# IMAP, SMTP, Graph, and App Password email access

> These are different ways to work with mail: receiving, sending, API access, and a separate application password are not interchangeable.

## IMAP and SMTP

Mail clients use IMAP to read and synchronize a mailbox, while SMTP sends mail. Availability of one protocol does not guarantee the other.

## Microsoft Graph

Graph is Microsoft's official API for authorized programmatic access to Microsoft 365 data. Access depends on an OAuth token and the permissions granted to the application.

## App Password

An app password is a separate code for an older client that cannot use modern sign-in. Google states that it requires 2-Step Verification and recommends Sign in with Google where available.

## Before buying

Check the required protocol, primary sign-in, included 2FA, app password, and token lifetime. Labels such as IMAP, Graph, or App Password do not guarantee control over every account setting.

## Related

- [Account data formats: login, password, 2FA, token, cookie, and JSON](https://getproaccs.com/en/docs/account-data-formats)
- [What 2FA means and how to enable it safely](https://getproaccs.com/en/docs/two-factor-authentication)
- [Token, refresh token, and OAuth 2.0 explained](https://getproaccs.com/en/docs/tokens-and-oauth)

## Sources

- [Google: App Passwords](https://support.google.com/accounts/answer/185833)
- [Microsoft Graph overview](https://learn.microsoft.com/en-us/graph/overview)

Canonical: https://getproaccs.com/en/docs/email-access-and-app-passwords
Updated: 2026-10-11
