It is common to end up with mail spread across several places: a legacy ISP mailbox nobody migrated, a domain registrar's free email plan, a personal Gmail account someone used for the business early on, and a "proper" Microsoft 365 or Google Workspace tenant added later. Checking all of them separately does not scale, and it is easy for a customer email to sit unread in the account nobody checks any more.
Consolidating means automatically pulling mail from every external account into one place — a server, a mailbox, or an archive — on a schedule, rather than relying on someone to remember to log in.
Each external account is collected using one of two protocols:
- POP3 — downloads what is in the inbox, typically deleting or leaving a copy depending on configuration. Simple, and fine when the source account only matters as a feed into somewhere else.
- IMAP — copies the full folder structure (Gmail labels appear as IMAP folders) and can leave the source account intact for anyone who still needs to use it directly.
For Gmail and Microsoft 365 specifically, use OAuth2 rather than storing the account password. Both providers are steadily restricting plain password ("basic") authentication for third-party apps, and a stored password is also a bigger security liability than a revocable OAuth token.
For each external account you want to pull in, decide:
- Protocol. IMAP if you need folders/labels or must leave the source mailbox usable; POP3 if you only need the inbox and intend to empty it.
- Schedule. A one-minute poll is normal for a business feed; IMAP IDLE (push) is faster still if the collector supports it.
- Delete policy. Delete on the source once collected, leave a copy, or expire after N days — this depends entirely on whether anyone else still needs to see that account directly.
- Destination. A specific mailbox, a routed address based on who the mail was originally sent to, or an archive if the goal is a searchable record rather than a live inbox.
There are two different things people mean by "connect multiple accounts":
- Unified reading with separate identities. Mail from each account stays addressed to the right person or department; the collector is just plumbing that gets it into your own server so you are not relying on gmail.com or a registrar's webmail as the daily driver.
- True consolidation into one inbox. Everything lands in a single mailbox regardless of source, usually because one person is covering several old addresses. This is convenient but makes it harder to tell which original address a customer used, so keep the original To/From headers intact rather than rewriting them.
Either is legitimate. The mistake is doing it by accident — routing rules that were never really decided on tend to silently misfile mail until someone notices a missing reply weeks later.
A few mistakes show up repeatedly when people wire this up for the first time:
- Deleting on the source when someone else still checks it. If two people can log into the same ISP webmail, deleting on download will silently steal mail from the other person.
- Catch-all collection with no split logic. Pulling a catch-all account wholesale into one destination mailbox mixes customer mail from every address on the domain together.
- Password-based auth against Gmail or Microsoft 365. This breaks without warning as each provider tightens basic-auth restrictions; use OAuth2 from the start.
- No monitoring on the collector itself. If the collector's own credentials expire or an OAuth token is revoked, mail silently stops arriving with no obvious symptom until someone asks "did you get my email?"
Hexamail POP3 Downloader is built specifically for this job: it collects from any number of POP3 or IMAP accounts (including Gmail and Microsoft 365 via OAuth2) on independent schedules, supports IMAP IDLE, Gmail labels, and per-account delete/leave/expire policy, and can split catch-all mail by the original recipient header before delivering it into Hexamail Server, Exchange, or any SMTP server via standard SMTP.