Skip to content
All providers

Move your email from mailbox.org to FranklyMail

Straightforward unless you use their inbox encryption. Nothing needs enabling, and your normal password works until you turn on two-factor — at which point you need an email app password, which can be scoped to IMAP alone.

Which password mailbox.org wants

Your normal password, unless two-factor authentication is on — mailbox.org says outright that once 2FA is enabled, mail programs can no longer use it. Then you need an "E-Mail-App-Passwort", which is a separate thing from their general application password and is the one that works for mail.

Getting it, step by step.

Written against mailbox.org's current screens — the words in quotes are the words on the buttons.

If you would rather skip the menus: https://office.mailbox.org/ opens the right screen directly, in whatever language your account is set to.

  1. 1

    If two-factor is off, use your normal password — there is nothing to fetch and nothing to enable. IMAP is on by default.

  2. 2

    Otherwise open the gear icon, then All settings → Security → Email app-passwords.

  3. 3

    Give it a name, choose IMAP among the permitted protocols, and generate it.

    You can restrict it to IMAP only, which is exactly what an import needs — it cannot send mail even if it leaks.

  4. 4

    Use imap.mailbox.org, port 993, your main address as the username, and that password.

What to put in the import form.

In the FranklyMail panel, open Mailboxes and find "Bring your old mail across".

imap.mailbox.org
IMAP server
imap.mailbox.org
Port
993 — TLS from the first byte.
Username
Your full address at mailbox.org, not just the part before the @.
Password
Password, or an app password with 2FA, from the steps above.

For the technically curious: on 24 August 2026 this server answered AUTH=PLAIN, AUTH=LOGIN, AUTH=OAUTHBEARER, AUTH=XOAUTH2 to a CAPABILITY command on port 993. That is what it accepts on the wire; which password it accepts from you is the separate question the section above answers.

What goes wrong with mailbox.org.

  • If you use mailbox.org’s inbox encryption, mail that arrived while it was on is stored as PGP ciphertext and comes across that way — readable only with your own key, which is the entire point of the feature. Mail received before you switched it on is unaffected, and the Sent folder is never encrypted.
  • Turning that encryption off does not decrypt what is already stored, and mailbox.org documents no way to bulk-decrypt it. Export your key pair from Guard before you move, and never deactivate Guard mid-migration — doing so deletes the keys held on their servers, and they state they cannot recover the plain text.
  • Aliases are not logins. They are internal forwards and sending addresses; sign in as your main address.
  • mailbox.org publishes no IMAP connection or rate limit. That does not mean there is none — it means nobody can tell you the number, so a very large mailbox may simply need patience.

Then the part that is the same for everyone.

Getting the password is the only step that differs by provider. The order of the move, what does and does not come across, and the one decision that stops you ending up with two copies of every message are on the main migration page.

How the move works

$9/yr, and your archive comes with you.

Unlimited mailboxes and aliases on your own domain, 10 GB pooled across the account, 30 days to change your mind.