bridge as a desktop-only convenience rather than a general answer. If you need both without compromise, neither product gives it to you, because the two goals are in genuine tension.

Verify before you buy

Plan names, protocol availability and platform support all change. Everything here was checked against Proton's and Fastmail's own live pages in September 2026. Before you pay for either, open the vendor's current setup documentation and confirm that the specific plan you are buying includes the specific protocol you need.

At a glance: how each one connects#

DimensionProton MailFastmail
Direct IMAP to a third-party clientNo. Nothing to connect toYes. Standard IMAP server
What you connect to insteadProton Bridge, a local app on your own computerimap.fastmail.com on port 993
Plan requirement for client accessBridge is available only on a paid plan that includes Proton MailBasic plans do not include IMAP, SMTP, CalDAV or CardDAV
Desktop operating systemsWindows, macOS and Linux (Bridge is a desktop application)Any OS with a mail client, because there is no extra software
Third-party mail app on iPhone or AndroidNot supported. Bridge has no mobile versionSupported. Standard IMAP settings
Credential you actually typeA per-account password that Bridge generates, not your Proton loginA Fastmail app password, not your login password
Background software requiredYes. Bridge must be running and unlockedNo
Modern protocol beyond IMAPNone exposed publiclyJMAP (RFC 8620 and RFC 8621)
Server-side content search from a clientLimited. Bridge searches what it has decrypted locallyYes, server-side over IMAP
Provider can read your message bodiesNo. Zero-access encryption at restYes, in principle. Standard encryption in transit and at rest

Why Proton needs a bridge at all#

IMAP was designed on an assumption that has quietly become controversial: the server can read your mail. RFC 9051, the current IMAP4rev2 specification, describes a server that indexes message bodies, evaluates SEARCH commands against their text, and returns parts of messages on request. Every one of those operations requires plaintext on the server side.

Proton's storage model breaks that assumption deliberately. Message bodies are encrypted so that Proton cannot decrypt them, which means a Proton IMAP server would have nothing useful to send. There is no configuration flag that fixes this. It is not a missing feature; it is the feature.

Bridge resolves the contradiction by moving the IMAP server onto your computer. It authenticates to Proton, pulls your encrypted mail down, decrypts it locally using keys that only exist on your machine, and then presents a perfectly ordinary IMAP and SMTP server on localhost for Apple Mail, Outlook or Thunderbird to talk to. Proton documents exactly those three clients.

Illustration of a local bridge sitting between an encrypted remote mailbox and a desktop email client, showing that decryption happens on the user's own machine rather than on the provider's server
Bridge does not unlock Proton's servers. It moves the IMAP server to your desk.

Where Fastmail wins#

Fastmail wins on setup, on platform coverage, on what happens when you add a second device, and on what a mail client can ask the server to do for it. These are four separate wins, and they compound.

Setup is the obvious one. You create an app password in Fastmail's settings, scoped to mail access, then type imap.fastmail.com on port 993 and smtp.fastmail.com on port 465 into your client. Fastmail is explicit that your regular login password will not work here, which is a security improvement rather than an inconvenience: the credential in your mail client is revocable on its own without changing anything else.

Platform coverage is the bigger one. Because there is no helper application, there is nothing to port. A Linux desktop, an old Windows machine, a Mac, a phone, a scripted backup job, a mail archiver on a home server — anything that speaks IMAP works, and it works the same way everywhere. Nothing needs to be running in the background for your mail to arrive.

Multi-device behaviour follows from that. Each new client is a fresh app password and the same two hostnames. Fastmail's own mobile apps and the standard settings coexist; you are not choosing between them.

  • Server-side search: your client sends a SEARCH command and the server answers from its own index, so searching a large archive does not depend on what your laptop has downloaded.
  • JMAP as an alternative: RFC 8620 defines the core protocol and RFC 8621 defines JMAP for Mail, with RFC 8887 covering JMAP over WebSocket and RFC 9749 covering push. Fastmail has driven this work.
  • No single point of failure on your desk: if your computer is off, your phone still gets mail, because there is no local decryption step in the path.
  • Standard tooling works: migration utilities, archiving scripts and backup tools that speak IMAP need no special handling.

What JMAP actually buys you over IMAP#

JMAP is worth understanding because it is the clearest example of Fastmail treating client access as a product rather than a legacy obligation. IMAP is a stateful, connection-oriented protocol with a long history of implementation differences; JMAP is a JSON API over HTTP designed for the way modern clients actually behave — intermittent connectivity, batched requests, efficient resynchronisation after being offline.

In practice, most readers will never touch JMAP directly, because most mail clients still speak IMAP. The point is not that you will use it. The point is what its existence tells you about which of these two companies is investing in third-party client access at all.

Proton's investment has gone the other way, toward its own clients, because that is where its encryption model works end to end. That is a coherent strategy. It is just the opposite of what you want if your requirement starts with the words in Thunderbird.

Check the plan, not just the product

Fastmail's own documentation states that Basic plans do not include access to IMAP, SMTP, CalDAV or CardDAV. Native IMAP support is a property of the service, but access to it is a property of your plan. Confirm on Fastmail's current plan comparison before assuming your tier includes it.

Where Proton wins, and it is the dimension most people came for#

Proton wins on confidentiality, outright. Message bodies are stored under zero-access encryption, meaning Proton cannot read them even if compelled to try. Fastmail does not claim this and does not pretend to; it offers ordinary transport and at-rest encryption, which protects your mail from interception and from someone walking off with a disk, but not from the provider itself.

If your threat model includes the provider — a journalist, an activist, someone handling material where a subpoena to the host is a real risk — that difference is not a tiebreaker. It is the whole decision, and no amount of IMAP convenience outweighs it.

Proton also wins a smaller point that is easy to miss: Bridge is genuinely cross-platform on desktop. Windows, macOS and Linux all get it. Linux users in particular are used to being the afterthought, and here they are not.

And there is a security argument for the bridge model itself. The decrypted copy of your mailbox lives on your machine, inside software you chose, rather than in a server-side index someone else operates. For some people that is exactly the right trade.

Can you use Proton Mail in Apple Mail on iPhone?#

No, not through IMAP. This is the single most common disappointment in this comparison and it deserves a direct answer.

Proton Bridge is a desktop application. There is no iOS or Android build, and the architecture explains why: Bridge works by running a mail server on the same machine as the client, and iOS does not let a background app serve a local IMAP port to Apple Mail in the way a desktop operating system does. On a phone, Proton mail means Proton's own app.

Fastmail does support this. The same IMAP and SMTP settings you would use on a desktop work in Apple Mail on iPhone, in Gmail's app where it accepts IMAP accounts, and in third-party clients. Fastmail also ships its own mobile apps, so you can use both.

If being able to choose your phone's mail app matters to you, this dimension alone settles the comparison, and no other dimension can rescue it.

Bridge only serves the machine it runs on

Bridge listens on 127.0.0.1, which is your own computer and nowhere else. A client on a different device, a second laptop, or any remote service cannot reach it over the network without you deliberately exposing a locally running mail server to the internet. Treat that as a security decision, not a configuration step.

Multi-device reality: what setup actually looks like#

  1. 1

    Fastmail, first device

    Create an app password scoped to mail, enter imap.fastmail.com:993 and smtp.fastmail.com:465 in your client, and you are done. Two to three minutes.

  2. 2

    Fastmail, every device after that

    Repeat with a new app password. Nothing else changes. The server is the same server, so all devices see the same folder state.

  3. 3

    Proton, first desktop

    Install Bridge, sign in with your Proton account, open the account's connection details, and copy the per-account password Bridge generates. Point your client at the local host and the ports Bridge shows you.

  4. 4

    Proton, every desktop after that

    Install Bridge again on that machine and repeat the whole process, including a new Bridge-generated password. Each computer runs its own local server.

  5. 5

    Proton, any phone or tablet

    Use Proton's own app. There is no third-party client path.

  6. 6

    Either one, when something breaks

    With Fastmail you check credentials and ports. With Proton you also check whether Bridge is running and unlocked, because when it is not, your mail client simply sees a dead server.

Decision fork illustration showing two paths for private email client access: a direct native IMAP route and an indirect route that passes through a locally installed bridge application
The fork is not Proton versus Fastmail. It is whether your requirement starts with a client name or with the word confidential.

Pricing model, without the numbers#

Prices change often enough that printing them here would make this page wrong within months, so here is the shape instead, and you should check both vendors' current pages before deciding.

Both companies sell subscriptions with no permanent free desktop-client path. Proton offers a free mailbox, but Bridge is not part of it: Proton states that Bridge is available only with a paid plan that includes Proton Mail. So on Proton, third-party client access is a paid capability, full stop.

Fastmail is paid across the board, with a trial, and gates protocol access by tier. Its documentation states that Basic plans do not include IMAP, SMTP, CalDAV or CardDAV, so choosing the cheapest tier can remove the exact capability this comparison is about.

The practical takeaway is the same on both sides and it is easy to get wrong: on neither service is client access guaranteed by simply having an account. Read the plan page for the protocol, not just the storage number.

Who each one is genuinely for#

If this describes youPickWhy
You want Thunderbird, Apple Mail or Outlook as your daily driverFastmailNative IMAP, no helper app, works identically on every desktop OS
You want to choose your own mail app on your phoneFastmailBridge has no mobile version, so Proton means Proton's app on mobile
Your threat model includes the email provider itselfProtonZero-access encryption of message bodies; Fastmail makes no such claim
You use one Mac or PC and rarely leave itEitherBridge's desktop-only limit costs you very little in this pattern
You run Linux and want a private mailbox in a desktop clientEitherFastmail needs nothing extra; Proton genuinely ships a Linux Bridge build
You need a cloud service or server-side tool to reach the mailboxFastmailBridge binds to localhost, so remote services cannot connect to it
You want fast search across a large archive from a thin clientFastmailServer-side IMAP search, plus JMAP for clients that support it

A third option, honestly#

There is a case this comparison does not cover: you are not really choosing a mailbox, you are choosing what reads it. Plenty of people already have a Fastmail or Proton account and the actual complaint is the client — too much manual triage, replies that sit for days, three accounts in three windows.

We build AI Emaily, an AI-native email client, so treat what follows as interested rather than neutral. It is relevant here for one reason and limited here for another, and both come straight out of the architecture this post just described.

The relevant half: AI Emaily connects over standard IMAP, so a Fastmail mailbox works the way any other IMAP account works. You create a Fastmail app password scoped to mail, paste it into the IMAP tab, and the account syncs alongside Gmail and Outlook accounts in one inbox. On top of that we do the work a plain client will not: triage, drafted replies you approve before anything sends, undo, and an audit trail of every action the agent took. Drafting voice comes from a Personal Context brain you fill in and per-client profiles you set, not from us reading your old mail, and we do not train on your messages.

The limiting half, stated plainly: AI Emaily generally cannot connect to Proton Mail. Bridge serves 127.0.0.1, which is your own computer, and we are a cloud service that cannot reach it. Our own setup documentation says exactly that and recommends forwarding Proton to a mailbox we can reach instead, which is a workaround, not parity. If your mail must stay end-to-end encrypted to Proton's standard, we are not the right answer and no amount of product copy changes that.

So the honest placement is narrow. If you picked Fastmail for the reasons above and want the client to do more than display messages, we are worth a look. Pricing is a 7-day free trial on our paid plans, with no permanent free tier. If you picked Proton for the encryption, stay in Proton's apps.

The short version#

Fastmail is the easier connection and the better answer for anyone whose requirement starts with a client name. Proton is the better answer for anyone whose requirement starts with the word confidential, and Bridge is the price of that, paid in setup friction and in the absence of any mobile option.

Neither company is being difficult. They optimised for different things, told you which, and documented the consequences. The mistake is buying one while expecting the other's strengths, and that mistake is easy to avoid by reading the plan page for the protocol you need before you pay.

Frequently asked

Nafiul Hasan

Written by

Nafiul Hasan

Nafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.

EntrepreneurAI Automation System BuilderAI EnthusiastBuilds AI Enterprise Solutions10+ years experience
More from Nafiul
Ready when you are

Already on Fastmail? Put an agent in front of it.

AI Emaily connects any IMAP mailbox and triages, drafts and closes loops — with approve-before-send, undo and a full audit trail. 7-day free trial, no permanent free tier.

  • 7-day free trial
  • Cancel anytime
  • Every provider