App passwords for mail programs
A mail program cannot ask you for a code from an app — IMAP simply has no room for it. So it gets a password of its own: one per device, revoked one at a time, and useless for signing in to the site.
When you need them
With two-factor protection off — never. Your mail program takes the ordinary mailbox password.
With it on — always. Otherwise the phone will keep saying "wrong password" while the password is perfectly right: the program simply has no way through the second step.
Creating one
- Account → Security → App passwords.
- Give it a name. It changes nothing, but later it tells you which password belongs to which device: "iPhone", "laptop", "the tablet".
- Press Create. A twenty-character password appears once — put it straight into the mail program.
- Closed the page without copying it? No harm done: delete that password and make another.
Where it goes
Anywhere the program asks for the mailbox password. Nothing else changes:
- Incoming mail server
- mail.alpost.ch, port 993, SSL/TLS
- Outgoing server
- mail.alpost.ch, port 587, STARTTLS
- Username
- the full mailbox address
- Password
- the app password, not the main one
How it differs from the main password
It cannot sign you in to the website or the account area — only fetch and send mail. If it leaks, a stranger reads your correspondence but cannot change your password, switch off your protection, or take the mailbox away from you.
Each password has its own trail: your account page shows when it was last used and from which address.
If a device is lost
Delete the password that lived on it. Every other device carries on — nothing to reconfigure.
That is the whole point of separate passwords: losing one phone does not force you to set up everything else again.