"The email server refused that sign-in" on a mailbox that isn't @gmail.com (your own domain, Hostinger, iCloud, Fastmail)

Modified on Tue, 4 Aug at 12:33 PM

You created a Google app password, pasted it in, pressed Check it, and got turned away. Most people write it down as "The email server refused that sign-in for Gmail/Claude. Use an app-specific password"; on screen it reads "The mail server refused that sign-in. For Gmail/iCloud use an app-specific password." Your reaction is the one we hear most: "I have already done exactly that, and it still does not work". On top of it, Otto reports an authorization error: invalid_grant for both inboxes, so it looks like two things are broken at once. If the address you are connecting is not an @gmail.com address, this article is almost certainly your answer, and the fix is not another app password.

You are looking at two errors, and only one of them matters

Customers report these together, and they are not the same thing. Separating them is the whole diagnosis.

  • "The mail server refused that sign-in. For Gmail/iCloud use an app-specific password." This is the direct connection: your address plus an app password, tested live. The mail server is turning the login away. This is the actual blocker.
  • invalid_grant This is the old Gmail link that rides on your claude.ai account. Otto only falls back to it because the direct connection is failing, and that link's Google sign-in expires on its own. It is a symptom, not the cause.

So if you have been asking why Gmail authentication continues to fail with the invalid_grant error even when app-specific passwords are configured correctly, here is the honest answer: invalid_grant is not coming from your app password at all. Fix the direct sign-in and invalid_grant stops on its own. Do not spend another minute relinking Gmail on claude.ai. Almost everyone tries that first, and it is a dead end: it clears for a moment, then lapses again. Skip it.

This is also why "Otto was able to send drafts to my address before but not now" is such a common line. What used to work was that claude.ai link. It needed no setup, which is exactly why it just worked, and it expires quietly. The direct app-password connection takes a few minutes to set up once and then stays put.

What "Check it" actually does, and why that explains everything

Check it is not a settings validator. It opens a real, live login to the exact mail server you typed, using the exact address you typed and the password you pasted. Green means the mail provider itself accepted the sign-in. Red means the provider said no.

That has one consequence that decides everything below: the login can only succeed if that address is a genuine mailbox on that server. Not a forwarder. Not an alias. Not a domain that merely has mail pointed at it. A mailbox you could sign into yourself, on that server. This is why a perfect app password can be refused over and over on a custom-domain address.

Update the app first. Some of this was ours, not your setup

Use Check for updates in the top bar. To see which build you are actually on, open Settings and read the Updates panel: it names the version you are running. Three faults in this area were ours, and below the build that fixed each one, no amount of correct configuration gets you through.

  • 1.11.5, the pasted spaces. Google shows an app password as four blocks with spaces, like abcd efgh ijkl mnop. The real password is those 16 characters with no spaces. Pasting the spaces used to fail the sign-in every single time, identically on every account. The password field now strips spaces as you type or paste, so copy the password exactly as Google shows it and do not fight the spaces.
  • 1.11.5, the missing tool programs. The direct Gmail tool programs were left out of the installer's unpack list, so they were missing from every installed build. Nothing you configured could work around it, and Otto kept saying "reconnect Gmail" or invalid_grant even after Check it went green.
  • 1.11.32, and 1.11.33 if your mailbox is not Gmail. Mail providers name the Drafts folder in your account's own language. In Dutch it is Concepten, in German Entwürfe. Otto looked only for the English name and reported that the Drafts folder does not exist, so drafts silently never appeared. 1.11.32 fixed that for Gmail. 1.11.33 did the same for every other IMAP mailbox, and for the Sent folder, so if your mailbox lives anywhere other than Gmail, 1.11.33 is the build you need.

Keep those last two apart in your own head. If you updated for the missing tool programs and drafting still failed with a message that the Drafts folder does not exist, you were never looking at the same bug: that is the folder-name one, and for a mailbox that is not Gmail it was not fixed until 1.11.33.

After updating, fully quit and reopen the app and click Start fresh.

Where does your mailbox actually live? That one question decides the fix

An address on your own domain tells you nothing about where its mail is stored. Find yourself in one of these four, because each has a different fix and only one of them involves a Google app password.

1. A real Google mailbox on your own domain (Google Workspace)

This is you if you read that mail by signing in at Google, just with your own domain address. As one performer put it, "I sign through Gmail into those two accounts". Three details have to be right, and all three are easy to get wrong:

  1. The Mail server field must read exactly imap.gmail.com. Not mail.yourdomain.com. For sending, smtp.gmail.com on port 465.
  2. The app password must have been created while you were signed into that exact address. An app password from one Google account never signs in another. If you run several brands, this is the single most common cause of a red result: 9 times out of 10 the password was made under a different Google login.
  3. IMAP has to be switched on inside that mailbox. Open the inbox on the web, then the gear icon > See all settings > Forwarding and POP/IMAP > Enable IMAP > Save. If IMAP is off there, Google refuses the login even with a flawless app password.

If your notes read "I've set up the app specific password for both accounts set to imap.gmail.com" and both still fail, work down that list in order. Item 2 and item 3 are the ones people skip.

2. The branded address only forwards into a normal @gmail.com

This is extremely common for performers: mail sent to you@yourbandname.com actually lands in a personal @gmail.com inbox, and the branded address is only a redirect. Be clear-eyed about this one. That branded address is not a mailbox Google will let anything log into, so it will be refused forever, no matter how many app passwords you create. This is a dead end, not a configuration problem.

What works: connect the account using the real @gmail.com that actually receives the mail, with that Gmail's own app password. Then, so your clients still see your brand, open that Gmail's settings and add the branded address as a Send mail as address. Otto drafts into Gmail, and Gmail sends showing your branded name. If your goal was "I would like to use this email to send email to my clients instead google account", that is exactly what Send mail as gives you.

3. The mailbox lives with your web host or another provider

Hostinger, GoDaddy, a cPanel host, iCloud, Fastmail, Zoho. Here a Gmail app password is the wrong key entirely. Add the mailbox as Any email (IMAP) using that host's own incoming server and that mailbox's own password.

Hostinger is the one we get asked about most, usually as "I want Otto to draft into my Hostinger-hosted email". If you are at the stage of "Getting the email set up with your Hostinger instructions" and want the values in one place, they are:

  • Mail server (incoming): imap.hostinger.com, port 993
  • Outgoing server (optional): smtp.hostinger.com, port 465
  • Password: your normal mailbox password. Hostinger does not need a special app password at all.

Gmail and iCloud are the exceptions that do need an app-specific password. For iCloud, generate it in your Apple account security settings. Every other provider publishes its exact IMAP and SMTP values on its own help pages, and those published values are what belongs in these fields.

4. A Microsoft 365 or Outlook mailbox

Do not use IMAP for this one. Microsoft 365 has its own sign-in in the app, by device code, where you sign in on Microsoft's own page and no password ever touches Booked Solid. The details are in Microsoft 365 by device code: what Otto can and cannot do in Outlook.

The reverse is worth stating just as plainly, because people burn hours on it: the Microsoft 365 and Outlook connections drive Microsoft-hosted accounts and the Outlook app already set up on your own computer, and nothing else. It will never connect a Hostinger mailbox, or any other non-Microsoft mailbox, however many times you retry. If the Outlook connection keeps refusing an address that is not hosted by Microsoft, that is the connection working as designed. Stop fighting it and use Any email (IMAP) instead.

The steps, one account at a time

Do not set up two addresses at once. Get one green, then repeat.

  1. If the mailbox needs an app password (Gmail, Google Workspace, iCloud), create it while signed in as that exact address. For Google, that is at myaccount.google.com/apppasswords, and 2-Step Verification has to be on for that page to appear. The screen-by-screen version is in Connect your Gmail with an app password (step by step).
  2. In the app, open More > Connections > Mail & calendars > Add an email account.
  3. Keep the method on Any email (IMAP), which is where the form already starts. Do not pick the Gmail linked-account route: that is the browser one that keeps expiring.
  4. Enter the address, the mail server for wherever that mailbox actually lives, and the password. Give the account a name you will recognise and pick its purpose tag: bookings, personal, support, or business. The tag is what lets the app run its date clash check between your bookings and personal calendars.
  5. Press Check it. It has to come back "Connected - the address and password work." Anything else, fix that before you touch anything else. Then Save.
  6. Repeat for the next address, with its own password created under its own sign-in.
  7. Fully quit and reopen the app, then click Start fresh.

To correct one field later, use the account card's Edit button rather than removing the account: it opens the form filled in, and leaving the password box empty keeps the password you already saved.

"Where is the Drafts Connection in Tool Access?" There is no such switch

This stops more people than any error message does. There is no switch called Drafts Connection. If you have been hunting for one and thinking "I don't have a Drafts Connection switch", you are not missing anything: it is not there.

The switch you want is on the same Connections screen, below the accounts, in the section headed Tool access (optional), and it is labelled Gmail (app password). Say it out loud, because the label misleads everybody: despite the Gmail wording, that switch is the generic IMAP drafts engine wearing a Gmail label. It works for Hostinger, iCloud, Fastmail, Zoho, your own domain on Google Workspace, and plain Gmail. So if your thought was "my email is not Gmail, this cannot be the right switch", it is the right switch. A rename is on the list.

If instead the problem is "This Gmail button will not toggle on no matter what I do", that is not a broken button either. That switch does not connect anything by itself. It only hands Otto access to an inbox you have already added, so until an IMAP inbox exists it has nothing to point at and cannot turn on. The card says so, and gives you a button that opens the account form ready to go. Account first, switch second.

On current versions you usually do not have to touch it at all: saving a brand new IMAP inbox that has a stored password switches Gmail (app password) on for you. And if an inbox is ever saved while the switch is off, that account's row says Not handed to Otto yet with a Turn on for Otto button right on it.

What each "Check it" message means

What the app saysWhat it means
Connected - the address and password work.A real login just succeeded. The credential is genuinely good.
The mail server refused that sign-in. For Gmail/iCloud use an app-specific password.The server answered and rejected the sign-in. Everything above applies: right kind of password, created under the right account, on a server where that address is a real mailbox.
That mail server name could not be found - check the spelling.The server name does not resolve. One typo does this. Gmail is imap.gmail.com for reading and smtp.gmail.com for sending.
The mail server refused the connection - the port is usually the culprit.Wrong port. 993 for IMAP, 995 for POP3, 587 or 465 for sending.
The mail server could not be reached at all - a firewall or this network may be blocking mail connections.Try once from a different network, such as a phone hotspot, to see whether the network is the cause.
The secure connection to the mail server was broken mid-setup.Nearly always an antivirus mail shield or web shield inspecting mail connections. Pause the shield once and retest, then add an exception and turn it back on. See Email will not connect: antivirus mail shields (AVG, Avast, Norton).
The mail server did not answer in time. / The mail server closed the connection before the check finished.The server exists but did not complete the exchange. Try again in a minute; if it repeats, the server may be down or blocking the connection.
No saved password for this account - add it again.The stored password is gone. Click Edit on the account, re-enter the password, and run Check it again.
Could not reach that mail server. Check the server name and port.The catch-all, with the raw error code in brackets. Send us that code if you are stuck.

What you get once it is green

Otto reads that mailbox over IMAP and writes drafts into that mailbox's own Drafts folder. There is no send button anywhere in it. You always send from your own mail app, after reading what he wrote. A draft quietly appearing in Drafts is the successful result, not a sent message.

Several inboxes are welcome, one per brand or persona. Every enabled inbox rides along in the same run, and Otto names which one he is acting in, so you always know which address is doing the work.

One timing rule catches people out. Account changes reach Otto the moment you save them, but a connection switched on after a conversation was already open is not loaded into that conversation. If Otto says the direct Gmail tools are not available in this session, that is what it means: fully quit the app, reopen it, and click Start fresh.

Calendars use the same Check it

If a calendar added by ICS link fails with "That address did not return a calendar. Use the private ICS link.", you pasted the public calendar page rather than the private feed link. Grab the private link from your calendar provider. Unreadable calendars are always named as skipped, never silently ignored, and a calendar the app could not read is never reported as a free day.

Prefer a fully managed experience? Booked Solid OS runs on your computer and you stay hands-on. If you would rather have this handled for you on a hosted platform (lead finding, follow-ups, email sending, invoicing, all managed in one place), take a look at KM Hub from the same team.

If it still does not work

If you have reached the point where you are typing "I'm at the point of giving up", stop and hand it to us instead of running the loop again. Open a ticket at bookedsolid@kivimedia.freshdesk.com and include three things: the exact red text from Check it, the address you are connecting, and where you actually sign in to read that mailbox. That last one is the question that solves most of these. In Settings, use Generate Support Bundle and attach it: it carries app errors, system details and safe settings, never your passwords, your client details or the text of your messages. A person will pick it up from there.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article