·
Guides
iCloud
IMAP

iCloud app-specific password: how to create one, step by step (2026)

Apple never lets a third-party app sign in to iCloud Mail with your real password. Here is exactly how to generate an app-specific password at account.apple.com, the iCloud IMAP and SMTP settings to pair it with, and how to fix the sign-in errors when it does not work.

Trying to add your iCloud address to Thunderbird, Outlook, an email backup tool or an AI assistant, and your Apple password keeps getting rejected? That is not a bug. Apple blocks your real Apple Account password for every third-party app, on purpose. Anything that is not made by Apple must use an app-specific password: a 16-character password Apple generates for you, which only works for mail, contacts and calendar data, and which you can revoke at any time without touching your real password.

Before you start: two requirements

  • Two-factor authentication must be on. Apple only offers app-specific passwords on accounts protected by two-factor authentication. Almost every Apple Account created in the last few years already has it; if yours does not, turn it on first (Settings → your name → Sign-In & Security on an iPhone or Mac).
  • iCloud Mail must be active. An app-specific password gets you through the door, but there has to be a mailbox behind it: check that Mail is enabled in your iCloud settings and that you can see your inbox at icloud.com/mail.

How to generate an iCloud app-specific password

  1. Go to account.apple.com in any browser and sign in with your Apple Account. (This is the successor of appleid.apple.com — old links redirect.) You will confirm with a two-factor prompt on one of your devices.
  2. Open the Sign-In and Security section.
  3. Choose App-Specific Passwords.
  4. Click the + (or “Generate an app-specific password”), and give it a name that tells you later which app holds it — “thunderbird laptop”, “anymailmcp”, “backup tool”.
  5. Re-enter your Apple Account password to confirm.
  6. Apple shows the new password once, in the form xxxx-xxxx-xxxx-xxxx. Copy it now and paste it straight into the app that needs it. You cannot look it up again later — if you lose it, you just revoke it and generate a new one.

There is no way to do this from the Settings app on an iPhone or from System Settings on a Mac — app-specific passwords are managed only on the account.apple.com website.

The settings to pair it with: iCloud IMAP and SMTP

The app-specific password replaces your password in any standard mail client. The rest of iCloud Mail's settings are the same for everyone:

  • Incoming (IMAP): imap.mail.me.com, port 993, SSL/TLS
  • Outgoing (SMTP): smtp.mail.me.com, port 587, STARTTLS
  • Username: your full address (@icloud.com, @me.com, @mac.com — or your custom domain if it is hosted on iCloud+)
  • Password: the app-specific password, dashes included
  • Calendar (CalDAV): caldav.icloud.com, same username and app-specific password

Good to know

  • You can hold up to 25 at once. Generate a separate one per app instead of reusing one everywhere: when you retire an app, you revoke its password and nothing else breaks.
  • Changing your Apple Account password revokes all of them. After a password change, every app signed in with an app-specific password stops working until you generate fresh ones. If iCloud mail suddenly fails everywhere at once, this is almost always why.
  • Revoking is instant and harmless. The App-Specific Passwords page lists every active one by the name you gave it; remove any of them and only that app loses access. Your Apple account itself is untouched.
  • It only unlocks data over open protocols — mail (IMAP/SMTP), calendars (CalDAV), contacts (CardDAV). It cannot be used to sign in to icloud.com, make purchases or change your account.

When the sign-in still fails

  • “Username or password incorrect” with your real password — expected, by design. Only an app-specific password works in third-party apps.
  • Rejected app-specific password — make sure you pasted all 19 characters including the dashes, with no trailing space. If it was generated before your last Apple Account password change, it is dead: generate a new one.
  • Login works but no mailbox is found — iCloud Mail was never activated for the account. Turn on Mail in iCloud settings on your iPhone or at icloud.com, pick your @icloud.com address, then retry.
  • Custom domain address fails — check the domain is fully set up under iCloud+ (all DNS records verified) and that the address shows up in iCloud Mail on the web. The IMAP servers and the app-specific password are the same as for @icloud.com addresses.
  • No “App-Specific Passwords” section — the account has no two-factor authentication yet. Enable it, sign out of account.apple.com and back in.

Why we wrote this

We run anymailmcp.com, a bridge that connects mailboxes to AI assistants like Claude and ChatGPT over MCP — and iCloud is a special case we handle every day. Apple offers no OAuth “Sign in with Apple” for mail data and no API, so no assistant will ever ship a native iCloud connector: an app-specific password over IMAP is the door, for us and for every mail app you have ever used.

If that is what brought you here, the flow takes about a minute: generate the app-specific password exactly as above, then connect your iCloud mailbox — the IMAP, SMTP and CalDAV settings are filled in automatically, we verify the login live against Apple's servers, and your assistant can read, search and (if you allow it) send from your iCloud address, and see your calendar. The details live on our iCloud provider page.

Ready to let your assistant into your inbox?

Get started, free