Skip to content
Migration

Bring your old mail with you.

FranklyMail copies your existing mailbox across for you. Give it your old server's hostname, username and password, and it walks every folder — keeping what was read, what was flagged, and the date each message actually arrived. It runs on our side, so you can close the tab.

This page is the honest version: which providers still permit it, which two have closed the door entirely, and the one ordering decision that separates a clean move from a mailbox with two of everything.

If you're on Microsoft 365, this won't work — and it isn't us.

Microsoft has removed password authentication from IMAP. Connecting to outlook.office365.com on port 993 returns LOGINDISABLED — the server declining a password before one is offered — alongside AUTH=XOAUTH2 as the only method left. App passwords went with it. Microsoft's own documentation states that Basic authentication is disabled in all tenants and that nobody, including their own support, can re-enable it.

No importer that asks you for a password can get past that, ours included, and any tool promising otherwise is describing a world that ended. The way across is Thunderbird, which signs in to Microsoft the way a browser does and then speaks ordinary IMAP to us — with one setting that matters more than the rest, because Thunderbird now prefers to set Microsoft accounts up over a protocol Microsoft begins switching off in October 2026.

The Microsoft 365 route, step by step

Google Workspace is a different case, and a much better one. It gets grouped with Microsoft in most write-ups, and that is wrong. Google withdrew plain-password IMAP from every account in March 2025, but app passwords are a separate mechanism and they came through it intact — the importer works with Workspace. Whether you can create one is up to your administrator, and there are four separate settings that can stand in the way.

They are listed, with the deep links an administrator needs, on the Google Workspace page. One of them fails silently — a perfectly valid app password refused because client access has been restricted to OAuth clients only — which is worth knowing before you spend an afternoon on the password itself.

The order to do it in.

Five steps, and the third one is deliberately not where other guides put it.

  1. 1

    Add your domain and publish its DNS records

    Add the domain in the panel and publish the MX, SPF, DKIM and DMARC records it gives you. Leave your old provider running — nothing has moved yet, and mail keeps arriving where it always did until the MX record actually changes.

    Publish everything except the MX change if your registrar lets you stage it. SPF and DKIM can be live for days before the switch without affecting your old mail.

  2. 2

    Create the mailbox that will receive the archive

    Make the mailbox at the same address it had on the old provider. The import copies into a mailbox that already exists — it does not create one, and it does not care whether the address matches, but you will.

    A domain has to be verified before it will take a mailbox. If the button refuses you, the DNS records have not landed yet.

  3. 3

    Write down your old server’s address, then switch the MX record over

    Copy the incoming server name out of your old provider first and keep it somewhere. Then change the MX record at your registrar to ours. From that moment new mail arrives at FranklyMail and your old mailbox stops growing. Most registrars propagate within an hour; the outer bound is 48.

    The order inside this step matters as much as the step itself. If your old mail lives on web hosting, its server is usually mail.yourdomain.com — a record in the DNS zone you are about to move. Once it moves, that name stops resolving and the import cannot find a mailbox that is sitting right there, full. Use the server’s own hostname instead, the one your control panel prints under its SSL settings.

  4. 4

    Run the import against the old mailbox

    In the panel, open Mailboxes and fill in the old server's hostname, port, username and password. The job starts within about two minutes and the progress line tells you which folder it is on. A large archive takes hours; you can close the tab.

    Run it once. The importer keeps no record of what it already copied, so a second run against the same mailbox duplicates everything it copied the first time.

  5. 5

    Check it, then close the old account

    Open the mailbox and look at the folder list and the message counts. When you are satisfied, cancel the old provider — not before. Keeping it for a month costs one more month and removes every reason to hurry.

    IMAP moves mail and nothing else. Export contacts and calendars from the old provider separately, before the account closes, or they go with it.

Why the MX record moves before the import, not after

The standard advice is to copy the mail first, switch the MX record second, then run a second pass to sweep up whatever arrived in between. That assumes an importer you can run twice. Ours keeps no record of what it already sent, so a second pass copies everything a second time — and duplicates in someone's mail are not undone by trying again.

Moving the MX record first removes the problem rather than managing it. New mail starts arriving here, the old mailbox stops changing, and the import then runs once against something standing still. What it costs you is an hour or two where the new mailbox has your new mail but not yet your archive. That is a smaller thing to live with, and it is why we would rather tell you the order than ship a deduplicator that would be wrong in its own quieter way.

What comes across, and what doesn't.

Copied

  • Every folder, under the name it had. A slash in a folder name becomes a hyphen, because a slash means something else in a mail client.
  • Read and unread, exactly as they were.
  • Flagged and starred messages, as flagged.
  • The original date each message arrived, so your archive sorts the way it always did rather than all landing today.
  • Attachments, headers and the raw message, byte for byte. Nothing is re-encoded.

Left behind

  • Trash, Spam, Junk and Deleted Items. They are the old server’s bookkeeping and you did not ask to carry them.
  • Gmail’s All Mail, Starred and Important. These are not folders — they are the same messages a second and third time, and copying them is how a migration turns 4,000 messages into 16,000.
  • Single messages larger than 50 MB. They are skipped and counted, and the count is shown; the rest of the folder still arrives.
  • Contacts and calendars. IMAP carries mail and has never carried anything else — export those from the old provider yourself.
  • Filters, rules, signatures and vacation responders. Those are settings, not mail, and every provider stores them differently.

About handing us your old password.

You should be uneasy about this. It is somebody else's credential, it belongs to a company with no relationship to us, and an import that runs for an hour cannot hold it in a browser tab — it has to be written down somewhere. So here is exactly what happens to it.

  • It is encrypted before it is stored, with a key that does not live in the database.
  • No part of the panel will return it. The route that reports progress does not read the column, and a test greps the whole API to keep it that way.
  • It is erased the moment the job stops — finished, failed or cancelled — in the same database statement that records the outcome.
  • A constraint in the database refuses to record a finished job that still carries one, so this cannot be forgotten in a later edit.
  • It travels over TLS to your old server and nowhere else. Port 993 is encrypted from the first byte; anything else is upgraded before a password is sent, and there is no unencrypted path at all.

If your old provider offers app passwords, use one rather than your real password: it is scoped to mail, it can be revoked on its own, and you can delete it the moment the import finishes. That is good advice for any migration tool, not only this one.

If the import stops.

The panel prints one of five sentences, and only these five — we would rather say something short and true than forward an error from another company's server with your username in it. Each one is here with what it usually means.

"That server rejected the username or password. Gmail, Yahoo, iCloud and Fastmail all need an app password here rather than your normal one."
Nine times out of ten this is exactly what it says: a normal account password where the provider wants an app password. Check the table above for which one yours issues. The other case is a username that needs to be the full address rather than the part before the @. Note that a rejected password often comes back within a second — a failure that fast is almost never a network problem.
"That server did not answer in time."
The host is right but nothing is listening, or a firewall is dropping us. Confirm the port — 993 is right for almost everything — and check whether the old provider requires you to switch IMAP on before it will answer at all. GMX and some Zoho plans do.
"We could not find that server."
A typo in the hostname, or a domain that has already stopped resolving because you cancelled the old account. Your old provider’s webmail settings page prints the exact hostname; imap. or mail. followed by the domain is the usual shape.
"That server refused the connection on that port."
Something answers at that hostname but not on that port. Try 993. We use implicit TLS on 993 and upgrade with STARTTLS on anything else; there is no unencrypted path, so a server that only offers plain IMAP on 143 will refuse us and should.
"The import stopped early. Nothing was changed at your old provider — try again, and tell us if it keeps happening."
The catch-all, shown when the failure does not match anything above. It deliberately does not name a suspect: it used to say “check the server address and port”, which sent at least one person round the same wrong password three times while the real answer was an app password. If you see this one, write to us — we log the underlying error and can read it.
"That server's TLS certificate could not be verified."
The old server is presenting an expired or self-signed certificate. This is common on small self-hosted boxes and on hosts where a certificate lapsed. It has to be fixed at that end; we will not skip the check, because doing so would mean handing your password to whoever answered.

Questions people actually ask.

Can I move my existing email to FranklyMail?
Yes, if your current provider allows IMAP access with a password. FranklyMail has a built-in importer: give it your old server's hostname, port, username and password, and it copies every folder across in the background, keeping read state, flags and original dates. It works with Gmail, Fastmail, Purelymail, iCloud, Yahoo, Zoho, Migadu, mailbox.org and any standard IMAP host. It cannot import from Microsoft 365 or Proton Mail.
How long does an email migration take?
Roughly an hour per 10,000 messages, though it varies more with the old server’s rate limiting than with anything on our side. A typical personal archive of a few thousand messages finishes in well under an hour. You do not have to keep the page open — the job runs on our servers and the progress line picks up where you left it.
Will I lose any email during the switch?
No, if you move the MX record before you start the import. New mail arrives at FranklyMail from the moment the record changes, and the archive on the old server stops changing, so the import copies a complete snapshot. Nothing is deleted from the old provider at any point — the import only reads.
How do I import from Google Workspace?
With an app password, once your administrator has enabled them. Google withdrew plain-password IMAP from every account on 14 March 2025, but app passwords are a separate mechanism and they still work — an administrator turns them on under Security → Authentication → 2-Step Verification in the Admin console (admin.google.com/ac/security/2sv goes straight there), the user switches on 2-Step Verification, and then generates one at myaccount.google.com/apppasswords. That 16-character password is what goes in the import form. If your administrator will not enable them, the Thunderbird route below works without any password at all, because Thunderbird signs in to Google the way a browser does.
Why can’t I import from Microsoft 365 or Outlook.com?
Because Microsoft turned password authentication off. Connecting to outlook.office365.com on port 993 returns LOGINDISABLED — the server declines a password before one is offered — and app passwords were withdrawn along with it. Microsoft's documentation states Basic authentication "is now disabled in all tenants" and cannot be re-enabled by anyone. The way across is a desktop client that speaks OAuth: add both accounts to Thunderbird and drag the folders over.
Do you keep my old email password?
No. It is encrypted before it is written down, it is never returned by any part of the panel, and it is erased the moment the job stops — success or failure, in the same database statement that marks the job finished. A rule in the database refuses to record a finished job that still carries one.
Can I run the import again if it fails?
Yes, but not into the same mailbox. A failed job stops where it got to and tells you how far it reached; it keeps no record of which messages it already sent, so running it again copies those a second time. If a job fails part-way, delete the mailbox, make it again, and start over — or move the remainder by hand from a mail client.
Does the import move my contacts and calendar?
No. IMAP is a protocol for mail and carries nothing else, which is true of every IMAP-based migration and not a FranklyMail limitation. Export contacts as vCard or CSV and calendars as ICS from your old provider before you close the account.
Is there a size limit?
No limit on the mailbox. Individual messages over 50 MB are skipped and counted so you can see it happened. Storage is what you pay for: $9/yr includes 10 GB pooled across every mailbox on the account, and more is $0.40/GB/yr.

Your archive is the reason you never switched.

It is the thing that makes leaving feel expensive, which is exactly what it is for. Move it in an afternoon, keep the folders and the dates, and pay $9/yr a year for the mailbox it lands in.