How to Create an App-Specific Password in Zoho Mail

The short answer
Sign in at accounts.zoho.com, open Security, then App Passwords, and click Generate New Password. Name it after the client, click Generate, and copy it, because Zoho shows it only once. Turn on IMAP under Zoho Mail Settings, Mail Accounts, then enter your full email address and that app password in the IMAP client.
How to create an app password in Zoho Mail: generate it under Security, App Passwords, then use it in any IMAP, POP or SMTP client instead of your login.
On this page
- 01What is the short answer?
- 02What do you need before you start?
- 03Do you need two-factor authentication turned on first?
- 04How do you generate a Zoho app password step by step?
- 05Why name each password after a device?
- 06How does setup differ by Zoho account type?
- 07Do different email clients handle it differently?
- 08Why does Zoho reject my password in Outlook?
- 09How do you revoke a Zoho app-specific password?
- 10Is there a faster way to run a Zoho inbox once it is connected?
If you want to know how to create an app password in Zoho Mail, the short version is that it lives in Zoho Accounts, not in Zoho Mail itself. Once two-factor authentication is on, Zoho stops accepting your normal password from outside apps like Outlook, Apple Mail or Thunderbird. Those apps sign in with a separate, single-purpose password instead.
This guide covers where that password is generated, how to use it for IMAP and SMTP, how the setup differs between personal and organization accounts, and how to revoke one when you stop using a client. Every menu path below was checked against Zoho's own help pages in September 2026. Zoho changes its interface from time to time, so if a label looks different, the help links at the end of this post are the place to confirm it.
What is the short answer?#
Go to accounts.zoho.com, open Security, choose App Passwords, and click Generate New Password. Give it a name, click Generate, and copy the result. Paste that password into your email client wherever it asks for a password, and keep your full email address as the username.
Zoho's help pages call these application-specific passwords, and some older pages call them device-specific passwords. They are the same thing. Each one is a long password that works only for mail and calendar clients, never for signing in to the Zoho website.
Zoho shows the password once
What do you need before you start?#
Three things decide whether the setup works first time. Check them before you generate anything, because a new app password will not fix a problem that sits somewhere else.
- IMAP access switched on. Zoho's IMAP help page says IMAP must be enabled before a client can connect. The switch is in Zoho Mail under Settings, Mail Accounts, then the IMAP section of your address.
- A plan that includes IMAP. As of September 2026, Zoho's IMAP help page states that newly signed-up Free plan users do not get IMAP access. If you are on the free plan, check that page before you spend time on passwords.
- Your admin's permission, on organization accounts. Admins can switch off IMAP, POP and ActiveSync for users through Access Restrictions in the Zoho Mail Admin Console. If IMAP is blocked there, no password will get you in.
Do you need two-factor authentication turned on first?#
Not to generate one. Zoho's account security help says app passwords are available whether or not multi-factor authentication is enabled, and recommends them either way. They become required once two-factor authentication is on, because your regular password then fails in outside clients.
Zoho's two-factor authentication page also lists organization users with SAML sign-in. If your company signs in to Zoho through a single sign-on provider, your IMAP and POP clients still need an app password, because the client cannot complete a browser-based sign-in.
How do you generate a Zoho app password step by step?#
- 1
Open Zoho Accounts
Go to accounts.zoho.com and sign in. You can also reach it from My Account in the profile panel of any Zoho app.
- 2
Go to Security, then App Passwords
Choose Security in the left menu, then App Passwords. This is the answer to where Zoho app passwords are in settings: they are in your account security, not in Zoho Mail's settings.
- 3
Click Generate New Password
Zoho asks for a name for the application. Use something you will recognize later, such as Outlook work laptop or iPhone Mail.
- 4
Click Generate and copy the password
Copy it right away. Zoho's help advises entering it without spaces, so if you retype it by hand, leave out any spacing from the display.
- 5
Enable IMAP in Zoho Mail
In Zoho Mail, open Settings, then Mail Accounts, select your email address, and tick IMAP Access in the IMAP section. Save.
- 6
Add the account to your client
Choose manual or IMAP setup. Enter your full email address as the username and the app password as the password, for both incoming and outgoing mail.
Why name each password after a device?#
One password per client is the whole point of the feature. If your phone is lost, you delete the phone's password and your laptop keeps syncing. If you share one password across every device, revoking it cuts off all of them at once.
Zoho's two-factor authentication page also notes that app passwords never expire, even when your web password does. That is convenient, and it is also why naming matters. A password that never expires stays valid until someone deletes it, so a clear name is how you find the right one to remove a year from now.
How does setup differ by Zoho account type?#
The password step is identical for everyone. What changes is the server name your client needs, which depends on whether you have a personal address or an organization address on your own domain.

| Account type | IMAP server | SMTP server | Password to use |
|---|---|---|---|
| Personal (@zohomail.com) | imap.zoho.com, port 993, SSL | smtp.zoho.com, port 465 SSL or 587 TLS | App password if two-factor authentication is on |
| Organization (your own domain) | imappro.zoho.com, port 993, SSL | smtppro.zoho.com, port 465 SSL or 587 TLS | App password if two-factor authentication is on |
| Organization with SAML sign-in | imappro.zoho.com, port 993, SSL | smtppro.zoho.com, port 465 SSL or 587 TLS | App password, per Zoho's two-factor authentication page |
| New Free plan sign-up | Not available, per Zoho's IMAP page (September 2026) | Not applicable | Not applicable |
Do different email clients handle it differently?#
The rule is the same in every client: full email address as the username, app password as the password, and the servers from the table above. Where clients differ is how many places they ask for the password.
- Outlook and Apple Mail usually ask once and use the same credentials for sending. If sending fails but receiving works, check the outgoing server settings for a separate password field.
- Thunderbird and most Android mail apps keep incoming and outgoing credentials separate. Paste the app password into both.
- Any client that tries automatic setup may guess the wrong server for an organization account. Choose manual setup and enter the imappro and smtppro hosts yourself.
- Zoho's own help says the exact server details for your account type and data center are listed inside your account. If your account is hosted in a regional data center, use the hosts shown there rather than the defaults above.
Why does Zoho reject my password in Outlook?#
Almost always because Outlook is sending your normal Zoho password after two-factor authentication was turned on. Zoho's help article on Outlook and iPhone authentication errors names this as the cause and gives one fix: generate an application-specific password and use it instead.
If you are already using an app password and it still fails, work through the causes below in order. They are listed from most to least common in practice.
- IMAP is off. Check Settings, Mail Accounts, IMAP section in Zoho Mail. A new account or a recently changed plan may have it switched off.
- Wrong server for your account type. Organization addresses use imappro.zoho.com and smtppro.zoho.com. Personal addresses use imap.zoho.com and smtp.zoho.com.
- Username is not the full address. Zoho's SMTP help says the username must be the complete email address, matching the account or one of its aliases.
- Spaces or a typo in the password. Paste it rather than retyping it. If in doubt, delete it and generate a fresh one.
- Your admin blocked IMAP. On organization accounts, ask whoever manages Zoho whether an Access Restriction applies to you.
- The password was deleted. If someone cleaned up the App Passwords list, the client will fail with no other warning. Generate a new one.
Test with one client first
How do you revoke a Zoho app-specific password?#
Go back to accounts.zoho.com, open Security, then App Passwords. Find the entry by the name you gave it and delete it. Zoho's two-factor authentication page says you can delete one whenever you no longer use that device or application, or whenever you want to cut off its access.
The client using that password stops syncing at its next sign-in attempt. Your web password, your other app passwords and your other devices are not affected. On organization accounts, Zoho's help says admins can also revoke a user's app passwords from the two-factor authentication settings, which is the step to take when a staff member leaves.
A good habit is to review the list whenever you replace a phone or laptop. Because app passwords never expire, an old entry for a device you sold two years ago is still a working credential until it is removed.
Is there a faster way to run a Zoho inbox once it is connected?#
The steps above get your mail into a client. What they do not do is sort it, draft replies or chase the threads that stall. That work starts after the password and repeats every day.
We build AI Emaily, an email client that connects to Zoho Mail through its IMAP tab using exactly the app password you just generated. It envelope-encrypts that password at rest and decrypts it only inside an isolated sync worker, and it tests the connection before saving. Once connected, it triages incoming mail and drafts replies from the Personal Context you set, and in Copilot mode nothing is sent until you approve it, with undo and an audit log for every action. It does not replace Zoho's own admin console, filters or calendar. It is the triage and drafting layer on top of the mailbox you already have.
Frequently asked
See it in AI Emaily
Keep reading
Sources
- Zoho Mail Help: IMAP access and configuration
- Zoho Mail Help: Two-factor authentication and application-specific passwords
- Zoho Mail Help: SMTP configuration
- Zoho Accounts Help: Securing your Zoho account
- Zoho Mail Help: Authentication error during Outlook or iPhone IMAP setup
- Zoho Mail Help: Email policy access restrictions

Written by
Nafiul HasanNafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.