One-step mail setup on Apple devices: configuration profile (.mobileconfig) for an app password
openProblem
Setting up a mailbox on iPhone means typing the same app password (40 characters) twice: once for IMAP and again for SMTP, which iOS keeps separately and often leaves blank. Without SMTP credentials iOS submits unauthenticated, Stalwart answers 503 5.5.1 You must authenticate first, and iOS reports “The sender address was invalid” (seen on mx99, 2026-10-08, with [email protected]).
Proposal
sovrnd generates an Apple configuration profile when the user creates an app password: a “Set up iPhone / iPad / Mac” button next to the new password.
- One EmailAccount payload: IMAP
| :993 SSL, SMTP | :587 (or 465) SSL, username, IncomingMailServerAuthentication/OutgoingMailServerAuthentication = EmailAuthPassword, EmailAddress, display name. | - Password handling, default: embedded (IncomingPassword + OutgoingPasswordSameAsIncomingPassword = true): installing the profile is the whole setup. The profile is then a secret: generate on demand for the signed-in user only, serve over HTTPS with Content-Type application/x-apple-aspen-config and Cache-Control no-store, never store or email it; ideally a single-use, short-lived download URL tied to the session.
- Fallback option: no embedded password, OutgoingPasswordSameAsIncomingPassword = true, so iOS asks once at install and uses it for both.
- Phone delivery: tap the button on the phone; from a computer, show a QR code for the single-use URL.
- Signing (optional, recommended for customers): sign the profile (CMS) with the cell’s TLS certificate so iOS shows Verified instead of Unsigned.
- Use the cell’s own hostname (sovrn.cell.hostname); the IMAP username is what Stalwart expects for the account (on mx99 the IMAP login is account “test”).
Related, separate
Thunderbird/K-9/etc. autoconfig (autoconfig.
Found during fleet Phase 9 (mx99 acceptance).