Blog/ Other providers

How to Create an App-Specific Password in Zoho Mail

Nafiul HasanNafiul Hasan· 9 min read
How to create an app password in Zoho Mail: a key passing from Zoho Accounts security settings to an IMAP email client

The short answer

Sign in at accounts.zoho.com, open Security, then App Passwords, and click Generate New Password. Name it after the client, click Generate, and copy it, because Zoho shows it only once. Turn on IMAP under Zoho Mail Settings, Mail Accounts, then enter your full email address and that app password in the IMAP client.

How to create an app password in Zoho Mail: generate it under Security, App Passwords, then use it in any IMAP, POP or SMTP client instead of your login.

On this page
  1. 01What is the short answer?
  2. 02What do you need before you start?
  3. 03Do you need two-factor authentication turned on first?
  4. 04How do you generate a Zoho app password step by step?
  5. 05Why name each password after a device?
  6. 06How does setup differ by Zoho account type?
  7. 07Do different email clients handle it differently?
  8. 08Why does Zoho reject my password in Outlook?
  9. 09How do you revoke a Zoho app-specific password?
  10. 10Is there a faster way to run a Zoho inbox once it is connected?

If you want to know how to create an app password in Zoho Mail, the short version is that it lives in Zoho Accounts, not in Zoho Mail itself. Once two-factor authentication is on, Zoho stops accepting your normal password from outside apps like Outlook, Apple Mail or Thunderbird. Those apps sign in with a separate, single-purpose password instead.

This guide covers where that password is generated, how to use it for IMAP and SMTP, how the setup differs between personal and organization accounts, and how to revoke one when you stop using a client. Every menu path below was checked against Zoho's own help pages in September 2026. Zoho changes its interface from time to time, so if a label looks different, the help links at the end of this post are the place to confirm it.

What is the short answer?#

Go to accounts.zoho.com, open Security, choose App Passwords, and click Generate New Password. Give it a name, click Generate, and copy the result. Paste that password into your email client wherever it asks for a password, and keep your full email address as the username.

Zoho's help pages call these application-specific passwords, and some older pages call them device-specific passwords. They are the same thing. Each one is a long password that works only for mail and calendar clients, never for signing in to the Zoho website.

Zoho shows the password once

Zoho's help pages say the generated password is displayed only once and will not be shown again. Copy it straight into your client. If you lose it, delete that entry and generate a new one rather than hunting for the old one.

What do you need before you start?#

Three things decide whether the setup works first time. Check them before you generate anything, because a new app password will not fix a problem that sits somewhere else.

  • IMAP access switched on. Zoho's IMAP help page says IMAP must be enabled before a client can connect. The switch is in Zoho Mail under Settings, Mail Accounts, then the IMAP section of your address.
  • A plan that includes IMAP. As of September 2026, Zoho's IMAP help page states that newly signed-up Free plan users do not get IMAP access. If you are on the free plan, check that page before you spend time on passwords.
  • Your admin's permission, on organization accounts. Admins can switch off IMAP, POP and ActiveSync for users through Access Restrictions in the Zoho Mail Admin Console. If IMAP is blocked there, no password will get you in.

Do you need two-factor authentication turned on first?#

Not to generate one. Zoho's account security help says app passwords are available whether or not multi-factor authentication is enabled, and recommends them either way. They become required once two-factor authentication is on, because your regular password then fails in outside clients.

Zoho's two-factor authentication page also lists organization users with SAML sign-in. If your company signs in to Zoho through a single sign-on provider, your IMAP and POP clients still need an app password, because the client cannot complete a browser-based sign-in.

How do you generate a Zoho app password step by step?#

  1. 1

    Open Zoho Accounts

    Go to accounts.zoho.com and sign in. You can also reach it from My Account in the profile panel of any Zoho app.

  2. 2

    Go to Security, then App Passwords

    Choose Security in the left menu, then App Passwords. This is the answer to where Zoho app passwords are in settings: they are in your account security, not in Zoho Mail's settings.

  3. 3

    Click Generate New Password

    Zoho asks for a name for the application. Use something you will recognize later, such as Outlook work laptop or iPhone Mail.

  4. 4

    Click Generate and copy the password

    Copy it right away. Zoho's help advises entering it without spaces, so if you retype it by hand, leave out any spacing from the display.

  5. 5

    Enable IMAP in Zoho Mail

    In Zoho Mail, open Settings, then Mail Accounts, select your email address, and tick IMAP Access in the IMAP section. Save.

  6. 6

    Add the account to your client

    Choose manual or IMAP setup. Enter your full email address as the username and the app password as the password, for both incoming and outgoing mail.

Why name each password after a device?#

One password per client is the whole point of the feature. If your phone is lost, you delete the phone's password and your laptop keeps syncing. If you share one password across every device, revoking it cuts off all of them at once.

Zoho's two-factor authentication page also notes that app passwords never expire, even when your web password does. That is convenient, and it is also why naming matters. A password that never expires stays valid until someone deletes it, so a clear name is how you find the right one to remove a year from now.

How does setup differ by Zoho account type?#

The password step is identical for everyone. What changes is the server name your client needs, which depends on whether you have a personal address or an organization address on your own domain.

Two settings switched on before a Zoho IMAP client can connect: IMAP access in Zoho Mail and an app password in Zoho Accounts
Most failed Zoho logins come down to one of two switches: IMAP access, or the password type.
Account typeIMAP serverSMTP serverPassword to use
Personal (@zohomail.com)imap.zoho.com, port 993, SSLsmtp.zoho.com, port 465 SSL or 587 TLSApp password if two-factor authentication is on
Organization (your own domain)imappro.zoho.com, port 993, SSLsmtppro.zoho.com, port 465 SSL or 587 TLSApp password if two-factor authentication is on
Organization with SAML sign-inimappro.zoho.com, port 993, SSLsmtppro.zoho.com, port 465 SSL or 587 TLSApp password, per Zoho's two-factor authentication page
New Free plan sign-upNot available, per Zoho's IMAP page (September 2026)Not applicableNot applicable

Do different email clients handle it differently?#

The rule is the same in every client: full email address as the username, app password as the password, and the servers from the table above. Where clients differ is how many places they ask for the password.

  • Outlook and Apple Mail usually ask once and use the same credentials for sending. If sending fails but receiving works, check the outgoing server settings for a separate password field.
  • Thunderbird and most Android mail apps keep incoming and outgoing credentials separate. Paste the app password into both.
  • Any client that tries automatic setup may guess the wrong server for an organization account. Choose manual setup and enter the imappro and smtppro hosts yourself.
  • Zoho's own help says the exact server details for your account type and data center are listed inside your account. If your account is hosted in a regional data center, use the hosts shown there rather than the defaults above.

Why does Zoho reject my password in Outlook?#

Almost always because Outlook is sending your normal Zoho password after two-factor authentication was turned on. Zoho's help article on Outlook and iPhone authentication errors names this as the cause and gives one fix: generate an application-specific password and use it instead.

If you are already using an app password and it still fails, work through the causes below in order. They are listed from most to least common in practice.

  • IMAP is off. Check Settings, Mail Accounts, IMAP section in Zoho Mail. A new account or a recently changed plan may have it switched off.
  • Wrong server for your account type. Organization addresses use imappro.zoho.com and smtppro.zoho.com. Personal addresses use imap.zoho.com and smtp.zoho.com.
  • Username is not the full address. Zoho's SMTP help says the username must be the complete email address, matching the account or one of its aliases.
  • Spaces or a typo in the password. Paste it rather than retyping it. If in doubt, delete it and generate a fresh one.
  • Your admin blocked IMAP. On organization accounts, ask whoever manages Zoho whether an Access Restriction applies to you.
  • The password was deleted. If someone cleaned up the App Passwords list, the client will fail with no other warning. Generate a new one.

Test with one client first

When several devices are failing at once, fix one client end to end before touching the others. If a freshly generated password works there, the problem on the other devices is their stored password or server settings, not your Zoho account.

How do you revoke a Zoho app-specific password?#

Go back to accounts.zoho.com, open Security, then App Passwords. Find the entry by the name you gave it and delete it. Zoho's two-factor authentication page says you can delete one whenever you no longer use that device or application, or whenever you want to cut off its access.

The client using that password stops syncing at its next sign-in attempt. Your web password, your other app passwords and your other devices are not affected. On organization accounts, Zoho's help says admins can also revoke a user's app passwords from the two-factor authentication settings, which is the step to take when a staff member leaves.

A good habit is to review the list whenever you replace a phone or laptop. Because app passwords never expire, an old entry for a device you sold two years ago is still a working credential until it is removed.

Is there a faster way to run a Zoho inbox once it is connected?#

The steps above get your mail into a client. What they do not do is sort it, draft replies or chase the threads that stall. That work starts after the password and repeats every day.

We build AI Emaily, an email client that connects to Zoho Mail through its IMAP tab using exactly the app password you just generated. It envelope-encrypts that password at rest and decrypts it only inside an isolated sync worker, and it tests the connection before saving. Once connected, it triages incoming mail and drafts replies from the Personal Context you set, and in Copilot mode nothing is sent until you approve it, with undo and an audit log for every action. It does not replace Zoho's own admin console, filters or calendar. It is the triage and drafting layer on top of the mailbox you already have.

Frequently asked

Nafiul Hasan

Written by

Nafiul Hasan

Nafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.

EntrepreneurAI Automation System BuilderAI EnthusiastBuilds AI Enterprise Solutions10+ years experience
More from Nafiul
Ready when you are

Connect Zoho Mail and let the triage run for you

Add your Zoho app password on the IMAP tab, then try Pro or Autopilot free for 7 days. Every send waits for your approval.

  • 7-day free trial
  • Cancel anytime
  • Every provider