{"id":8586,"date":"2026-05-28T10:03:18","date_gmt":"2026-05-28T08:03:18","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=8586"},"modified":"2026-06-09T07:12:54","modified_gmt":"2026-06-09T05:12:54","slug":"imapsync-si-autentificarea-cu-doi-factori-2fa-migrarea-cutiilor-postale-protejate","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/ro\/knowledgebase\/imapsync-and-two-factor-authentication-2fa-migrating-protected-mailboxes\/","title":{"rendered":"Imapsync \u0219i autentificarea cu doi factori (2FA): Migrarea cutiilor po\u0219tale protejate"},"content":{"rendered":"<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">Imapsync is a command-line tool that synchronizes mailboxes between two email servers over IMAP, which stands for Internet Message Access Protocol. This matters during email migration between hosting providers or when moving mailboxes to a new server. If 2FA or MFA is enabled on the source or destination mailbox, a normal password login may not work for automated migration.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">2FA, also called Multi-Factor Authentication, adds a second login step such as an SMS code, an authenticator app prompt, or a hardware key. Imapsync cannot stop during a migration to wait for that interactive step. In this situation, the usual method is to use an App-Specific Password so the mailbox can be accessed securely without disabling 2FA.<\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/imapsync-and-two-factor-authentication-2fa-migrating-protected-mailboxes\/#What_App-Specific_Passwords_are\" >What App-Specific Passwords are<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/imapsync-and-two-factor-authentication-2fa-migrating-protected-mailboxes\/#Distinction_account_password_vs_App-Specific_Password\" >Distinction: account password vs App-Specific Password<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/imapsync-and-two-factor-authentication-2fa-migrating-protected-mailboxes\/#How_to_generate_an_App-Specific_Password\" >How to generate an App-Specific Password<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/imapsync-and-two-factor-authentication-2fa-migrating-protected-mailboxes\/#How_to_run_Imapsync_with_2FA-enabled_mailboxes\" >How to run Imapsync with 2FA-enabled mailboxes<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/imapsync-and-two-factor-authentication-2fa-migrating-protected-mailboxes\/#What_the_command_options_do\" >What the command options do<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/imapsync-and-two-factor-authentication-2fa-migrating-protected-mailboxes\/#Security_note_for_password_handling\" >Security note for password handling<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/imapsync-and-two-factor-authentication-2fa-migrating-protected-mailboxes\/#After_the_mailbox_migration\" >After the mailbox migration<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/imapsync-and-two-factor-authentication-2fa-migrating-protected-mailboxes\/#Update_application_email_settings_if_the_mailbox_sends_system_email\" >Update application email settings if the mailbox sends system email<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/imapsync-and-two-factor-authentication-2fa-migrating-protected-mailboxes\/#Clear_cache_after_related_site_changes\" >Clear cache after related site changes<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/imapsync-and-two-factor-authentication-2fa-migrating-protected-mailboxes\/#What_to_expect\" >What to expect<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/imapsync-and-two-factor-authentication-2fa-migrating-protected-mailboxes\/#Summary\" >Summary<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_App-Specific_Passwords_are\"><\/span>What App-Specific Passwords are<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<\/div>\n\n<div id=\"mybox-380407053\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Acces timpuriu<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Mai ave\u021bi nevoie de ajutor?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contacta\u021bi echipa noastr\u0103 de servicii pentru clien\u021bi.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Trimite mesaj<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">An App-Specific Password, sometimes called an Application Token, is a separate password generated for a specific app or script. It is used instead of the main account password for non-interactive access such as IMAP connections from Imapsync.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This password lets Imapsync connect to a mailbox without triggering the normal 2FA prompt. It also helps keep the main account password separate from the migration process.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Distinction_account_password_vs_App-Specific_Password\"><\/span>Distinction: account password vs App-Specific Password<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Account password:<\/strong> The main password used to sign in to the mailbox account directly.<\/li>\n\n\n\n<li><strong>App-Specific Password:<\/strong> A separate generated password used by a script or application that cannot complete an interactive 2FA step.<\/li>\n\n\n\n<li><strong>2FA or MFA:<\/strong> An extra verification step added to account login, such as a code or device approval.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_generate_an_App-Specific_Password\"><\/span>How to generate an App-Specific Password<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The exact screens vary by provider, but the process is usually similar.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Sign in to the security settings for the email account at your email provider or hosting control panel.<\/li>\n\n\n\n<li>Open the <strong>Security<\/strong> or <strong>Sign-in options<\/strong> section.<\/li>\n\n\n\n<li>Find the setting called <strong>App passwords<\/strong> or <strong>App-Specific Passwords<\/strong>.<\/li>\n\n\n\n<li>Create a new password or token for mail access, and give it a clear name such as <strong>Imapsync Migration<\/strong>.<\/li>\n\n\n\n<li>Copy the generated code and save it securely.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">In the source article, this generated value is described as a random alphanumeric string. Use the value exactly as provided by your email provider.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_run_Imapsync_with_2FA-enabled_mailboxes\"><\/span>How to run Imapsync with 2FA-enabled mailboxes<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">After you generate the App-Specific Password, use it in your Imapsync command in place of the normal mailbox password. The source article recommends passing the credentials through password files with <code>--passfile1<\/code> and <code>--passfile2<\/code>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This approach is useful for both sides of the migration:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Source mailbox:<\/strong> Use an App-Specific Password if the source account has 2FA or MFA enabled.<\/li>\n\n\n\n<li><strong>Destination mailbox:<\/strong> Use an App-Specific Password there as well if the destination account also uses 2FA or MFA.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Example command:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>imapsync --host1 imap.sourceprovider.com --user1 workspace@yourdomain.com --passfile1 \/path\/to\/app_password_txt \n         --host2 imap.mybox.com          --user2 workspace@yourdomain.com --passfile2 \/path\/to\/destination_password_txt \n         --ssl1 --ssl2 --syncinternaldates\n<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_the_command_options_do\"><\/span>What the command options do<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>--host1<\/code> and <code>--host2<\/code> define the source and destination IMAP servers.<\/li>\n\n\n\n<li><code>--user1<\/code> and <code>--user2<\/code> define the mailbox usernames.<\/li>\n\n\n\n<li><code>--passfile1<\/code> and <code>--passfile2<\/code> point to files that contain the passwords or App-Specific Passwords.<\/li>\n\n\n\n<li><code>--ssl1<\/code> and <code>--ssl2<\/code> enable encrypted IMAP connections for the source and destination.<\/li>\n\n\n\n<li><code>--syncinternaldates<\/code> tells Imapsync to preserve internal message dates during synchronization.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Security_note_for_password_handling\"><\/span>Security note for password handling<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">It is safer to store passwords or App-Specific Passwords in files and reference those files with <code>--passfile<\/code> than to place the secrets directly in the command line. This helps reduce exposure in shell history and process listings.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you use passfiles, keep them in a secure location on the server and limit file access appropriately.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"After_the_mailbox_migration\"><\/span>After the mailbox migration<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Once the mailbox data has been migrated, there may be related settings to update if that mailbox is used by applications or website features.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Update_application_email_settings_if_the_mailbox_sends_system_email\"><\/span>Update application email settings if the mailbox sends system email<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If the migrated mailbox is used by an application account, such as contact forms, transactional messages, invoices, or password reset emails, update the application&#8217;s outbound mail settings after the migration.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The source article specifies using <strong>mail.mybox.com<\/strong> for SMTP routing in that scenario. This applies when your application sends mail programmatically and needs to use the verified outgoing mail path after the mailbox has moved.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Clear_cache_after_related_site_changes\"><\/span>Clear cache after related site changes<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you also changed configuration files, mail settings, or contact form behavior on the website after the migration, cached content may still reflect older settings. In that case, clear the server cache so the updated configuration is served consistently.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The source article specifically mentions LiteSpeed Cache and the option to run <strong>Purge All LSCache<\/strong> from the control panel.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_to_expect\"><\/span>What to expect<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If 2FA is enabled, this is expected behaviour: the main account password may not be enough for an automated IMAP migration. Using an App-Specific Password is the standard workaround described in the source article.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the migration includes only mailbox data, the Imapsync step and the application update step are separate tasks. Mailbox synchronization moves email content. SMTP settings and cache clearing only apply if your website or application also uses that mailbox after the migration.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Summary\"><\/span>Summary<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Use Imapsync to synchronize mailboxes over IMAP.<\/li>\n\n\n\n<li>If 2FA or MFA is enabled, use an App-Specific Password instead of the main account password.<\/li>\n\n\n\n<li>Store passwords in passfiles and reference them with <code>--passfile1<\/code> and <code>--passfile2<\/code>.<\/li>\n\n\n\n<li>Use <code>--ssl1<\/code> and <code>--ssl2<\/code> for encrypted IMAP connections.<\/li>\n\n\n\n<li>If the migrated mailbox is used by an application, update SMTP settings to <strong>mail.mybox.com<\/strong> where needed.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n<\/div>","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[41],"manual_kb_tag":[7125,7126,7127,7128,7129,229,400,867,868,5168],"class_list":["post-8586","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-email","manual_kb_tag-imapsync-migration","manual_kb_tag-imapsync-tool","manual_kb_tag-imap-over-ssl","manual_kb_tag-application-token","manual_kb_tag-password-files","manual_kb_tag-two-factor-authentication","manual_kb_tag-email-migration","manual_kb_tag-mailbox-synchronization","manual_kb_tag-imap-protocol","manual_kb_tag-app-specific-password"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/8586","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":5,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/8586\/revisions"}],"predecessor-version":[{"id":8587,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/8586\/revisions\/8587"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/media?parent=8586"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manualknowledgebasecat?post=8586"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb_tag?post=8586"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}