RE:NODE

App hosting11 min read

IMAP vs POP3 vs JMAP: mail access protocols compared

How IMAP, POP3 and JMAP differ: sync model, push, ports, client support and battery use, and which ones to enable on your own mail server.

0 readers

Use IMAP. It keeps mail on the server and in sync across every device, every mail client supports it, and on port 993 it is encrypted from the first byte. JMAP is the modern replacement - JSON over HTTPS, efficient sync, proper push - and it is excellent where a client supports it, but most mainstream clients still do not. POP3 downloads mail to one device and is only worth enabling for a specific legacy device that cannot do anything else. On your own server, that translates to: enable IMAPS on 993 and a submission port for sending, add JMAP over HTTPS if you have clients that use it, and leave POP3 and plain-text ports off.

None of these protocols sends mail. Sending is always SMTP submission on 587 or 465 - except in JMAP, which folds sending into the same API. That distinction catches people configuring clients, so it comes up again below.

The three protocols at a glance#

POP3IMAPJMAP
StandardRFC 1939 (1996)RFC 9051 IMAP4rev2 (2021); RFC 3501 rev1RFC 8620 core, RFC 8621 mail (2019)
TransportText over TCPText over TCPJSON over HTTPS
Ports110 STARTTLS, 995 TLS143 STARTTLS, 993 TLS443
Mail livesOn the deviceOn the serverOn the server
FoldersInbox onlyYesYes (mailboxes)
Multiple devicesPoorlyYesYes
PushNoIDLE, one folder per connectionPush for all changes
SendingNo - use SMTPNo - use SMTPBuilt in
Client supportUniversalUniversalLimited

POP3: download and (usually) delete#

POP3 - Post Office Protocol version 3 - treats the server as a holding area. The client connects, lists the messages waiting, downloads them, and by default deletes them from the server. The mail then lives on that one device.

a POP3 session, abbreviated
+OK POP3 readyUSER anna@example.com+OKPASS ********+OK 3 messagesRETR 1+OK message follows...DELE 1+OKQUIT

That model made sense when people had one computer and the server had little disk. It fails in every way that matters now: read a message on your phone and it is gone from the laptop; folders do not exist, so filing on one device means nothing elsewhere; and when the device dies, the mail dies with it unless someone backed it up.

Clients offer "leave a copy on the server", which helps a little. They track which messages they have already fetched using UIDL (unique IDs), so two devices can both download everything. But read status, deletions and folders still do not sync, and mailboxes on the server grow forever unless one client is set to delete after a number of days.

When POP3 still makes sense: an old device or application that can only fetch, such as a ticketing system that imports mail from a mailbox, or a user who genuinely wants all mail on one machine and none on the server. That is about it.

IMAP: the server holds the truth#

IMAP - Internet Message Access Protocol - keeps all mail and folders on the server, and the client shows a view of it. Read a message on your phone and it is marked read on your laptop. File it in a folder and it is filed everywhere. Lose the phone, and nothing is lost.

What makes IMAP work in practice:

  • Folders and flags on the server. Seen, answered, flagged, deleted, and custom keywords, all stored per message.
  • Partial fetches. A client can download headers and structure first, then the body or a single attachment only when opened. That is what makes large mailboxes usable on a phone.
  • Server-side search. SEARCH runs on the server, so a client can find a message in a 10 GB mailbox without downloading it.
  • IDLE (RFC 2177). The client tells the server "notify me of changes" and keeps the connection open; new mail appears within seconds. The catch is that IDLE watches one folder per connection, so a client that wants instant updates on five folders needs five connections.
  • Efficient resync with the CONDSTORE and QRESYNC extensions (RFC 7162). A client that reconnects can ask "what changed since modification sequence N" instead of re-listing every message. Without them, opening a large folder after a day offline means re-checking every message's flags.

IMAP's weakness is that it is a chatty, stateful text protocol designed in the 1980s and extended ever since. Each client must hold a long-lived connection per folder it watches, parse a complicated grammar, and handle a long list of optional extensions that servers support unevenly. On a phone, keeping connections open drains battery, which is why mobile clients often poll instead of using IDLE. Apple's Mail app on iPhone, for example, offers push for some account types but fetches IMAP accounts on a schedule.

Use port 993 (implicit TLS). Port 143 with STARTTLS is acceptable only if the server refuses to accept a login before TLS is negotiated; RFC 8314 recommends implicit TLS for exactly the reason that there is no plaintext phase to attack.

JMAP: mail as a modern API#

JMAP - the JSON Meta Application Protocol - was designed at Fastmail and standardised by the IETF in 2019 to replace IMAP's problems with a modern design. It is JSON requests over HTTPS:

a JMAP request: list the 10 newest messages in the inbox
{  "using": ["urn:ietf:params:jmap:core", "urn:ietf:params:jmap:mail"],  "methodCalls": [    ["Email/query", {      "accountId": "a1",      "filter": { "inMailbox": "inbox-id" },      "sort": [{ "property": "receivedAt", "isAscending": false }],      "limit": 10    }, "q"],    ["Email/get", {      "accountId": "a1",      "#ids": { "resultOf": "q", "name": "Email/query", "path": "/ids" },      "properties": ["subject", "from", "receivedAt", "preview"]    }, "g"]  ]}

Two calls in one request: the second uses the result of the first through a back-reference (#ids), so a client gets the list and the details in one round trip. That batching is a large part of why JMAP is fast on slow mobile connections.

The other design points:

  • State strings for sync. Every object type has a state. A client asks "what changed since state X" and gets exactly the created, updated and destroyed IDs. No re-listing, no per-folder connections.
  • Push for everything. One connection - EventSource over HTTP, or WebSocket (RFC 8887) - notifies the client of changes across all mailboxes. Battery-friendly and instant.
  • Sending built in. EmailSubmission sends mail through the same API and the same authentication. A JMAP client needs no separate SMTP settings.
  • Discovery. Clients find the API at https://<host>/.well-known/jmap, which returns the session object with the endpoints and capabilities.
  • Ordinary web infrastructure. It is HTTPS, so it goes through firewalls, proxies and load balancers that already handle web traffic, and it is easy to use from a browser or any programming language.

The limitation is clients. Most mainstream desktop and phone mail apps - Outlook, Apple Mail, the Gmail app - do not speak JMAP. It is used by Fastmail's own apps, some newer and open-source clients, web clients, and libraries for building your own tools. On the server side, Stalwart, Cyrus IMAP and Apache James implement it. If you are writing software that reads or files mail, JMAP is far nicer to program against than IMAP; if you are setting up phones for an office, IMAP is still what they will use.

What each means for your users#

read, plus SMTP 587/465read, plus SMTP 587/465read and sendfetch onlyPhonesIMAP 993Desktop clientsIMAP 993Web client or scriptsJMAP over 443Legacy importerPOP3 995 if neededYour mail serverone mailbox store
Which protocol each device or tool should use

All of these work against the same mailbox at once. A server like Stalwart stores mail once and serves it over every protocol you enable, so a user can read on a phone over IMAP while a script files messages over JMAP, and both see the same folders.

The client settings for the common case:

SettingValue
Incoming servermail.example.com, IMAP
Incoming port and security993, SSL/TLS
Outgoing servermail.example.com, SMTP
Outgoing port and security465 SSL/TLS, or 587 STARTTLS
UsernameThe account's login name (often the full address)
AuthenticationNormal password, or an app password

Email client setup for IMAP and SMTP walks through Thunderbird, Outlook, iOS and Android, including autoconfig so users do not have to type any of this.

What to enable on your own server#

Every open port is something exposed to the internet and to password-guessing bots. Enable what you use.

  • IMAPS on `993`: yes. Every client needs it.
  • Submission on `465` or `587`: yes, one of them, for sending. Both if you have clients that insist on one.
  • JMAP on `443`: yes if you use a JMAP client or want to build tools against the mailbox; it shares the HTTPS listener with the web admin on Stalwart.
  • IMAP on `143`: only if a client cannot do implicit TLS, and only with STARTTLS required before login.
  • POP3 on `995`: only for a named device that needs it. Never 110 without TLS.
  • ManageSieve on `4190`: only if users edit filter rules from a client that uses it.

On a RE:NODE Mail Server plan there are five ports to allocate, so this choice is concrete: IMAPS, a submission port and HTTPS cover almost everyone, leaving room for one or two of the extras. Port 25 for receiving mail from the internet is a separate matter that support sets up on request. Stalwart mail server setup covers the listener side, and port 25 and outbound mail blocks explains why 25 is different.

Logins, passwords and security across protocols#

All three protocols carry a username and password, and all three are targets. Password-guessing bots sweep the internet's IMAP, POP3 and submission ports around the clock, and an account that falls to one of them is used to send spam within hours. The protocol choice matters less than how logins are protected.

  • Encrypt every connection. Implicit TLS on 993, 995 and 465, or STARTTLS enforced before authentication on the others. A server that accepts a password in plain text on 143 or 110 hands it to anyone on the path.
  • Use app passwords per device where the server supports them. A phone, a laptop and a tablet each get their own password, so a lost device means revoking one credential, not changing the user's main password everywhere.
  • Turn off what you do not use. A disabled POP3 listener cannot be brute-forced. This is the strongest argument for leaving POP3 off by default.
  • Watch the authentication failures in the server's logs. A steady stream from many addresses against one account is a guessing attack; consider whether that account's password is strong enough to ignore it.
  • OAuth is how the large providers now prefer clients to sign in, and some self-hosted servers support it for IMAP and SMTP too, through the XOAUTH2 and OAUTHBEARER mechanisms. Client support for OAuth against a self-hosted server is patchy, so plain passwords over TLS remain the common case.

JMAP has a small advantage here: it runs over HTTPS with the same authentication options as any web API, so the tooling for tokens and rate limiting that already protects web services applies directly.

Moving users from POP3 to IMAP#

If you inherit users on POP3 - common after years on an old host - moving them to IMAP is worth the effort, but it has to be done carefully, because their mail may exist only on their computers.

  1. Find out where each user's mail lives. If their client deleted from the server after download, the only copy is local. If it left mail on the server, the server copy may be complete, partial or years old.
  2. Add the IMAP account alongside the POP3 one in the same client, pointing at the same mailbox. Do not remove the POP3 account yet.
  3. Drag the local folders into the IMAP account. The client uploads them to the server, which can take hours for a large mailbox. Check the counts on the server side afterwards.
  4. Set up the other devices with IMAP only.
  5. Remove the POP3 account once the upload is confirmed, keeping a local backup of the old data file for a while.

For whole-server moves between providers, copying server-side over IMAP with a tool such as imapsync is faster and more reliable - migrating email to your own server covers it.

Common problems with each#

  • POP3 "ate" the mail. A client set to delete after download emptied the server; the other devices see nothing. Turn on "leave on server", or better, switch to IMAP.
  • IMAP folders missing on one device. The folders exist but are not subscribed in that client. Look for a "subscribe" or "manage folders" option.
  • Sent mail appears twice, or not at all. With IMAP, the client uploads a copy to the Sent folder after sending over SMTP. If the server also saves sent mail, you get duplicates; if the client's Sent folder setting points at a local folder, the server never sees it. Set the client's sent folder to the server's Sent.
  • New mail is slow on the phone. The client is polling rather than using IDLE, often to save battery. Check the fetch interval, or use a client with push.
  • "Cannot connect" on 993 but 143 works. A firewall or the port is not exposed. Check the port mapping before the certificate.
  • Certificate warnings. The client connects to a name that is not on the server's certificate, such as the bare IP. Use the host name.

FAQ#

Is POP3 more private because mail is removed from the server?

Only if the client deletes after download and nothing else keeps a copy - and then your mail exists on one device that is probably not backed up. For privacy, encrypt the connection and secure the server; do not rely on deletion.

Can I use IMAP and POP3 on the same mailbox?

Yes, if the server allows it, but a POP3 client that deletes after download will remove mail from the IMAP view too. If you must mix them, set the POP3 client to leave mail on the server.

Does JMAP replace SMTP?

For clients, yes - JMAP clients send through the API. Between servers, no. Mail still travels from your server to other organisations over SMTP on port 25.

Why does my phone not support JMAP?

Most phone mail apps were built around IMAP and Exchange, and have not added JMAP. Use IMAP on phones; JMAP's advantages show most in web clients and in software you build yourself.

Which port should I use for IMAP?

993 with SSL/TLS. Use 143 only with STARTTLS required, and only if a client cannot use implicit TLS.


Comments

Completely anonymous: no account, no email, no cookie. We store the name you type, the text and the time - nothing else. Links are limited and markup is not rendered.

0/2000