SingleSign Mail on Your Phone
There are two ways to use SingleSign Mail on your phone, and both live in one place: Settings → Phone & apps.
- The home-screen app — install the SingleSign Mail web app on your home screen. Full-screen mail, swipe actions, pull-to-refresh, and every protection intact. This is the recommended way.
- Your phone's built-in mail app — connect Apple Mail or any IMAP mail app with an app password. Your mail shows up next to your other accounts, still protected.
You can use either, or both.
Everything on this page is per mailbox. If you have a personal mailbox and a company mailbox, each one is added to your phone separately, with its own app password — see More than one mailbox below.
Option 1: The home-screen app
Open Settings → Phone & apps and look for "Put your inbox on your home screen". If your browser supports it, a one-tap "Install" button does everything. On a desktop computer, you'll see a QR code instead — point your phone's camera at it and, after you sign in, this setup screen opens right on your phone.
Manual steps, if you'd rather:
iPhone / iPad (Safari only — other browsers can't install apps on iPhone):
- Open email.singlesign.com in Safari.
- Tap the Share button — the square with an arrow at the bottom of the screen.
- Scroll down and tap "Add to Home Screen".
- Tap "Add". SingleSign Mail appears on your home screen and opens full-screen, like any other app.
Android:
- Open email.singlesign.com in Chrome.
- Tap the ⋮ menu in the top-right corner.
- Tap "Add to Home screen" (on some phones it says "Install app").
- Confirm "Install". SingleSign Mail appears in your app drawer and home screen.
Option 2: Your phone's built-in mail app
Prefer Apple Mail or another IMAP app? Two quick steps in Settings → Phone & apps.
Step 1 — Create an app password
App passwords let mail apps sign in to your mailbox without your real SingleSign password.
- Under "Create an app password", click "Create app password" and give it a label (e.g. "Joseph's iPhone").
- The password is shown once — copy it or save it right away. It won't be shown again.
One app password is active at a time, per mailbox. Creating a new one replaces the previous password everywhere for that mailbox — any device still using the old one is signed out within seconds and needs the new password. All of your devices share the one active password. You can also "Revoke" it at any time, which immediately signs out every connected mail app.
Step 2 — Add the account on your phone
iPhone — one-tap profile:
- Tap "Download iPhone profile".
- Open the downloaded profile: Settings app → Profile Downloaded → Install. (The profile is unsigned, so iOS may label it "Unverified" — that's expected.)
- Enter your app password when Mail asks for a password.
Android & other apps — manual settings. Any IMAP mail app works; add an account manually with:
| Setting | Value |
|---|---|
| Incoming (IMAP) | email.singlesign.com, port 993, SSL/TLS (not STARTTLS) |
| Outgoing (SMTP) | email.singlesign.com, port 465, SSL/TLS (not STARTTLS) |
| Username | the address of the mailbox you're adding — you@singlesign.com, or you@yourcompany.com for a company mailbox |
| Password | that mailbox's app password |
More than one mailbox
Your personal @singlesign.com mailbox and each company mailbox are separate mailboxes with their own app passwords, so your phone sees them as separate accounts:
- In the web app, switch to the mailbox you want on the phone — click your avatar in the top-right corner and pick it.
- Open Settings → Phone & apps — the page says which mailbox you're in — and create an app password for it.
- Add the account on your phone with that mailbox's address as the username. Then repeat for the next mailbox.
The home-screen app needs no repeating: it has the same account menu as the web app, so every mailbox you're signed in to is one tap away, and All inboxes reads them together. See Your Accounts & Organizations.
If your access to a company mailbox ends, its app password stops working at the same moment — remove that account from your phone. Your personal mailbox on the same phone carries on.
What reaches your phone
Your mail stays protected in these apps too:
- Only Screener-approved mail syncs. Mail waiting in the Screener — and anything screened out, spam, or trashed — never appears on your phone.
- Messages arrive as protected copies: tracking pixels are stripped, and links go through Link Guard.
- Mail you send from the phone goes through the same outbound pipeline as the web app — it lands in your Sent conversation, threads correctly, and gets the same delivery metrics.
How sync works
Reads and deletes sync both ways between web and phone:
- Web → phone changes arrive within seconds. Phone → web changes arrive within about 5 minutes.
- Deleting on the phone moves the message to your web Trash — even the phone's own "delete forever". Nothing is permanently destroyed from a phone; permanent deletion ("Delete forever" and "Empty trash") happens only from the web app.
- Reading a message on your phone marks it read on the web, and vice versa. The one exception: marking a message unread on the phone doesn't sync back — mark it unread on the web instead.
Sending limits for mail apps
Mail sent through a connected mail app has its own limits — up to 50 recipients per hour and 100 recipients per day. See Privacy & Protections for how limits work.
Last updated: 2026-09-10
Related articles
- Help CenterFind answers about using SingleSign to sign in, manage your privacy, and secure your account.
- Mobile app authenticationMobile app authentication for iOS and Android: Authorization Code with PKCE in a system browser, custom scheme redirects, and secure token storage on device.
- free identity providerSingleSign pricing in one line: sign-in is free, with no monthly-active-user meter. See exactly what is included, and what SingleSign Mail costs for businesses.
- Identity provider alternativesIdentity provider alternatives, by the provider you are leaving: what actually has to change in your code, and what does not.
- Auth0 comparisonSingleSign vs Auth0 compared on the difference that matters: who owns the account. A side-by-side table, then the three cases where each one is the right call.
- Okta comparisonSingleSign vs Okta: Okta is built for workforce identity inside a company, SingleSign for consumer sign-in across applications.
- SingleSign vs Firebase AuthenticationSingleSign vs Firebase Authentication on lock-in, portability and consent, plus the cases where staying on Firebase is right.
- Google Sign-In alternativeSingleSign vs Google Sign-In: the same one-tap convenience, without an advertising business behind the identity.
- alternative to Auth0Auth0 alternatives compared, plus the part most listicles skip: what migrating off Auth0 actually involves, which code changes, and which does not.
- Okta alternativesOkta alternatives for teams that need customer sign-in rather than workforce identity. The table first, then what changes when you move consumer auth off Okta.
- alternative to Firebase AuthFirebase Authentication alternatives for teams leaving Google Cloud or wanting a standalone OIDC provider. Comparison table, then the real migration path.
- SaaS single sign-onSSO for SaaS applications using OAuth 2.0 and OpenID Connect: the flow to pick, the scopes to request, and a working integration path with SingleSign.