Proton Mail keeps your inbox encrypted end to end, which is exactly why a normal desktop client cannot just plug into it over IMAP — there is nothing for Thunderbird or Outlook to read without breaking the encryption. Proton Mail Bridge is the answer: a small app that runs an encrypted IMAP/SMTP server on your own machine. I set Bridge up with Thunderbird myself, and once you understand that the credentials live inside the Bridge app rather than on a remote Proton server, the whole thing takes about ten minutes. Here is the full setup, the real settings, and the one rule people forget.
What Bridge Actually Does
Proton Mail Bridge is a desktop app that adds end-to-end encryption to popular email apps. It runs a local IMAP/SMTP server on your computer and encrypts and decrypts messages as they enter and leave your machine, so a standard client like Thunderbird, Outlook, or Apple Mail can use a Proton account without breaking Proton’s encryption.
The reason Bridge exists comes down to how Proton differs from Gmail or a generic IMAP host. With most providers, your client connects straight to the provider’s servers, downloads readable messages, and that is that. Proton does not work that way — your mail is stored encrypted, and decryption happens with keys only you hold. A plain IMAP connection to Proton would hand your client a pile of ciphertext it cannot read.
Bridge solves it by moving the decryption onto your own device. Per Proton, the app encrypts and decrypts messages as they enter and leave your computer, presenting your client with a normal-looking local mail server. Your client talks to Bridge over the loopback connection; Bridge talks to Proton over the encrypted channel. The practical upshot: Thunderbird sees ordinary IMAP folders, you read and send as usual, and the privacy model stays intact because the plaintext never leaves your machine. Proton also notes your passwords never leave your machine and that it never permanently stores your PGP keys or decrypted message data on disc.
Prerequisites: A Paid Plan
Bridge requires a paid Proton plan that includes Proton Mail — a free account cannot use it. You also need a supported desktop operating system (Windows, macOS, or Linux) and an email client such as Thunderbird, Outlook, or Apple Mail. The Bridge app itself is a free download once you are on a paid plan.
Before installing anything, confirm two things. First, the plan. Proton states plainly that Bridge is available only with a paid plan that includes Proton Mail, so a free Proton account will not be able to connect a desktop client this way — the web and mobile apps are the only access for free users. If desktop IMAP is the goal, the paid tier is the entry fee.
Second, the client and the operating system. Proton lists Microsoft Outlook, Apple Mail, and Mozilla Thunderbird as supported on all popular operating systems, and the Bridge installer ships for Windows, macOS, and Linux. Thunderbird is the cleanest pairing for most people because it is free, cross-platform, and handles manual server settings gracefully — if you are weighing clients first, our guide on how to migrate to Thunderbird walks through the move. With the plan confirmed and a client in mind, the install is quick.
Install Proton Mail Bridge
Download Proton Mail Bridge from proton.me for your operating system and run the installer. Then open Bridge and add your account by signing in with your normal Proton email and password, plus a two-factor code if you use one. Bridge logs in once and keeps a local connection so your client never talks to Proton’s servers directly.
The install is conventional. Grab the Bridge build for Windows, macOS, or Linux from Proton’s site and run it like any other desktop app. There is no browser extension and no account to create beyond the Proton account you already have.
The first run is where Bridge does its real work. Open the app and choose to add your account, then sign in with your Proton Mail credentials — the same email and password you use on the web, and your second factor if two-factor authentication is on. Proton’s installer walks this with a setup wizard. Bridge authenticates once, establishes the encrypted link to Proton, and from then on stands in as a local mail server on your machine. Crucially, this sign-in is the only place your real Proton password is entered; your email client never sees it, because Proton Mail Bridge uses a unique password that is different from your login password and never leaves your computer.
Get Your Bridge Credentials
In Bridge, select your account and open Mailbox Details. Bridge shows the local server address, the IMAP and SMTP ports, your username, and a unique Bridge password that differs from your Proton login password. Those exact values — and the Bridge password, not your Proton password — are what you enter in your email client.
This is the step that trips people up, because the settings are not on a Proton help page — they live inside the running Bridge app, generated for your machine. Select your account in Bridge and open the Mailbox Details panel.
There you will find everything the client needs:
- Server address — the local loopback host on your own computer, since Bridge runs the server on your machine rather than a remote Proton box.
- IMAP port — the local port your client uses to read mail. Copy it exactly as Bridge displays it.
- SMTP port — the local port your client uses to send. Again, use the value shown.
- Username — usually your Proton email address.
- Bridge password — a unique string generated by Bridge. This is the credential your client authenticates with, not your Proton login password.
Copy these verbatim; a single transposed digit in a port number is the most common reason a Bridge setup fails to connect. Keep the Bridge window open while you configure the client so you can refer back to the panel.
Configure Thunderbird
In Thunderbird, add a new account and enter the IMAP server, SMTP server, ports, username, and Bridge password exactly as Mailbox Details shows them. If Thunderbird does not auto-detect the local server, choose Configure manually. When prompted, accept the Bridge security certificate for both the IMAP and SMTP connections.
Thunderbird is the reference setup because it exposes manual server fields cleanly. Open Account Settings → Account Actions → Add Mail Account, enter your name and Proton email, and paste the Bridge password rather than your Proton account password when Thunderbird asks.
Thunderbird may try to detect settings automatically. Per Proton’s client guidance, if it does not find the local Bridge server, click Configure manually and type the IMAP and SMTP servers and ports straight from Mailbox Details. Because Bridge presents a local server with its own certificate, Thunderbird will warn about the security certificate the first time it connects — Proton’s setup expects this, and you confirm the certificate exception for both the IMAP and the SMTP connection. Once accepted, Thunderbird downloads your folders and you are live. If you want to tame the inbox afterward, the same client handles rules well; our Thunderbird filters setup and Thunderbird spam filter setup guides pick up from here.
Configure Outlook or Apple Mail
Outlook and Apple Mail follow the same pattern as Thunderbird: add an account manually, enter the IMAP and SMTP servers, ports, username, and Bridge password from Mailbox Details, and accept the Bridge certificate. Proton’s setup wizard can pre-fill these in some versions, but the credentials always come from the Bridge app.
The logic does not change across clients — only the menu layout does. Proton lists Outlook and Apple Mail alongside Thunderbird as supported, and the Bridge setup wizard offers per-client help so the steps match each app’s interface.
In Outlook, add an account and choose manual or advanced setup so you can enter the local IMAP and SMTP servers and the Bridge password rather than letting Outlook guess at Microsoft-style autodiscovery. In Apple Mail, add an “Other Mail Account,” then fill the incoming and outgoing server details from Mailbox Details. Both clients, like Thunderbird, will surface a certificate prompt for the local Bridge server — accept it for incoming and outgoing. The single constant across all three is that the server, ports, and password come from Bridge’s Mailbox Details, never from a generic IMAP cheat sheet. If you are setting up a different IMAP client entirely, the mechanics are identical to a normal provider once Bridge is the host — our Mailbird IMAP setup guide shows the same manual-server flow in another app.
Troubleshooting and Limits
Most Bridge problems come from three causes: Bridge is not running, a port number was mistyped, or the certificate was rejected. Bridge must stay open in the background for the client to sync; the server address and ports must match Mailbox Details exactly; and the Bridge certificate must be accepted for both IMAP and SMTP. Fixing those resolves nearly every failure.
Bridge is reliable once configured, but its design imposes a few honest limits worth knowing up front:
- Bridge must stay running. This is the rule people forget. Bridge is the local server, so if you quit it, the IMAP and SMTP connection dies and your client shows errors until you reopen it. Set Bridge to start on login and run in the background.
- Ports must match exactly. Bridge picks local ports and displays them in Mailbox Details. If your client cannot connect, re-check the IMAP and SMTP port numbers against the panel — a single wrong digit breaks it. If another local app already holds a port, Bridge can reassign it, so trust the current Mailbox Details value over one you wrote down earlier.
- The certificate prompt is expected. Because Bridge serves locally with its own certificate, clients flag it the first time. Accept the exception for both connections; declining it blocks the setup.
- Use the Bridge password. Entering your Proton login password instead of the generated Bridge password is the second most common failure. They are deliberately different.
If sync still stalls after checking all four, restarting Bridge and the client clears most transient connection issues, since the whole link re-establishes from scratch.
Verdict
Proton Mail Bridge is the only way to use a Proton account in a desktop IMAP client, and it works well once set up: install Bridge, sign in, copy the server, ports, and Bridge password from Mailbox Details, and add the account in your client. It needs a paid plan and must stay running, but it keeps Proton’s end-to-end encryption fully intact.
Best for: paid Proton users who want their encrypted mail inside Thunderbird, Outlook, or Apple Mail instead of the web app — anyone who prefers a desktop client, manages multiple accounts in one place, or needs offline access while keeping Proton’s privacy model. Bridge is the bridge, literally, between Proton’s encryption and the conventional IMAP world.
Skip if: you are on a free Proton plan, since Bridge requires a paid tier, or you are happy in the Proton web and mobile apps and never need a third-party client. For those users the extra background app earns nothing.
Install Bridge, pull the exact server, ports, and Bridge password from Mailbox Details, point your client at the local server, accept the certificate, and keep Bridge running. Do that and a Proton account behaves like any other IMAP mailbox on your desktop — with the encryption that made you choose Proton still doing its job underneath.

Alexis Dollé, email expert for 10+ years. Founder of Email Tools. I test every email client and utility myself, then write about them the way I’d explain them to a friend — no marketing fluff, no sponsored rankings, every claim sourced.
LinkedInSources & references
- Proton, “Proton Mail Bridge” — Bridge adds end-to-end encryption to popular email apps, runs a local IMAP/SMTP server, encrypts and decrypts messages as they enter and leave your computer, is available only with a paid plan that includes Proton Mail, uses a unique Bridge password that never leaves your computer, and never permanently stores PGP keys or decrypted data on disc. Accessed 2026-06-19. proton.me/mail/bridge
- Proton Support, “Installing Proton Mail Bridge” — download the Bridge app, add your account, and configure Outlook, Thunderbird, or Apple Mail via the setup wizard. Accessed 2026-06-19. proton.me/support/protonmail-bridge-install
- Proton Support, “Configuring your client with Bridge (Thunderbird on Windows)” — enter the details from the Bridge Mailbox Details section, use the Bridge password rather than your account password, and confirm the security certificate for the IMAP and SMTP connections. Accessed 2026-06-19. proton.me/support/protonmail-bridge-clients-windows-thunderbird
Frequently Asked Questions
What is Proton Mail Bridge and why do I need it?
Proton Mail Bridge is a desktop app that adds end-to-end encryption to popular email apps. It runs a local IMAP/SMTP server on your computer and encrypts and decrypts messages as they enter and leave your machine, so a standard client like Thunderbird or Outlook can use a Proton account without breaking Proton’s encryption. You need it because Proton does not expose normal IMAP/SMTP directly — Bridge is the secured local relay that makes desktop access possible.
Do I need a paid Proton plan to use Bridge?
Yes. Proton states that Bridge is available only with a paid plan that includes Proton Mail. Free accounts cannot use Bridge and are limited to the Proton Mail web app and mobile apps. If desktop IMAP access through Thunderbird, Outlook, or Apple Mail is the goal, a paid plan is the prerequisite.
What IMAP and SMTP settings does Proton Bridge use?
Bridge runs the server locally on your own machine, so the host is your local loopback address rather than a remote Proton server. The exact server address, IMAP port, SMTP port, username, and the unique Bridge password are all shown in the Mailbox Details section of the Bridge app. Copy those values into your client exactly — and use the Bridge password, not your Proton login password.
Why does the Bridge password differ from my Proton password?
By design. Proton Mail Bridge uses a unique password that is different from your login password and never leaves your computer. The Bridge password authenticates only the local connection between your email client and the Bridge app, so your real Proton credentials are never stored in the client. If you reset the Bridge password, update it in your client too.
Does Bridge have to stay running all the time?
Yes, whenever you want the client to sync. Bridge is the local server your client connects to, so if Bridge is closed the IMAP and SMTP connection drops and mail stops flowing until you reopen it. Set Bridge to launch on startup and run in the background so the client always finds it. When Bridge is running, email passes through the encrypted local relay normally.
Does using Bridge keep Proton’s end-to-end encryption intact?
Yes. Bridge decrypts incoming mail and encrypts outgoing mail locally on your device, and Proton notes that your passwords never leave your machine and that it never permanently stores your PGP keys or decrypted message data on disc. The decryption happens on your computer, not on a third-party server, so the security model that makes Proton private stays in place while you use a conventional desktop client.
Related: How to migrate to Thunderbird — the cleanest free client to pair with Bridge. Thunderbird filters setup — sort your Proton mail once it syncs. Mailbird IMAP setup guide — the same manual-server flow in another desktop client.