Imapsync is a command-line tool that synchronizes mailboxes between two email servers over IMAP, which stands for Internet Message Access Protocol. This matters during email migration between hosting providers or when moving mailboxes to a new server. If 2FA or MFA is enabled on the source or destination mailbox, a normal password login may not work for automated migration.
2FA, also called Multi-Factor Authentication, adds a second login step such as an SMS code, an authenticator app prompt, or a hardware key. Imapsync cannot stop during a migration to wait for that interactive step. In this situation, the usual method is to use an App-Specific Password so the mailbox can be accessed securely without disabling 2FA.
Table of Contents
What App-Specific Passwords are
An App-Specific Password, sometimes called an Application Token, is a separate password generated for a specific app or script. It is used instead of the main account password for non-interactive access such as IMAP connections from Imapsync.
This password lets Imapsync connect to a mailbox without triggering the normal 2FA prompt. It also helps keep the main account password separate from the migration process.
Distinction: account password vs App-Specific Password
- Account password: The main password used to sign in to the mailbox account directly.
- App-Specific Password: A separate generated password used by a script or application that cannot complete an interactive 2FA step.
- 2FA or MFA: An extra verification step added to account login, such as a code or device approval.
How to generate an App-Specific Password
The exact screens vary by provider, but the process is usually similar.
- Sign in to the security settings for the email account at your email provider or hosting control panel.
- Open the Security or Sign-in options section.
- Find the setting called App passwords or App-Specific Passwords.
- Create a new password or token for mail access, and give it a clear name such as Imapsync Migration.
- Copy the generated code and save it securely.
In the source article, this generated value is described as a random alphanumeric string. Use the value exactly as provided by your email provider.
How to run Imapsync with 2FA-enabled mailboxes
After you generate the App-Specific Password, use it in your Imapsync command in place of the normal mailbox password. The source article recommends passing the credentials through password files with --passfile1 and --passfile2.
This approach is useful for both sides of the migration:
- Source mailbox: Use an App-Specific Password if the source account has 2FA or MFA enabled.
- Destination mailbox: Use an App-Specific Password there as well if the destination account also uses 2FA or MFA.
Example command:
imapsync --host1 imap.sourceprovider.com --user1 [email protected] --passfile1 /path/to/app_password_txt
--host2 imap.mybox.com --user2 [email protected] --passfile2 /path/to/destination_password_txt
--ssl1 --ssl2 --syncinternaldates
What the command options do
--host1and--host2define the source and destination IMAP servers.--user1and--user2define the mailbox usernames.--passfile1and--passfile2point to files that contain the passwords or App-Specific Passwords.--ssl1and--ssl2enable encrypted IMAP connections for the source and destination.--syncinternaldatestells Imapsync to preserve internal message dates during synchronization.
Security note for password handling
It is safer to store passwords or App-Specific Passwords in files and reference those files with --passfile than to place the secrets directly in the command line. This helps reduce exposure in shell history and process listings.
If you use passfiles, keep them in a secure location on the server and limit file access appropriately.
After the mailbox migration
Once the mailbox data has been migrated, there may be related settings to update if that mailbox is used by applications or website features.
Update application email settings if the mailbox sends system email
If the migrated mailbox is used by an application account, such as contact forms, transactional messages, invoices, or password reset emails, update the application’s outbound mail settings after the migration.
The source article specifies using mail.mybox.com for SMTP routing in that scenario. This applies when your application sends mail programmatically and needs to use the verified outgoing mail path after the mailbox has moved.
Clear cache after related site changes
If you also changed configuration files, mail settings, or contact form behavior on the website after the migration, cached content may still reflect older settings. In that case, clear the server cache so the updated configuration is served consistently.
The source article specifically mentions LiteSpeed Cache and the option to run Purge All LSCache from the control panel.
What to expect
If 2FA is enabled, this is expected behaviour: the main account password may not be enough for an automated IMAP migration. Using an App-Specific Password is the standard workaround described in the source article.
If the migration includes only mailbox data, the Imapsync step and the application update step are separate tasks. Mailbox synchronization moves email content. SMTP settings and cache clearing only apply if your website or application also uses that mailbox after the migration.
Summary
- Use Imapsync to synchronize mailboxes over IMAP.
- If 2FA or MFA is enabled, use an App-Specific Password instead of the main account password.
- Store passwords in passfiles and reference them with
--passfile1and--passfile2. - Use
--ssl1and--ssl2for encrypted IMAP connections. - If the migrated mailbox is used by an application, update SMTP settings to mail.mybox.com where needed.