Unibox
All resources
ACCOUNT TROUBLESHOOTING

How to fix email account connection problems on a Mac

Most account-connection failures come from one of four places: an expired or revoked authorization, a provider app-registration setting, the wrong kind of password, or an incorrect mail-server setting. The safest fix is to identify which layer failed instead of repeatedly changing unrelated settings.

9 minute read

Start with the exact error and the affected account

Confirm which provider and email address failed, then copy the exact error text without including passwords, access codes, API keys, or authorization tokens. A failure in one account does not mean every connected account needs to be removed or reauthorized.

Check whether receiving, sending, or both are affected. Receiving points toward OAuth or IMAP; sending alone often points toward SMTP authorization, the outgoing server, or the sender identity.

  • Note the provider, account address, time, and exact error message.
  • Test the provider's own webmail to confirm the account itself is available.
  • Reconnect only the affected account before considering removal and re-adding.
  • Never send a password, app password, token, or API key to support.

Fix Google authorization that expired or was revoked

Use the account's Reconnect control and finish Google's consent flow for the same address shown in Unibox. A successful browser sign-in must return to the matching local account; reconnecting a different Google address will not repair the expired one.

Google states that external OAuth apps left in Testing status issue authorizations and refresh tokens that expire after seven days when mail scopes are requested. That recurring behavior is a project publishing-status limitation, not a normal daily sign-in requirement. Production verification, user revocation, Workspace administrator policy, password or security changes, prolonged token inactivity, and provider limits can also affect authorization.

Fix Microsoft 365 or Outlook sign-in

A native Microsoft desktop app is a public client. Its redirect URI must match the URI registered in Microsoft Entra, and the application must be configured for the intended work, school, or personal Microsoft account audience.

If Microsoft reports a reply-URL mismatch, do not improvise a new URL. Compare the exact redirect URI in the error with the app registration. An organization administrator can also require approval or block an app even when the registration itself is correct.

Fix Yahoo authentication failures

Yahoo's regular web password may not work in a third-party mail client. Generate a separate app password from Yahoo Account Security while signed in to the correct account, then use that generated value in Unibox's Yahoo setup.

Yahoo says app passwords remain active until deleted. If a previously working account stops authenticating, delete the saved app password in Yahoo, create a new one, and reconnect the affected account. Do not reuse the generated credential for unrelated apps.

Fix generic IMAP and SMTP settings

Generic accounts need separate incoming IMAP and outgoing SMTP settings. Copy the host names, ports, encryption requirements, username format, and authentication method from the email provider rather than guessing common values.

A certificate mismatch is not a prompt to disable certificate validation. Verify the host name with the provider. If receiving works but sending fails, inspect SMTP separately, including whether the provider expects TLS or STARTTLS and whether the complete email address is the username.

Know when to reconnect, re-add, or contact support

Reconnect first when an OAuth token expired or was revoked. Replace the app password when Yahoo explicitly rejects it. Correct server settings when an IMAP or SMTP host, port, or encryption error appears. Remove and re-add an account only after a targeted reconnect fails, because removal can discard that account's local working cache.

A useful support request includes the provider, affected address, Unibox and macOS versions, exact error text, whether webmail works, and whether sending or receiving failed. Redact personal message content and every secret.

FREQUENTLY ASKED QUESTIONS

Questions about this workflow

Should Google ask me to reconnect every seven days?

Not in normal production use. Google documents seven-day authorization and refresh-token expiration for external apps in Testing status when broader scopes such as Gmail access are requested. Other account or administrator policies can still require reauthorization.

Why can I receive email but not send it?

Receiving and sending use different services for generic accounts. Recheck the SMTP host, port, encryption mode, username, and authentication even when IMAP is working.

Should I remove an account whenever sign-in fails?

Usually not as the first step. Reconnect the affected OAuth account, replace a rejected app password, or correct the specific server setting first. Re-add only after the targeted repair fails.

What information is safe to include in a support request?

Include the provider, affected address, app and macOS versions, exact error, and whether sending or receiving failed. Never include a password, app password, token, API key, or unredacted private message content.

Sources and further reading

Provider behavior and security guidance in this article is grounded in primary documentation:

TRY THE WORKFLOW

Put every supported email account in one Mac workspace.

Unibox is free for 30 days. No credit card is required.

Try Unibox