Email Client Setup (Outlook, Mobile)

Google Workspace Email Settings: Ports, Servers, SSL & Client Configuration Guide

By the Domain India teamPublished 10 min read
Knowledge base article
Contents (9 sections)

If your domain's email runs on Google Workspace, your mail app needs Google's server names, ports and sign-in method. This guide lists Google's current settings for IMAP, POP and SMTP, explains how sign-in works now that plain passwords are no longer accepted, and shows how to set up common mail apps, printers and scripts.

This guide is for Google Workspace only

Domain India does not sell Google Workspace; you buy it from Google. These settings do not apply to Domain India Business Email or to the email included with your hosting. See Business Email vs the email included with your hosting.

Key takeaways

Incoming mail: imap.gmail.com, port 993, SSL/TLS (or pop.gmail.com, port 995). Outgoing mail: smtp.gmail.com, port 587 with STARTTLS or port 465 with SSL/TLS. The username is your full email address. Sign in with Google (OAuth) wherever your app offers it; for an app that can only take a password, use an app password, which needs 2-Step Verification. Devices and applications that send in bulk should use Google's SMTP relay, set up by your Workspace administrator.

1. Google Workspace server settings

ServiceServerPortSecurity
IMAP (incoming, recommended)imap.gmail.com993SSL/TLS
POP (incoming)pop.gmail.com995SSL/TLS
SMTP (outgoing)smtp.gmail.com587STARTTLS
SMTP (outgoing, alternative)smtp.gmail.com465SSL/TLS
SMTP relay (devices and apps)smtp-relay.gmail.com587, 465 or 25TLS

For every service, the username is your full email address, such as [email protected], and outgoing mail needs authentication.

IMAP or POP? Choose IMAP. It keeps mail on Google's servers and in sync across your phone, laptop and webmail. POP downloads mail to one device and suits only a single computer that keeps its own archive.

2. How sign-in works now

Google Workspace no longer lets third-party mail apps sign in with only your normal password. An app that asks for a username and password and then fails with "invalid credentials" or "please log in via your web browser" is usually hitting this rule. There are two ways in.

MethodHow it worksUse it for
Sign in with Google (OAuth 2.0)The app opens Google's sign-in page; you approve access; the app receives a token and never stores your passwordCurrent Outlook, Apple Mail, Thunderbird, the Gmail app, iPhone and Android
App passwordA 16-character password Google generates for one app, used in place of your normal passwordOlder apps and devices that cannot open Google's sign-in page

To create an app password, turn on 2-Step Verification in your Google Account, then open Security › App passwords at myaccount.google.com, name the app and copy the password shown. If the option is missing, your Workspace administrator may have disabled app passwords, or your account uses security-key-only sign-in. Treat an app password like a password: anyone who has it can read your mail.

3. Setting up common mail apps

  1. Outlook (Microsoft 365 and the new Outlook).
    Choose Add account, enter your full address and, when asked for the provider, choose Google. Outlook opens Google's sign-in page; approve access. Only older Outlook versions without Google sign-in need manual IMAP settings and an app password.
  2. Apple Mail on Mac, iPhone and iPad.
    Add an account and pick Google from the provider list. Sign in on Google's page and choose whether to sync mail, contacts and calendars. Avoid "Other" with manual settings unless you must use an app password.
  3. Thunderbird.
    Enter your name, address and password in the new-account screen. Thunderbird detects Google, switches authentication to OAuth2 and opens Google's sign-in window. If you configure it by hand, set the authentication method to OAuth2.
  4. Android and the Gmail app.
    In the Gmail app, choose Add another account › Google and sign in with your Workspace address. Mail, contacts and calendar sync without any server settings.
  5. Check it works.
    Send yourself a test message from the app, reply to it from webmail at mail.google.com, and make sure both directions arrive.

4. Printers, scanners and applications

Devices and business software that send email, such as scan-to-email copiers, ERP alerts or website contact forms, have three routes:

SMTP relay
smtp-relay.gmail.com. The administrator enables it in the Admin console under Gmail › Routing › SMTP relay service, and allows senders by IP address, by SMTP authentication, or both. Best for offices and servers with a fixed IP.
Normal SMTP
smtp.gmail.com, 587 with STARTTLS, signed in as a real user with an app password or OAuth. Fine for a single device with low volume.
Restricted Gmail server
aspmx.l.google.com on port 25, with no sign-in. It delivers only to Gmail and Google Workspace addresses, so it suits internal alerts only.

Google applies daily sending limits to user accounts and to the relay. Check Google's current limits before you point a mailing list or a busy application at Workspace.

Sending from website code on shared hosting

PHP libraries such as PHPMailer, and frameworks such as Laravel, connect to smtp.gmail.com through socket functions. On shared hosting where those functions are disabled, the SMTP connection fails before Google is ever reached. See PHP disabled functions on shared hosting for the workarounds.

5. DNS records Google Workspace needs

Mail reaches Google only when your domain's DNS says so. Add these records wherever your domain's DNS is managed:

  • MX: Google's current instruction is a single MX record, smtp.google.com with priority 1. Older setups use the five aspmx.l.google.com records, which still work. Follow what your Admin console shows.
  • SPF (TXT on the root of the domain): include include:_spf.google.com. Keep only one SPF record, and merge in any other services that send as your domain.
  • DKIM (TXT): generate the key in the Admin console under Gmail › Authenticate email, publish it as a TXT record at the name shown (usually google._domainkey), then click Start authentication.
  • DMARC (TXT at _dmarc): start with a monitoring policy such as v=DMARC1; p=none; rua=mailto:[email protected], then tighten it once reports look clean.

Gmail and other large mailbox providers require SPF, DKIM and DMARC from bulk senders, so set all three even if you send little mail. DNS records explained covers each record type.

6. If your domain also has web hosting

When your website is on a hosting account and your mail is on Google Workspace:

  • Point MX to Google in the DNS that actually answers for your domain. If the domain uses your hosting nameservers, edit the zone in the control panel; otherwise edit it where the nameservers point. How to change your domain DNS settings explains how to tell which applies.
  • Tell the hosting server that mail is remote. In cPanel, set Email Routing for the domain to Remote Mail Exchanger. Otherwise the web server may try to deliver messages from your own website locally instead of to Google.
  • Mailboxes on the hosting stop receiving new mail once MX points to Google. Copy anything you need out of them first.

Configuring third-party email servers with DNS walks through the same change for any outside provider.

7. Troubleshooting

ProblemLikely causeFix
Password rejected in a mail appPlain password sign-in is blockedUse Sign in with Google, or an app password
No "App passwords" option2-Step Verification off, or disabled by the adminTurn on 2-Step Verification; ask your admin
App cannot connect to IMAP or POPIMAP or POP turned off for your organisationAdmin console: Gmail › End User Access
Cannot connect on port 25Many networks block outgoing port 25Use 587 or 465
Mail not arriving at GoogleMX still points to the old serverCheck MX where your DNS is managed; allow time for DNS changes
Mail from your website missing or in spamSPF, DKIM or DMARC missing, or hosting delivering locallyAdd the records; set Email Routing to Remote

To test a connection from a computer, use openssl, which works where telnet cannot handle encryption:

bash
openssl s_client -connect imap.gmail.com:993 -quiet
openssl s_client -starttls smtp -connect smtp.gmail.com:587 -quiet

A greeting from Google's server means the network path and port are open.

8. Where Domain India fits

Domain India does not sell or manage Google Workspace; you subscribe with Google, and Google's support handles your Workspace account. What we provide is the domain, and the hosting or DNS where you add Google's records. If you would rather keep email with us, there are two options:

  • Email included with shared hosting: mailboxes on the same server as your website, managed in your control panel.
  • Business Email: a separate mail platform, priced per mailbox, with webmail at https://mail.yourdomain.com:8443/, IMAP and SMTP over TLS, and no office suite.
Business Email
₹60/mo + GST
  • Priced per mailbox - start with one
  • Email at your own domain ([email protected])
  • Add and remove mailboxes yourself
  • Webmail with calendar, contacts and tasks
See plan details

Frequently asked questions

What are the IMAP settings for Google Workspace?

Server imap.gmail.com, port 993, security SSL/TLS, and your full email address as the username. Sign in with Google (OAuth) where the app offers it, or use an app password.

What are the SMTP settings for Google Workspace?

Server smtp.gmail.com, port 587 with STARTTLS or port 465 with SSL/TLS, authentication required, with your full email address as the username.

Why does my Google Workspace password not work in my mail app?

Google Workspace no longer accepts a normal password from third-party mail apps. Add the account with Sign in with Google, or create an app password after turning on 2-Step Verification and use it instead of your password.

How do I send email from a printer or scanner with Google Workspace?

Ask your Workspace administrator to enable the SMTP relay service and allow the device's IP address or an SMTP login, then point the device at smtp-relay.gmail.com on port 587 with TLS. For low volume, smtp.gmail.com with an app password also works.

What MX record does Google Workspace use?

Google currently instructs new setups to use a single MX record, smtp.google.com, with priority 1. The older set of five aspmx.l.google.com records still works. Use what your Admin console shows.

Should I use IMAP or POP with Google Workspace?

IMAP. It keeps your mail on Google's servers and in sync across every device. POP downloads mail to one device and is only worth using for a single computer that keeps its own archive.

Does Domain India sell Google Workspace?

No. Google Workspace is bought from Google. Domain India provides domains, hosting with included email, and a separate Business Email product priced per mailbox.

Ready to set up your domain's email? Check where your DNS is managed in How to change your domain DNS settings, compare Business Email, or open a support ticket if you need help finding your DNS records.

Prefer email from Domain India?

Mailboxes at your own domain, priced per mailbox, with webmail and IMAP and SMTP over TLS.

See Business Email

Ready when you are

Get Business Email from ₹60/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app