Connect your business email to FlintPOS
FlintPOS uses a provider-generated app password instead of your normal mailbox password. Choose your provider below, complete its security steps, then return to Settings > Email in FlintPOS.
Do not enter your normal Google, Apple, or Microsoft password in FlintPOS. Create a new app password for FlintPOS, copy it when the provider shows it, and store it securely. Providers usually show it only once.
Start in FlintPOS
- Open Settings, choose Email, and start the email setup wizard.
- Choose what FlintPOS should do. Google and iCloud can send email and connect the built-in inbox. Microsoft app-password setup supports sending only.
- Select your provider. Leave the wizard open or return to it after creating the app password.
- Follow the matching provider section below, then paste the generated password into the app-password field.
- Review and save. A successful SMTP connection proves the credentials can send; a successful IMAP connection proves the built-in inbox can read mail.
Google: Gmail or Google Workspace
Use these steps for an @gmail.com mailbox or a business domain hosted by Google Workspace.
Turn on Google 2-Step Verification
- Sign in to your Google Account Security page.
- Under How you sign in to Google, select 2-Step Verification.
- Select Turn on 2-Step Verification and complete Google’s prompts.
Create the Google app password
- Open Google App Passwords. Google may ask you to sign in again.
- Enter FlintPOS as the app name.
- Select Create.
- Copy the 16-character password. Paste that password into FlintPOS; spaces are optional.
Confirm 2-Step Verification is on. Google may also hide app passwords for security-key-only accounts, Advanced Protection accounts, or organization accounts whose administrator has disabled them.
Enter the Google account in FlintPOS
| Email address | The complete Gmail or Google Workspace address. |
|---|---|
| Username | Leave blank to use the email address, or enter the same complete address. |
| Password | The 16-character Google app password. |
| Incoming inbox | imap.gmail.com, port 993, encrypted connection on. |
| Outgoing email | smtp.gmail.com, port 587, STARTTLS. |
Read Google’s app-password documentation.
iCloud Mail
Use these steps for an @icloud.com, @me.com, or @mac.com mailbox, or for a custom email domain whose mail is hosted by iCloud.
Confirm two-factor authentication
Apple requires two-factor authentication before an app-specific password can be created. If you already approve Apple sign-ins on a trusted device or phone number, this is normally already on.
Create the Apple app-specific password
- Sign in at account.apple.com.
- Open Sign-In and Security.
- Open App-Specific Passwords.
- Select Generate an app-specific password.
- Enter FlintPOS as the label, select Create, and copy the generated password.
Choose the iCloud email and username carefully
Use the address customers should see in the FlintPOS Email address field. For Username, use the name portion of the iCloud Mail address first—for example, janedoe for [email protected]. If that does not connect, use the complete iCloud Mail address. Do not use an unrelated email address that only serves as the Apple Account sign-in.
Enter the iCloud account in FlintPOS
| Email address | The complete iCloud Mail address or custom-domain address customers should see. |
|---|---|
| Username | Usually the name portion of the iCloud Mail address. If needed, try the complete iCloud Mail address. |
| Password | The Apple app-specific password. |
| Incoming inbox | imap.mail.me.com, port 993, encrypted connection on. |
| Outgoing email | smtp.mail.me.com, port 587, STARTTLS. |
Read Apple’s app-specific-password documentation
Read Apple’s current iCloud Mail server settings
Microsoft 365 and Outlook
Microsoft accepts the app password for SMTP sending when the organization and mailbox settings below permit it. Microsoft blocks the password-based IMAP login used by this setup, so choose Send customer emails in the wizard.
Microsoft 365 administrator setup
Complete these steps with an account that can manage Microsoft Entra and Exchange settings. The mailbox user creates the final app password after the administrator steps are finished.
1. Turn off Security Defaults
- Sign in to the Microsoft Entra admin center.
- Open Entra ID > Overview > Properties.
- Select Manage security defaults.
- Set Security defaults to Disabled, choose a reason if Microsoft asks, and select Save.
Security Defaults blocks older sign-in protocols, including app-password SMTP. The individual MFA steps below keep additional verification on for the mailbox user.
2. Allow users to create app passwords
- In the Entra admin center, open Conditional Access > Named locations.
- Select Configure multifactor authentication trusted IPs in the toolbar. This opens the multifactor authentication service settings.
- Open Service settings if that tab is shown.
- Check Allow users to create app passwords to sign in to non-browser apps.
- Select Save.
3. Enable MFA for the individual mailbox user
- In the Entra admin center, open Identity > Users > All users.
- Select Per-user MFA.
- Select the user whose mailbox will send FlintPOS email.
- Select Enable MFA and confirm.
- Have that user sign in and register Microsoft Authenticator, a phone, or another permitted MFA method. After registration, Microsoft normally changes the user from Enabled to Enforced.
4. Enable SMTP AUTH for the organization
- Sign in to the Exchange admin center.
- Open Settings > Mail flow.
- Uncheck Turn off SMTP AUTH protocol for your organization.
- Select Save.
If Turn off SMTP AUTH is checked, SMTP is disabled. The box must be unchecked for FlintPOS SMTP authentication to work.
5. Enable Authenticated SMTP for the mailbox
- Sign in to the Microsoft 365 admin center.
- Open Users > Active users and select the mailbox user.
- Open Mail, then select Manage email apps.
- Check Authenticated SMTP.
- Select Save changes.
6. Create the Microsoft 365 app password
- Sign in as the mailbox user at Microsoft Security info.
- Select Add sign-in method.
- Select App password, then select Add.
- Enter FlintPOS as the app name and select Next.
- Copy the generated password before closing the window.
7. Enter the Microsoft account in FlintPOS
| Setup mode | Send customer emails. |
|---|---|
| Email address | The complete Microsoft mailbox address. |
| Username | Leave blank to use the email address, or enter the same complete address. |
| Password | The generated Microsoft app password. |
| Microsoft 365 SMTP | smtp.office365.com, port 587, STARTTLS. |
| Personal Outlook SMTP | smtp-mail.outlook.com, port 587, STARTTLS. |
If App password is not listed
- Confirm Security Defaults is disabled.
- Confirm Allow users to create app passwords is saved in the multifactor authentication service settings.
- Confirm the mailbox user is enabled for per-user MFA and has completed MFA registration.
- Refresh the Security info page or sign out and back in after the administrator changes have propagated.
- Some organizations require modern authentication and do not allow app passwords. In that case, the Microsoft app-password path cannot be used.
How to read the FlintPOS test results
- SMTP connection successful: Microsoft accepted the mailbox address and app password.
- Outbound email is disabled in staging: expected on the FlintPOS staging system; staging verifies the connection without sending a real message.
- IMAP connection failed or logging in is disabled: expected if an older setup attempted to add the Microsoft mailbox to the built-in inbox. Reconfigure Microsoft as send-only.
Microsoft: Security Defaults
Microsoft: allow app passwords
Microsoft: enable per-user MFA
Microsoft: enable SMTP AUTH
Microsoft: create a work or school app password
After the connection works
- Keep MFA enabled for the mailbox account.
- Create a separate app password for FlintPOS rather than reusing one from another application.
- Delete the app password from the provider if the mailbox is retired, an administrator leaves, or you believe the password was exposed.
- Create a new app password and update FlintPOS after changing security policies that revoke the old credential.
- Use a business-controlled mailbox rather than an employee’s personal mailbox.