PProAccs

Outlook and Hotmail: password, OAuth, IMAP, and first access

Updated October 11, 2026Markdown version

For Outlook and Hotmail, browser sign-in, application OAuth, IMAP, SMTP, and Microsoft Graph are different capabilities. A token or one enabled protocol does not mean full control of the account.

What to check before buying

Verify the email address and domain, primary password, recovery data, 2FA method, included access or refresh token, enabled protocols, and stated limitations. Each capability should be listed separately.

First inspection through official sign-in

Start a screen recording before opening the delivery and use Microsoft's official sign-in first when browser access is promised. After access, review recent activity and unfamiliar security changes. A new region or device can itself trigger additional verification.

OAuth and refresh tokens

OAuth lets an application act only within granted permissions. An access token is normally time-limited, while a refresh token can request new access tokens. Neither is a password or proof of access to every account setting; use tokens only through an official OAuth flow and a trusted application.

IMAP, SMTP, and Graph

IMAP reads and synchronizes mail, SMTP sends it, and Microsoft Graph provides API access according to the application's permissions. Support for one method does not guarantee the others. Microsoft documents OAuth for Outlook.com and Microsoft 365 access through IMAP, POP, and SMTP.

When the stated access fails

Do not try random sign-in methods or submit tokens to third-party bots. Preserve the original delivery, first-inspection recording, product ID, exact error text, and order number, then contact support.

Primary sources