
IMAP vs POP3 comes down to where your mail lives. IMAP keeps messages on the server and syncs folders, read status and deletions across every device. POP3 downloads messages to one computer and usually removes them from the server. Reading mail on a phone and a laptop? Use IMAP; POP3 only fits a single machine with a local archive.
Where IMAP and POP3 fit in the email stack
Email is a chain of protocols rather than a single one. Sending and receiving are handled by different parts of it:
- SMTP sends. Your mail client hands a message to your provider on port 587 or 465, and the provider relays it to the recipient's server on port 25. The port details are covered in our guide to mail ports 25, 465, 587, 110, 143, 993 and 995.
- IMAP retrieves while leaving the mailbox on the server.
- POP3 retrieves by downloading, after which the client works on its own copy.
- Webmail is just HTTPS: when you read Gmail in a browser, neither IMAP nor POP3 is involved.
- Proprietary and newer protocols such as Exchange ActiveSync, EWS, MAPI and the open JMAP standard do the same job as IMAP, with narrower client support.
Neither IMAP nor POP3 can send anything. A client that receives fine but cannot send has an SMTP problem, not an incoming-server problem.
How IMAP works
IMAP, the Internet Message Access Protocol, gives a client remote access to a mailbox that stays on the server. The current specification is IMAP4rev2 in RFC 9051; IMAP4rev1 remains widely deployed. Your mail app is effectively a window onto the server, caching messages locally for speed and offline reading.
- Server-side folders. Inbox, Sent, Junk and your own folders are shared by every device.
- Flags. Message state is stored on the server as
\Seen,\Answered,\Flagged,\Deletedand\Draft, so a message you read on your phone is not bold on your laptop. - Partial fetches. A client can pull headers or the text part without attachments, which matters on a slow mobile connection.
- Server-side search.
SEARCHfinds messages that were never downloaded. - Push. The IDLE extension keeps a connection open so the server announces new mail instead of the client polling.
Deletion is a two-step affair: a message is marked \Deleted and only disappears on EXPUNGE. Most clients move messages to a Trash folder instead, which still counts against your quota.
How POP3 works
POP3, defined in RFC 1939, was designed for one computer on a dial-up line. The client logs in (USER/PASS), counts messages (STAT, LIST), downloads them (RETR) and marks them for deletion (DELE). Nothing is actually deleted until the client sends QUIT and the session enters the UPDATE state. A connection that drops before QUIT leaves everything in place, which is why flaky links produce duplicate downloads.
POP3 has no folders (it only sees the Inbox), no server-side read status, no shared Sent folder and no push. "Leave a copy on the server" works by remembering each message's unique ID from the UIDL command, so the client skips what it already has. That prevents duplicates, but two POP3 computers still end up with two independent histories.
IMAP vs POP3 compared
| Aspect | IMAP | POP3 |
|---|---|---|
| Where mail is stored | Server, with a local cache | Local disk; server copy optional |
| Multiple devices | Identical view everywhere | Each device diverges |
| Folders | All server folders | Inbox only |
| Read / flagged status | Synced | Local only |
| Sent items | Shared server folder | Only on the sending device |
| Offline access | Cached messages | Everything already downloaded |
| Server storage | Consumes quota | Freed when deleted from server |
| New mail | Instant via IDLE | On a polling interval |
| Plain / STARTTLS port | 143 | 110 |
| Implicit TLS port | 993 | 995 |
| Losing the device | Nothing lost | Mail gone unless backed up |
Which one should you use?
For almost everyone, IMAP. Most people check mail on at least two devices, and only IMAP keeps them consistent.
Choose IMAP when
- you read mail on a phone, a computer and the web;
- a team shares one mailbox, such as support@ or sales@;
- you rely on folders, server-side filters or rules;
- replacing a laptop should not mean losing years of correspondence.
POP3 still makes sense when
- there is exactly one workstation and policy requires a local archive;
- the hosting plan gives you a tiny mailbox that fills up fast;
- a system ingests mail and removes it, for example a helpdesk that turns messages into tickets;
- you need a one-off dump of the Inbox to disk.
If you do pick POP3, back up the mail client's profile folder. It will hold the only copy of your mail.
IMAP and POP3 ports: 143, 993, 110, 995
Each protocol has two ports. On 143 (IMAP) and 110 (POP3) the session starts in plaintext and upgrades with STARTTLS (STLS in POP3). On 993 and 995 TLS starts immediately, known as implicit TLS.
RFC 8314 recommends implicit TLS for mail access. With STARTTLS, an attacker on the network path can strip the server's offer to upgrade, and a careless client carries on unencrypted. On port 993 there is nothing to strip: without TLS the conversation never starts. In your client, pick "SSL/TLS", not "STARTTLS" and certainly not "None".
On your own server there is rarely a reason to expose 110 and 143 to the internet. To see which mail ports a Linux host listens on:
ss -tlnp | grep -E ':(110|143|993|995)\b'
On Dovecot, doveconf protocols lists the enabled protocols. If pop3 is there and nobody uses it, remove it and shrink your attack surface.
Server settings for common providers
| Provider | IMAP | POP3 | SMTP |
|---|---|---|---|
| Gmail | imap.gmail.com, 993 | pop.gmail.com, 995 | smtp.gmail.com, 465 or 587 |
| Outlook.com / Microsoft 365 | outlook.office365.com, 993 | outlook.office365.com, 995 | smtp.office365.com, 587 |
| Yahoo Mail | imap.mail.yahoo.com, 993 | pop.mail.yahoo.com, 995 | smtp.mail.yahoo.com, 465 or 587 |
| iCloud Mail | imap.mail.me.com, 993 | Not offered | smtp.mail.me.com, 587 |
The username is normally your full email address. For mail on a custom domain, your provider publishes its own hostnames, and some also publish SRV records under RFC 6186 (_imaps._tcp, _pop3s._tcp, _submission._tcp) that clients use for auto-discovery. Check one with dig SRV _imaps._tcp.example.com.
Enabling IMAP access and app passwords
Many providers keep third-party client access restricted, so a stolen password cannot simply be plugged into someone else's mail app. The usual sequence:
- In webmail settings, find the section for POP/IMAP or mail apps and confirm IMAP is allowed. In Gmail it is the "Forwarding and POP/IMAP" tab.
- Generate an app password in your account security settings. Providers that support app passwords typically require two-step verification to be on first.
- In the client, enter the IMAP host, port 993, SSL/TLS, your full address and the app password.
- Send yourself a test message to verify both incoming IMAP and outgoing SMTP at once.
An app password works for one app, cannot open the web interface or change account settings, and can be revoked without touching your main password. Microsoft has gone further: basic password authentication for IMAP and POP is switched off in Exchange Online, so you need a client that supports OAuth; see Microsoft's deprecation notice. Gmail likewise blocks sign-in from clients that use only a regular password.
Common IMAP and POP3 errors
- Authentication failed. Usually the main password was used where an app password is required, or the username lacks the domain. IMAP servers report this with response codes such as
[AUTHENTICATIONFAILED]or[AUTHORIZATIONFAILED]; Outlook shows 0x800CCC92 when a POP3 server rejects the login. - Protocol disabled for the mailbox. The password is right and login still fails: check the IMAP/POP setting in webmail.
- Port and encryption mismatch. Port 993 with "STARTTLS" or port 143 with "SSL/TLS" ends in a dropped connection or handshake error. Outlook typically reports 0x800CCC0E (cannot connect) or 0x800CCC0F (connection interrupted).
- Blocked port. A corporate firewall or an antivirus product that scans mail intercepts 993/995.
- Certificate name mismatch. Common with shared hosting: you connect to
mail.example.combut the certificate names the host's server. Use the hostname from your provider's documentation. - Full mailbox. With IMAP, Sent and Trash count against the quota; once it is full, new mail bounces.
If the client connects cleanly but mail never arrives, the problem is delivery (MX records, filtering, spam), and our checklist for missing email is the place to start.
How to test an IMAP or POP3 server
Work from the bottom up: port, then TLS, then login.
1. Is the port reachable?
Test-NetConnection -ComputerName imap.gmail.com -Port 993
In PowerShell, look for TcpTestSucceeded : True. On Linux or macOS, nc -vz imap.gmail.com 993 does the same. For your own server, the port scanner checks from the internet rather than from your network, so it shows what the hosting firewall is actually letting through.
2. Does TLS work, and which certificate is served?
openssl s_client -connect imap.gmail.com:993 -servername imap.gmail.com </dev/null 2>/dev/null | openssl x509 -noout -subject -dates
This prints the certificate subject and validity dates. For STARTTLS ports add -starttls imap (port 143) or -starttls pop3 (port 110).
3. Log in by hand
Open a session with openssl s_client -connect imap.gmail.com:993 -crlf -quiet, wait for the greeting, then type tagged IMAP commands:
a1 LOGIN you@gmail.com your-app-password
a2 LIST "" "*"
a3 SELECT INBOX
a4 SEARCH UNSEEN
a5 LOGOUT
For POP3 use port 995 with USER, PASS, STAT, LIST and QUIT; +OK means success and -ERR a refusal. The password is visible on screen, so do not do this while screen sharing.
4. Check the domain and outbound mail
Once incoming mail works, test the rest of the chain: the email domain check reports MX, SPF, DKIM and DMARC, and the SMTP test shows whether the sending server responds. For deeper SMTP troubleshooting, see how to test a mail server, and for the records that decide whether you land in the inbox, our SPF, DKIM and DMARC guide.
FAQ
Can I use IMAP and POP3 on the same mailbox?
You can, but it is risky: a POP3 client set to delete after download will make messages vanish from every IMAP device. If you need POP3 alongside IMAP, enable "leave a copy on the server".
What happens to my mail if I switch from POP3 to IMAP?
Only messages POP3 left on the server will appear. Anything downloaded and deleted stays in the old client; drag it from a local folder into an IMAP folder to upload it.
Is IMAP secure?
It is as secure as its transport. With TLS on port 993 and an app password or OAuth it is fine; on port 143 without STARTTLS, credentials travel in plaintext.
Why can't my POP3 client see the Junk folder?
POP3 only knows about the Inbox. Mail filed into Junk or other folders is invisible to it; use IMAP or webmail.
Should I use port 143 or 993 for IMAP?
993 with SSL/TLS. Port 143 exists for compatibility and is only acceptable with mandatory STARTTLS.
Does IMAP send email?
No. IMAP and POP3 only retrieve mail. Sending always uses SMTP, which is why a client asks for an incoming and an outgoing server.