Skip to content
OmniLeadDocs
Sign in

Fix a mailbox that won't connect

What each Test connection error means and how to fix it, including app passwords for Gmail and Microsoft accounts.

5 min readLast updated

When you connect a mailbox, Test connection runs three checks: it signs in to your SMTP server, sends a test email to the mailbox itself, and signs in to IMAP to read replies. If a check fails, the message under it says what went wrong. Find that error below for the fix.

Mailbox settings with the Test connection results

Before you start

Check the basics. Most connection problems come from one of these:

ProviderSMTP serverSMTP portIMAP serverIMAP port
Gmail and Google Workspacesmtp.gmail.com465 (TLS) or 587 (STARTTLS)imap.gmail.com993
Microsoft 365 and Outlook.comsmtp.office365.com587 (STARTTLS)outlook.office365.com993
Zoho Mailsmtp.zoho.com465 or 587imap.zoho.com993
Fastmailsmtp.fastmail.com465imap.fastmail.com993
Other providersSee your provider's help page for "IMAP and SMTP settings"465 or 587993
  • The username is usually your full email address.
  • The From address must be one the username is allowed to send as.
  • OmniLead can't use port 25. Use 465 or 587.

SMTP auth failed

What you see: "That SMTP password didn't work" or "Authentication failed".

The server rejected the username or password. The most common cause is using your normal account password when the provider requires an app password: a separate password made for one app.

  1. Check the username

    Use the full email address, for example sam@yourcompany.com.

  2. Create an app password

    Follow the steps for your provider below, then paste the app password into SMTP password and IMAP password.

  3. Test again

    Click Test connection.

Gmail app password

Google requires an app password for SMTP and IMAP when 2-Step Verification is on, and 2-Step Verification is required to create one.

  1. Turn on 2-Step Verification

    Open your Google Account at myaccount.google.com, go to Security, and turn on 2-Step Verification if it's off.

  2. Open app passwords

    Go to myaccount.google.com/apppasswords. If the page says the setting isn't available, see the note below.

  3. Create the password

    Type a name such as "OmniLead" and click Create.

  4. Copy it into OmniLead

    Copy the 16-character password (spaces don't matter) into SMTP password and IMAP password, then click Test connection.

Also check that IMAP is on: in Gmail, open Settings → See all settings → Forwarding and POP/IMAP and make sure IMAP access is enabled.

Outlook, Microsoft 365 and Outlook.com

Microsoft has been retiring password (Basic) sign-in for IMAP and SMTP across Microsoft 365 and Outlook.com in favour of Microsoft sign-in (OAuth).

  • Microsoft 365 work accounts: your admin must enable Authenticated SMTP for the mailbox in the Microsoft 365 admin center (Users → Active users → the user → Mail → Manage email apps). If your organisation still allows password sign-in, create an app password at mysignins.microsoft.com/security-info (Add sign-in method → App password) and use it for SMTP and IMAP.
  • When password sign-in is switched off for your tenant or your Outlook.com account, an app password won't work however it's set up. Use Connect with Microsoft in Settings → Mailboxes if your workspace has it. If it doesn't yet, contact support and we'll tell you when it's available for you.

IMAP login failed

What you see: "That IMAP password didn't work", or the Read replies over IMAP check fails while SMTP passes.

Without IMAP, OmniLead can send but can't see replies, so sequences won't stop when someone answers. Fix it before you launch.

  • Same password as SMTP? Most providers use the same app password for both. Paste it into IMAP password too.
  • IMAP turned off? Gmail, Zoho and some hosts let you disable IMAP. Turn it on in your mail settings.
  • Different username? A few hosts use a different IMAP username. Check your provider's settings page.
  • Microsoft accounts: see Outlook, Microsoft 365 and Outlook.com above.

TLS

What you see: "The secure connection to … failed", or messages mentioning "wrong version number", "certificate" or "self-signed".

OmniLead always connects with TLS 1.2 or later. This error usually means the port and the security mode don't match:

  • Port 465 starts TLS immediately. Choose SSL/TLS in the security setting.
  • Port 587 starts in plain text and upgrades with STARTTLS. Choose STARTTLS.
  • Port 993 (IMAP) uses TLS immediately.

If the error mentions a certificate, the server's certificate may have expired or not match the host name. Use the host name your provider publishes (for example mail.yourhost.com rather than an IP address), and ask your host to renew the certificate if it has expired. OmniLead doesn't connect to servers with invalid certificates, because that would expose your password.

Port blocked

What you see: "… didn't answer on port …", a timeout, or "connection refused".

OmniLead couldn't open a connection to your server on that port.

  • Wrong port: use 465 or 587 for SMTP and 993 for IMAP. Port 25 isn't supported.
  • Wrong host: a typo in the host name shows as "We couldn't find the server". Copy it from your provider's settings page.
  • Firewall on your server: self-hosted and some business mail servers only accept connections from known networks. OmniLead connects from cloud infrastructure with changing addresses, so the server needs to accept authenticated connections from the internet on 465 or 587 and 993.
  • Provider outage: check your provider's status page and try again later.

Other errors

  • "The server refused to send from this address": the username isn't allowed to send as the From address. Use the address that matches the login, or give the login "send as" permission for the alias.
  • "The provider is rate-limiting this mailbox": you've hit your provider's sending limit. Wait an hour and test again, and lower the mailbox's Daily cap.
Does the test email count toward my daily cap?

No. It goes to the mailbox itself and is marked as automatic. You can delete it.

The test passed but sequences don't send. Why?

Check the mailbox's sending window and timezone, its daily cap and ramp-up, and the sequence's pre-launch checklist. A sequence also pauses automatically if its bounce rate reaches 5%.

Is my password safe?

Mailbox passwords are encrypted with AES-256-GCM before they're stored and are never shown again. See How OmniLead keeps your data secure.

What's next