Mail client setup is too hard for non-experts: guided per-device setup flow

open
#0444db1 opened by agent Oct 8

What happened (fleet Phase 9, mx99, 2026-10-08)

Setting up [email protected] on an iPhone took an operator who knows mail servers several tries: - iOS needs host, port, SSL and username/password entered for IMAP and again for SMTP. The SMTP credentials are a separate, easy-to-miss section (“optional”). Left blank, sending fails with iOS’s misleading “The sender address was invalid” (Stalwart answers 503 5.5.1 You must authenticate first). - The app password (~40 characters) is shown once and can’t be viewed or copied again, so filling in the SMTP section meant creating a second app password. Two passwords for one device is confusing, and nothing in the UI explains that one password works for both. - After editing the account, iOS Mail kept failing IMAP with “Network error (DNS -65,554)” on every network (home fiber, 5G, VPN) while SMTP to the same host worked. The server was fine (IMAPS verified over IPv4 and IPv6, no failed logins logged). Deleting the account on the phone and adding it again with a fresh app password fixed it: stale client state, but a non-expert would have been stuck.

Someone who doesn’t know email server settings can’t be expected to get through this.

Wanted

A guided “set up a device” flow in sovrnd, per platform: - Apple (iPhone, iPad, Mac): one tap. A configuration profile with IMAP and SMTP fully filled in and one app password embedded (or entered once): see bug 2b0ddfc. This removes every manual field. - Android / Thunderbird / others: autoconfig (autoconfig., .well-known/autoconfig/mail/config-v1.1.xml) so the client only asks for the address and password; plus a clear manual-settings card (host, ports, SSL, username = the account’s login, same password for incoming and outgoing) with copy buttons. - App passwords: created per device from that flow, named after the device, shown with a copy button and a clear “use this same password for incoming and outgoing” note; the flow carries the password into the profile/config so the user never retypes it. - Troubleshooting notes for the known misleading client errors: iOS “sender address was invalid” = outgoing login missing; persistent iOS IMAP/DNS errors after editing an account = remove and re-add the account (or reinstall the profile). - Show which username the client must use (Stalwart logs the account name “test”, not the full address); decide whether the full address should also work and say so.

Related: 2b0ddfc (Apple configuration profile).