Practical guide to using Gmail as an IMAP client on your email software

Setting up Gmail with IMAP on a third-party email client involves more than just entering a server address and a port. The authentication method, label visibility, and restrictions imposed by a Google Workspace administrator can significantly alter the outcome. This guide compares server settings, details actual bottlenecks, and clarifies what distinguishes a functional setup from partial synchronization.

Gmail IMAP, POP, and SMTP Server Settings: Comparison Table

Before adjusting the settings of an email client, the technical data to be entered should be laid out side by side. Confusion between IMAP and POP remains common, even though their behaviors diverge on a structural point: synchronization.

Further reading : What to do if you have a connection problem with your MyFoncia client area? Tips and solutions

Protocol Server Port Encryption Synchronization
IMAP (incoming) imap.gmail.com 993 SSL/TLS Bidirectional
POP (incoming) pop.gmail.com 995 SSL/TLS Download only
SMTP (outgoing) smtp.gmail.com 465 (SSL) or 587 (TLS) SSL or STARTTLS

With IMAP, every action is reflected on all connected devices. Deleting a message in Thunderbird also deletes it in the Gmail web interface and on a phone. POP, on the other hand, downloads a local copy without returning to the server.

For those who want to use Gmail as an IMAP client on multiple computers or devices, IMAP is the only coherent choice. POP is only relevant for archiving messages on a single machine, without the need for synchronization.

Read also : Discover how to boost your career with an innovative online collaborative platform

Woman checking Gmail IMAP settings on a large screen in a coworking space

OAuth Authentication and Gmail App Passwords

Server configuration is not enough if authentication fails. Google now favors OAuth to connect a third-party email client. This protocol allows access to the account without transmitting the main password to the software.

Recent versions of Outlook, Apple Mail, and Samsung Mail natively handle OAuth. The client opens a Google login window, the user validates, and the software receives an access token. No password is stored in the client configuration.

When an Email Client Does Not Support OAuth

Some older or less common software does not offer OAuth. In this case, Google requires generating an app password from the account’s security settings. This one-time password replaces the usual password in the client’s authentication field.

  • Enable two-step verification on the Google account (mandatory prerequisite)
  • Access the “App passwords” section in the security settings
  • Generate a password dedicated to the specific email client, then paste it into the IMAP configuration

An OAuth-compatible client is still preferable. The app password is a fallback mechanism, not a target configuration.

Gmail Label Visibility in an IMAP Client

Once the account is connected, some folders may be missing in the email client. This issue does not stem from the client but from the label configuration on the Gmail side.

Gmail does not operate with folders in the traditional sense. It uses labels, and only labels marked “Show in IMAP” will appear in the client. The inbox, sent messages, trash, and “All Mail” must each be individually enabled.

Enabling IMAP Visibility for Labels

In the Gmail web interface, open Settings, then the Labels tab. Each system label (Inbox, Sent Messages, Drafts, Trash, Spam, All Mail) has an “Show in IMAP” option. Custom labels follow the same logic.

A label hidden in IMAP does not delete any messages. It simply becomes invisible to the third-party client. This step conditions the correspondence between Gmail and the software.

Man with glasses configuring an IMAP Gmail client from his modern kitchen

IMAP Restrictions in Google Workspace Environment

For a personal Gmail account, enabling IMAP is done directly in the account settings. In a Google Workspace environment, the situation changes. The organization’s administrator controls IMAP access from the admin console.

There are two levels of restriction. The administrator can allow any email client, or restrict access to only clients compatible with modern OAuth authentication. In this second case, software that does not handle OAuth will be blocked, even with a valid app password.

This restriction applies at the organizational unit level. One service may have open IMAP access while another is locked. Before diagnosing a connection issue on a business account, checking the IMAP policy applied by the administrator can prevent searching for a configuration error that does not exist.

Quick User Check

  • Open Gmail on the web and go to Settings, “Forwarding and POP/IMAP” tab
  • If the IMAP option is grayed out or missing, the administrator has disabled access
  • If the option is available, ensure that “Enable IMAP” is checked, then save

An IMAP connection refusal on a Workspace account, despite correct server settings, almost always points to an administrative restriction or a client not approved by the organization’s OAuth policy.

The IMAP configuration of Gmail relies on three distinct layers: server settings (identical for all), the authentication method (OAuth or app password depending on the client), and label visibility. Neglecting any of these layers results in incomplete synchronization or silent connection failure. On a Workspace account, the administrator’s policy constitutes a fourth lock to identify before any other manipulation.

Practical guide to using Gmail as an IMAP client on your email software