Skip to main content
Overview

AI Email Sorting for Fastmail, Posteo, and Mailbox.org

September 6, 2026
5 min read

Diagram: connecting Fastmail, Posteo, and mailbox.org over IMAP

TL;DR. Fastmail, Posteo, and mailbox.org all speak standard IMAP/SMTP, and all three require an app-specific password rather than your normal login for third-party clients. Once you have that password, connecting AI Email Filter takes the same three fields on every provider: server, port, and app password.

Related reading: Private AI email sorting · Sender Smart Categories

Fastmail, Posteo, and mailbox.org are the three providers people switch to specifically because they don’t want their inbox mined for ad targeting. That same privacy stance means none of them expose a consumer OAuth flow the way Gmail does — you connect over plain IMAP, authenticated with an app-specific password. Here’s the exact setup for each, current as of September 2026.

Fastmail

IMAP: imap.fastmail.com, port 993, SSL/TLS SMTP: smtp.fastmail.com, port 465 (SSL/TLS) or 587 (STARTTLS)

Fastmail requires an app password for every third-party connection — your regular login password and your two-step verification code will not work over IMAP. To generate one:

  1. Log into the Fastmail web app.
  2. Go to Settings → Privacy & Security → Integrations.
  3. Click New App Password, confirm with your account password.
  4. Give it a name (e.g. “AI Email Filter”) and copy the generated password — it’s only shown once.

Use your full email address as the username and the app password (not your login password) when connecting AI Email Filter.

Posteo

IMAP: posteo.de, port 993 (SSL/TLS) or 143 (STARTTLS) SMTP: posteo.de, port 465 (SSL/TLS) or 587 (STARTTLS)

Posteo also only accepts app-specific passwords for IMAP/SMTP clients — this isn’t optional, and it applies even without two-factor authentication enabled. To create one:

  1. Log in at posteo.de.
  2. Go to Settings → My Account → Password & Security.
  3. Find the app password section and generate a new one (Posteo requires at least 16 characters, including one number and one uppercase letter — you can use its suggestion or type your own).
  4. Use this password for both the IMAP and SMTP connection, even if a field labels it optional.

Note that Posteo only accepts encrypted connections (TLS or STARTTLS) — plain, unencrypted IMAP is rejected outright, and older TLS 1.0/1.1 clients won’t connect either.

mailbox.org

IMAP: imap.mailbox.org, port 993, SSL/TLS SMTP: smtp.mailbox.org, port 465 (SSL/TLS) or 587 (STARTTLS)

If you haven’t enabled two-factor authentication on mailbox.org, your normal account password works directly over IMAP. If you have 2FA on (worth doing regardless), you need an application password instead:

  1. Log into mailbox.org webmail.
  2. Go to All Settings → Security → Application Passwords.
  3. Add a new password, label it (e.g. “AI Email Filter”), and generate it — copy it immediately, since it isn’t shown again.
  4. Tick IMAP and SMTP as the allowed protocols for that password.

Always use your main mailbox.org address as the username — an alias address will fail authentication even with a correct password.

Connecting to AI Email Filter

Once you have the right server details and an app password, the AI Email Filter side is identical across all three providers: add the account, enter the IMAP server and port, your email address as username, and the app password. AI Email Filter connects over IMAP/SMTP the same way any other mail client would — there’s no provider-specific integration required, because none of these three needed one.

Why this pairing makes sense

People who choose Fastmail, Posteo, or mailbox.org over Gmail have usually already decided that where their mail lives, and who reads it, matters. Sender Smart Categories fits that same instinct on the classification side: each sender is categorized once, that decision is cached, and every later email from the same address is sorted without a fresh classification call — see Sender Smart Categories for how the caching works. And if you want to take the privacy stance a step further, AI Email Filter’s Bring Your Own LLM setting lets you point classification at your own model instead of a hosted one, so mail content processed for sorting never has to leave infrastructure you control — see private AI email sorting for that combination in practice.

A note on app passwords in general

All three providers converge on the same security model: a scoped, revocable password per application, separate from your login credentials and independent of two-factor authentication on your main account. If you ever want to disconnect AI Email Filter, revoke that specific app password from your provider’s settings — it doesn’t touch your regular login, and no other connected app is affected.

If a connection fails, the first thing to check is whether you used the app password or your regular login password by mistake; that’s the most common setup error across all three providers, since the login prompt and the app-password prompt often look identical from the client side.

Troubleshooting a failed connection

A handful of other things are worth checking before assuming the account details are wrong:

  • Wrong port for the security type. Port 993 expects an SSL/TLS connection from the first byte; port 143 or 587 expects a plaintext connection that upgrades via STARTTLS. Mixing these up produces a generic “connection failed” error on all three providers rather than a clear message.
  • Username isn’t the full address. All three expect your complete email address as the IMAP username, not just the local part before the @. mailbox.org in particular will reject an alias address outright even with a correct app password, since the account owner has to be the primary address.
  • App password revoked or expired. If a connection worked before and suddenly stops, check whether the app password was revoked from the provider’s security settings — deleting an old device or app from that list also kills any client still using that password.
  • Firewall or VPN interference. Posteo in particular rejects unencrypted and legacy-TLS connections outright, so a corporate proxy that terminates and re-establishes TLS with an older configuration can break the handshake even when the credentials are correct.

Once the connection is live, it behaves like any other IMAP account in AI Email Filter — the provider-specific work is entirely in getting the server details and app password right up front.

Try AI Email Filtering

Define your own rules with natural language. Works with any email provider.

Connected Accounts

3 mailboxes
work@company.com
personal@gmail.com
team@startup.io

Your Filters

3 active

Personal

From people I know personally or have emailed before

Spam & Sales

Delete

Cold outreach, LinkedIn spam, or someone trying to sell me something

Favorite Shop Newsletter

Star

Deals and updates from the shops I actually buy from

Add new filter
Acme Project

AI Classification

Waiting for emails...

on your LLM or ours
Incoming emails will be sorted automatically