Getting business email onto the devices your team actually carries takes about ten minutes per device, provided you do things in the right order. Do them in the wrong order and you'll spend an afternoon guessing at hostnames and wondering why sending fails while receiving works.
This guide covers iPhone, Android, and Outlook, explains which protocol to choose, and ends with the security steps that stop a lost phone from becoming a data breach.
TL;DR
iPhone: Settings → Apps → Mail → Mail Accounts → Add Account → Other → Add Mail Account, then choose IMAP.
Android: Gmail app → profile picture → Add another account → Other → enter address → Personal (IMAP).
Outlook desktop: File → Add Account → enter your address and let it configure, or choose manual IMAP setup.
Typical settings: IMAP on port 993 (SSL/TLS), SMTP on port 587 (STARTTLS), username = your full email address.
Get your hostnames from your provider, not from a template, and turn on 2FA before adding mail to any phone.
What You Need Before Starting
Your full email address, such as sarah@yourcompany.com.
The right password. If two-factor authentication is on, most mail apps need an app-specific password rather than your normal one.
Your provider's incoming server hostname and port.
Your provider's outgoing (SMTP) hostname and port.
Your admin's contact, in case your organization requires device approval.
One important correction to advice you'll see elsewhere: your mail server hostname is usually your provider's domain, not yours. Guides that tell you to enter imap.yourdomain.com assume your provider set up that hostname for your domain, which many don't. Get the exact hostnames from your provider's setup documentation or admin console, since a typo or a wrong assumption here is the single most common reason setup fails.
Finally, do the setup on a network you trust. Some corporate and public Wi-Fi networks block ports 993 and 587, which makes a perfectly correct configuration fail.
Step 1: Verify the Account in Webmail First
Before touching a phone, sign in to your webmail in a browser. That confirms the password works, the account isn't locked, and the mailbox actually exists. If webmail fails, mobile setup will too, and you'll be troubleshooting the wrong layer.
While you're there:
Check whether IMAP access needs enabling. Some providers keep it off by default.
Note the server hostnames and ports from the settings or help page.
If 2FA is on, generate an app password for each device you'll configure.
Pro tip: Label each app password by device, like "iPhone – Sarah." If that phone is lost, you revoke one credential instead of resetting everything.
A caution worth knowing: an app password signs in with a password alone, which means it bypasses your second factor. Create only the ones you need, keep a list, and revoke them when a device is replaced. Our 2FA rollout guide explains why this matters.
Step 2: iPhone and iPad
If your company uses Microsoft 365 or Exchange, go to Settings → Apps → Mail → Mail Accounts → Add Account → Microsoft Exchange, enter your address, and sign in through the Microsoft page that appears. This option only works for Exchange-based accounts, so skip it otherwise.
For a standard IMAP provider:
Settings → Apps → Mail → Mail Accounts → Add Account → Other → Add Mail Account.
Enter your name, full email address, password (or app password), and a description like "Work."
On the next screen, make sure IMAP is selected.
Under Incoming Mail Server, enter your provider's incoming hostname, your username (usually the full email address), and the password.
Under Outgoing Mail Server, enter the SMTP hostname and the same credentials. iOS calls these "optional," but nearly every provider requires them.
Tap Save and let iOS verify.
If verification fails, open the account again and tap Advanced. Confirm SSL is on for incoming with the correct port, and check the outgoing server settings under SMTP → Primary Server. Wrong port and encryption pairings, and a blank outgoing username, cause most iPhone failures.
Pro tip: Menu paths shift slightly between iOS versions. If you don't see "Apps," look for Mail directly in the Settings list.
Step 3: Android
Android varies by manufacturer, but the Gmail app works everywhere:
Open Gmail → tap your profile picture → Add another account → Other.
Enter your full email address, tap Next, and choose Personal (IMAP).
Enter your password or app password.
Set the incoming server hostname, port 993, security type SSL/TLS.
Set the outgoing server hostname, port 587, security type STARTTLS, and leave "Require sign-in" enabled.
Choose a sync frequency. Every 15 minutes is a good balance for most people.
Samsung Email and other manufacturer apps use the same fields under different labels.
Pro tip: Push sync only works if your provider supports IMAP IDLE. If your battery drains noticeably, drop back to 15-minute polling; most people can't tell the difference.
Step 4: Outlook (Desktop and Mobile)
Classic Outlook for Windows and Outlook for Mac: go to File → Add Account, enter your address, and click Connect. If your provider publishes Autodiscover records, it configures itself. If not, choose manual setup and select IMAP, then enter the hostnames and ports. Under More Settings → Outgoing Server, tick "My outgoing server (SMTP) requires authentication," and confirm the ports on the Advanced tab.
New Outlook for Windows and Outlook on the web use a simplified flow: add the account, then enter IMAP and SMTP details when prompted. Note that the new Outlook has different support for some account types, so if one version refuses your account, try the other.
Outlook mobile: open the app, tap Add Account, enter your address, and authenticate. It supports Microsoft 365, Exchange, Gmail, Yahoo, and generic IMAP.
Pro tip: If Outlook loops asking for your password, clear the saved credential in Windows Credential Manager or macOS Keychain, then re-add the account. Stale cached credentials cause most re-auth loops.
Step 5: Test, Then Secure
Test both directions. Send from each device to an outside address, then reply from that address back to your business inbox. A one-way test only proves half the setup, and SMTP problems are the half people miss.
Then lock the device down:
Turn on two-factor authentication for the account if it isn't already.
Require a passcode or biometric unlock on the device itself.
If your organization uses mobile device management, enroll the device so it can be wiped remotely.
Write down which app passwords belong to which device.
Check folder sync. Sent, Drafts, and Archive should look the same everywhere. If sent mail only appears on one device, the client is saving to local folders instead of server ones; fix that in the account's advanced settings. If folders appear with an odd prefix like "INBOX.Sent," set the IMAP path prefix, which is usually blank or INBOX.
If a device is lost: revoke that device's app password, sign out all sessions, change the account password, and trigger a remote wipe if you have MDM. Doing this in minutes rather than days is the whole point of per-device credentials. See our business email security best practices.
Example: A 12-Person Design Agency
The following is an illustrative scenario.
An agency owner migrates her team off an old shared hosting mailbox. She starts by importing mail for each account over IMAP, then configures her own phone and laptop first so she knows exactly what her team will see.
She writes a one-page guide with screenshots showing the exact hostnames, ports, and where to get an app password, and sends it to everyone. Most of the team finishes in under twenty minutes. Three people need help: two mistyped the server hostname, and one hadn't generated an app password.
Within a day everyone is sending and receiving from their phones. The two things that saved the most time were testing the process herself first and putting the exact server details in writing, rather than telling people to "check the settings."
Which Protocol Should You Use?
Situation | Use | Why |
|---|---|---|
Most small businesses | IMAP + SMTP | Syncs across every device, works with any client, no vendor lock-in |
Microsoft 365 / Exchange organizations | Exchange (or Microsoft's own apps) | Mail, calendar, and contacts in one connection |
Teams that need shared calendars | Whatever your provider offers natively | Calendar sync doesn't come with plain IMAP |
One device, offline archive | POP3 | Rarely the right answer today |
IMAP is the default for business. Your mailbox lives on the server and every device mirrors it, so reading a message on your phone marks it read on your laptop.
POP3 downloads mail to one device and, depending on the settings, removes it from the server. That breaks multi-device access, which is why it's almost never right in 2026. Use it only for a deliberate offline archive.
Exchange ActiveSync carries mail, calendar, contacts, and tasks over HTTPS on port 443, which is why Exchange setups feel more complete out of the box. It's specific to Exchange-based platforms, though, so it isn't an option with most independent providers, which handle calendars through CalDAV or their own apps instead.
Calendar sync is worth checking before you commit to a provider; see how to choose a business email provider.
How the Settings Work
Email uses two separate protocols: one for receiving (IMAP or POP3) and one for sending (SMTP). They're independent, which is exactly why you can receive fine but fail to send.
Encryption and ports go together in fixed pairs:
IMAP: port 993 with SSL/TLS (implicit), or port 143 with STARTTLS.
SMTP: port 587 with STARTTLS, or port 465 with SSL/TLS.
Pairing 993 with STARTTLS, or 587 with implicit SSL, fails every time. Ports 143 and 25 without encryption are blocked almost everywhere now, and port 25 in particular is widely blocked for outbound mail from consumer connections.
SMTP almost always requires authentication. An unauthenticated outgoing server would be an open relay for spammers, which is why the "my outgoing server requires authentication" checkbox exists and why leaving it off causes silent send failures.
For more on how these protocols differ from API-based integrations, see IMAP vs SMTP vs API.
Common Mistakes
Using your normal password when 2FA is on. Most clients need an app password. This causes more failed setups than anything else.
Assuming the hostname matches your domain.
imap.yourcompany.comoften doesn't exist. Use your provider's documented hostname.Mismatching ports and encryption. 993 with SSL/TLS, 587 with STARTTLS. Don't mix them.
Leaving out the outgoing username and password. iOS marks them optional; your provider almost certainly doesn't.
Forgetting to enable IMAP in webmail when the provider disables it by default.
Never revoking app passwords. Old credentials for sold or lost phones keep working until someone removes them; add this to your offboarding checklist.
FAQ
What are the standard IMAP and SMTP settings for business email?
Typically IMAP on port 993 with SSL/TLS and SMTP on port 587 with STARTTLS, with your full email address as the username. The hostnames are specific to your provider, so take them from its documentation rather than assuming they match your domain.
Why won't my business email work on my iPhone?
Usually the password type (an app password is needed when 2FA is on), a wrong hostname, a port and encryption mismatch, or a blank outgoing server username. Check Advanced settings, and if all else fails delete and re-add the account.
Can I use the same business email on several devices?
Yes, with IMAP. Read status, folders, and sent mail stay in sync everywhere. Give each device its own app password if 2FA is enabled.
How do I fix "cannot connect to server" on Android?
Check hostname, port, and security type first, then test on cellular data. Some Wi-Fi networks block mail ports, which makes a correct configuration look broken.
Is it safe to put business email on a personal phone?
Yes, with a device passcode or biometric lock, 2FA on the account, a per-device app password you can revoke, and a way to wipe the device remotely if it's lost.
What's the difference between IMAP and Exchange?
IMAP syncs email only. Exchange ActiveSync syncs email, calendar, contacts, and tasks over one connection, but it's only available on Exchange-based platforms.
Should I ever use POP3?
Only for a deliberate single-device offline archive. It breaks multi-device sync.
How long does setup take?
A few minutes per device with the right details in hand. Most of the time people lose is spent hunting for hostnames and the correct password type, which is why Step 1 matters.
Business Email That's Simple to Set Up
NevTan Mail gives you secure, ad-free email on your own domain with a calendar and meetings built in, admin controls for your whole team, guided SPF/DKIM/DMARC setup, two-factor authentication with security key support, and up to 10 mailboxes free forever. Switching from another provider? You can import existing mail over IMAP with an app password, and there's a step-by-step Gmail migration guide.
For the exact server settings to enter on your devices, check the documentation or ask support.
