App passwords: your mail app never gets your main password

Why every mail app gets a password of its own, how that password relates to your mailbox key and what it does not prevent.

At privymail.eu, every mail app gets a password of its own: generated by the service, meant for exactly one device and revocable on its own. Your main password is not stored in any mail app.

Mail protocols demand a secret. It need not be your most important one.

Thunderbird, Apple Mail and the mail app on your phone fetch and send mail over IMAP and SMTP; calendars and contacts use CalDAV and CardDAV. With all of these protocols, the app sends a secret to the server to sign in, protected by TLS, the encryption of the connection. That has two consequences: the app has to keep the secret on the device so that it can check for new mail without you. And the server gets to see it at every sign-in.

For your main password, both would be too much. More than access depends on it: it also protects the key with which your stored mail is encrypted. Sign-in in the browser therefore uses a method in which the main password does not leave your device; the post A password that never leaves your device explains it. Mail protocols cannot do that. Mail apps therefore get a different secret.

One password per device. Each revocable on its own.

An app password is a long, random password that you do not make up yourself; the service generates it. Its path has four steps:

  1. Create. An app password is created in the account settings, and only if you have just proved your main password and, where set up, your second factor, the additional proof alongside the password. It carries a label, such as "phone".
  2. See it once. The service shows the app password exactly once and never stores it in plain text. You enter it in the mail app.
  3. Use. The mail app signs in with it to IMAP, POP3 and SMTP, the protocols for fetching and sending. It does not know your main password.
  4. Revoke. If the device is lost, you delete exactly this entry. An ordinary sign-in is enough for that, without a fresh confirmation: taking access away must not fail at a hurdle.

There is more behind this than a second list of passwords. In the default mode, Compatible, privymail.eu stores your mail encrypted, with a separate key per account. For each app password, the account service stores a separate copy of the secret that opens this key, locked with the app password itself. When a mail app signs in, its app password opens exactly this copy. Revoking deletes it. The other copies stay untouched: that is why the laptop keeps working when you lock out the phone, and why app passwords remain valid when you change your main password.

Main passwordApp password
Who sets ityouthe service, at random
Where it is keptonly with youin one mail app on one device
Does our server see it?noyes, every time the mail app signs in
What it is forsign-in in the browser and account settingsIMAP, POP3 and SMTP, plus calendars and contacts over CalDAV and CardDAV
Second factorrequired in addition, if set upno

What it costs

  • One entry per device. Every mail app needs an app password of its own, and the list needs tidying when a device goes.
  • No second look. What the service shows only once it cannot show again. If an app password is mislaid, the only remedy is to revoke it and create a new one.
  • A hurdle when creating one. Merely being signed in is not enough. Anyone who only steals the session cookie, the token that marks your sign-in in the browser, cannot use it to create an app password.

What it does not solve

  • It bypasses the second factor. Mail protocols have no second step. Whoever holds an app password can read the mailbox and send in your name, without a one-time code. The protection consists of the long random value, individual revocation and the hurdle when creating one.
  • It stays until it is revoked. An app password remains valid when you change your main password. Anyone who phishes the password and the second factor and uses them to create an app password keeps access to the mailbox until someone deletes the entry. An unknown entry in the list is a warning sign.
  • It brings nothing back. Mail that a lost device has already downloaded stays there. Revoking only blocks further access.
  • It hides nothing from the server. The app password goes to the server every time the mail app signs in. In Compatible mode, the server also processes plain text temporarily, for example while the app is signed in.

Access with mail apps over IMAP and SMTP is part of all paid plans.

Further reading