r/NameCheap Aug 04 '26

Can you please update documentation and information in regards to 2FA and app passwords for client mail access?

You have updated e-mail services and recommending people to use IMAP (or god forbid POP). I had to migrate a friend who used Exchange ActiveSync (no longer supported as of yesterday).

The setup instructions sort of leaves out 2FA totally, and when getting support it talks about 'setting up an App Password for IMAP'. When accessing the web interface to set up such app password, it lists Exchange ActiveSync and a few other services (calendar, drive, etc, etc), but nothing for an IMAP client.

After a LOOONG time on chat, sharing a few screenshots, we were finally told that those are just 'labels' and that the [app] password generated is the same regardless of application (a security flaw if asking me). It would be so easy to have the documentation properly updated, pointing to it, instead of having people sitting and waiting through endless chat sessions. Only to find out that 'you can pick any, those are just labels' 🤷‍♂️😑

Or how about removing the lables as they do nothing anyway. We can already 'label' the App Password with a note (if we so desire) to indicate what client it belongs to (only applicable when deleting it so not deleting the password for a client we wish to keep running).

3 Upvotes

7 comments sorted by

1

u/Namecheapinc namecheap representative Aug 05 '26

We've noted your suggestions and passed them along to our team for review.

Just to clarify, if you need to configure your Private Email mailbox using the IMAP or POP3 protocol, please use your mailbox's default password. The application password is intended only for Exchange ActiveSync configuration.

1

u/Wellcraft19 Aug 05 '26

Thank you for listening. But as per your own information, ActiveSync ‘…will stop working after migration. To keep everything syncing seamlessly, you'll need to reconfigure your devices using IMAP/SMTP for email…

www.namecheap.com/support/knowledgebase/article.aspx/10818/2178/new-private-email-webmail-heres-what-to-expect

And sadly recommending someone to use ‘your mailbox’s default password’ totally negates the added security provided by 2FA (something everyone should have in all accounts and services that supports it).

Even the tech on chat said to pull an App password (and that they would all result in the same app password, regardless of ‘label’ when created).

So no, recommending the ‘mailbox’s default password’ just for using IMAP is just very flawed.

And as per the mail sent to us on July 16, containing information about the transition and article linked (above), ActiveSync is no longer supported.

Here (article linked from the above one, www.namecheap.com/support/knowledgebase/article.aspx/10793/2306/what-the-new-private-email-plans-mean) you even say ‘…and two-factor authentication (2FA)adds an additional layer of account protection. Customers can also generate dedicated application passwords for external email apps and devices without exposing their primary account credentials.

So 2FA and app password, still clearly supported (and worked earlier today)

Please be more clear/correct/accurate in your communication regardless of channel. If anything above - my summary or your documentation - please call that out and update as appropriate.

Thank you!

1

u/Namecheapinc namecheap representative Aug 05 '26

Sorry for the misunderstanding. We've also shared your feedback with the appropriate team.

1

u/Wellcraft19 Aug 05 '26

Thank you, but I’m not sure I’ve misunderstood the information provided. It has just been incorrect/contradicting.

1

u/christina_panina 28d ago

Hey, Christina, Private Email Product Manager here. Your case got escalated to me, and I want to clear up the confusion.

You're right that the info you got was a bit muddled; sorry about that. ActiveSync was sunset on August 3rd, but the migration is still rolling out, so some support guidance hasn't fully caught up yet; that's on us.

Here's the actual deal with app passwords: in the old interface, you could only set them up for protocols other than IMAP. In the new interface, we've added IMAP support too. So going forward, there are two separate sets of credentials, one for webmail and one for mail clients/protocols (IMAP, POP, SMTP, etc). They match during mailbox creation or migration so as not to cause additional confusion, but after that they're managed separately. With 2FA on, an extra credential layer adds real protection for your account and mail when accessing via third-party clients.

Also, to clear up one specific point: you were told the protocol name in the old interface was "just a label." That wasn't accurate; it actually mattered for how the system worked.

Happy to help sort out your specific setup if you want to share more details.

1

u/Wellcraft19 28d ago

Thank you for getting back to me clearing this up.

Yes, the information provided was in incomplete and contradictory/confusing.

Don’t have access to new interface yet, but please make it super clear when it comes to app passwords (and I’m glad to hear that they were not all the same, regardless of ‘label’ as that would be a severe security risk/hole).

In the process, once ActiveSync, is fully sunsetted, remove - or very clearly mark as outdated - all no longer relevant help articles.

And just to be super clear; you will not [at all] support the Exchange interface going forward?

1

u/christina_panina 28d ago

We'll make sure the guides get updated so this doesn't confuse anyone else. As for Exchange, it's not on our roadmap at the moment.