Migrate from Zoho Mail to JustEmails: Step-by-Step IMAP Guide
Zoho Mail to JustEmails: IMAP sync, MX cutover, DKIM rotation — complete runbook.
Zoho Mail to JustEmails: IMAP sync, MX cutover, DKIM rotation — complete runbook.
The Zoho renewal email landed on a Thursday morning. Fourteen mailboxes at $1/month each — not terrible. But then I counted the role accounts. Support@, billing@, careers@, press@, info@, three different brand domains with their own hello@ addresses. Suddenly "cheap per-user" meant $37/month, and that number would only climb.
Look, I ran the math on Zoho vs flat-fee email three different ways before pulling the trigger. (If you want that comparison, we wrote up the full JustEmails vs Zoho Mail breakdown already.) The economics made sense for us. What I couldn't find anywhere was a Zoho-specific migration runbook — the Google Workspace ones are everywhere, but Zoho? Crickets.
So here's the guide I wish existed. We're the JustEmails team, part of Velocity Digital Labs. We've done this migration ourselves and walked customers through it. Zoho has some quirks — the two-factor app password dance, the IMAP server naming that isn't obvious, the way their DNS records look different from Google's — and we'll cover all of them.
All your email history moved to JustEmails. MX records pointing to our servers. SPF, DKIM, and DMARC configured and passing authentication checks. Mail-tester.com scores in the green. Your team using the same addresses, same folders, same email clients — just a different backend.
One thing you won't have: Zoho's calendar and contacts. We're email-only. If you're deep in Zoho Calendar for scheduling, plan to export that separately. (I'll flag this again later because people forget.)
Before starting, make sure you have:
That last one trips people up. Zoho requires app-specific passwords when 2FA is on — your regular login password won't authenticate IMAP connections. Generate these before day one: Zoho Account → Security → App Passwords → Generate New Password.
I spent forty-five minutes debugging "authentication failed" errors before realizing this. Don't be me.
Know the sending ceiling before you set a cutover date. The per-account cap is 20/day for the first week, 200/day in the second, and 500/day from day 15 on, with mailbox sends and API sends counted against the same number. Warm-up is measured from domain verification rather than signup, so a domain added to a long-standing account starts back at the bottom of that ramp. The imapsync transfer is unaffected — this governs mail you send once MX moves.
Log into JustEmails. Add your domain — the verification is a simple TXT record, takes about five minutes for DNS to propagate.
Create a mailbox for every address you're migrating. Match them exactly: if alex@yourcompany.com exists in Zoho, create alex@yourcompany.com in JustEmails. Same for role accounts. JustEmails includes unlimited mailboxes on the $49/year plan, so create all of them now — support@, billing@, info@, whatever you've got.
Write down the IMAP credentials for each mailbox. You'll need these for imapsync.
Don't touch MX records yet. We're not cutting over today.
imapsync is the tool. It copies mail between IMAP servers, preserving folders, dates, read/unread flags, everything. Installation is straightforward.
On Ubuntu/Debian:
sudo apt update && sudo apt install imapsync
On macOS with Homebrew:
brew install imapsync
(Windows users: WSL works fine. Native Windows? Possible, but annoying. Just use WSL.)
Verify it's installed:
imapsync --version
Now the actual sync. Zoho's IMAP server is imappro.zoho.com (or imap.zoho.eu if you're on the EU region — check your Zoho admin panel). Here's the command template:
imapsync \
--host1 imappro.zoho.com --port1 993 --ssl1 \
--user1 "alex@yourcompany.com" --password1 "zoho-app-password" \
--host2 mail.justemails.app --port2 993 --ssl2 \
--user2 "alex@yourcompany.com" --password2 "justemails-password" \
--automap
Run this for each mailbox. For multiple accounts, we use a CSV and a bash loop:
while IFS=, read -r user zpass jpass; do
imapsync \
--host1 imappro.zoho.com --port1 993 --ssl1 \
--user1 "$user" --password1 "$zpass" \
--host2 mail.justemails.app --port2 993 --ssl2 \
--user2 "$user" --password2 "$jpass" \
--automap
done < users.csv
The CSV format: email,zoho-app-password,justemails-password. One row per mailbox. Not fancy, but it works.
First sync can take hours depending on mailbox size. A 3GB mailbox took us about 90 minutes over a decent connection. Let it run. Go get lunch. imapsync is resumable — if it dies (and it will, eventually, for someone reading this), run the same command again. It picks up where it stopped.
This step is boring and critical. Don't skip it.
Your MX records have a TTL (time-to-live) — probably something like 3600 (1 hour) or 14400 (4 hours). When you change MX records, some servers will keep using the old cached values until the TTL expires.
In your DNS panel:
Now wait. At least as long as your old TTL, ideally 24 hours. I know that feels excessive. It's not. Mail servers cache aggressively, and enterprise servers cache more aggressively than that. The alternative is mail going to Zoho for hours after you thought you'd cut over. Ask me how I know. (Don't actually ask me. It was a bad day.)
While waiting, grab the JustEmails DNS records from your domain settings — MX, SPF, DKIM. You'll need them tomorrow.
This is the day. Take a breath.
Delete your Zoho MX records:
mx.zoho.com (priority 10)
mx2.zoho.com (priority 20)
mx3.zoho.com (priority 50)
(Or mx.zoho.eu, etc., depending on your region.)
Add the JustEmails MX record. Zoho hands you three; JustEmails uses a single host, which you'll find in your dashboard:
mail1.justemails.app (priority 10)
Check the exact value in your JustEmails domain settings.
Your SPF record probably includes Zoho. It looks something like:
v=spf1 include:zoho.com ~all
Change it to authorise JustEmails instead:
v=spf1 a:mail1.justemails.app ~all
Zoho uses an include; we don't have one. a:mail1.justemails.app authorises the IP behind that host directly. Writing include:spf.justemails.app out of habit is the failure mode here — that name has no TXT record, so the include authorises nothing at all and SPF fails while your DNS panel shows a record that looks perfectly fine.
If you have other senders (Mailchimp, your app's transactional email through something like Resend), keep those includes. Just swap Zoho's for our a: mechanism.
For DKIM, add the new records from JustEmails. They're typically CNAME records:
je1._domainkey.yourcompany.com → je1.dkim.justemails.app
je2._domainkey.yourcompany.com → je2.dkim.justemails.app
Delete the old Zoho DKIM record (zmail._domainkey or similar). Keeping dead DKIM records around doesn't break anything, but it's confusing later.
Here's where people get nervous. Your DMARC policy tells receiving servers what to do when SPF or DKIM fails. During a migration, you might see temporary alignment failures as DNS propagates.
If you're at p=reject, consider temporarily dropping to p=quarantine for a week. If you're at p=none, stay there. Don't tighten policy during a migration.
More importantly: make sure your DMARC aggregate report address (rua=mailto:...) still receives mail. If it was pointing at a Zoho inbox, update it to your new JustEmails address before cutover.
v=DMARC1; p=quarantine; rua=mailto:dmarc@yourcompany.com; fo=1
Watch those reports for the first few days. A spike in authentication failures means something's still sending through old credentials. For the full walkthrough on tightening DMARC post-migration, see our p=none to p=reject guide.
Don't trust "it looks fine." Test it.
Run your domain through MXToolbox:
https://mxtoolbox.com/SuperTool.aspx?action=mx:yourcompany.com
You should see the single JustEmails MX host, mail1.justemails.app, plus valid SPF and valid DKIM. Any warnings should be about propagation timing, not configuration.
Then send a test email to mail-tester.com. They'll give you a score out of 10 covering spam triggers, authentication, blacklist status, content issues. Aim for 9+. If you're below 8, something's misconfigured — usually SPF or DKIM. For ongoing monitoring of your email health, check out our email deliverability guide.
Send test emails from an external account (personal Gmail, Outlook.com) to confirm delivery. Send from your migrated addresses to external accounts and check that they land in inbox, not spam.
Mail that arrived at Zoho between your initial sync and the MX cutover is still sitting in Zoho. Run imapsync again for each mailbox:
imapsync \
--host1 imappro.zoho.com --port1 993 --ssl1 \
--user1 "alex@yourcompany.com" --password1 "zoho-app-password" \
--host2 mail.justemails.app --port2 993 --ssl2 \
--user2 "alex@yourcompany.com" --password2 "justemails-password" \
--automap
Same command as before. imapsync only copies new or changed messages — won't duplicate what's already there. This delta sync is usually fast. Minutes, not hours.
Your team needs new server settings. Here's what they'll enter:
Incoming (IMAP):
Outgoing (SMTP):
Thunderbird, Outlook, Apple Mail, mobile apps — all of them. Honestly? This is the most annoying part of any migration. Not the DNS. Not the DKIM rotation. Helping someone find SMTP settings in Apple Mail on their phone. Budget 10-15 minutes of hand-holding per non-technical team member. More if they're using some ancient Outlook version.
"Authentication failed" on imapsync
Your Zoho app password is wrong, or you generated it for the wrong account. Go to Zoho Account → Security → App Passwords and generate a new one. If you have multiple Zoho accounts, make sure you're logged into the right one.
Zoho IMAP connection refused
Check if you're using the right server. US accounts use imappro.zoho.com. EU accounts use imap.zoho.eu. India uses imap.zoho.in. Australia uses imap.zoho.com.au. The generic imap.zoho.com sometimes works but sometimes doesn't.
Mail still arriving at Zoho after cutover
DNS propagation isn't complete. If your old TTL was high, some servers are still caching. Keep Zoho active and run delta syncs daily until traffic stops. This can take 48-72 hours in stubborn cases.
DKIM fails validation
Wait 15-60 minutes for CNAME propagation. If it still fails, check the record names — it's je1._domainkey.yourcompany.com, not je1.domainkey.yourcompany.com. That underscore matters.
Mail-tester score is low
Usually SPF or DKIM misconfiguration. Make sure you only have ONE SPF record (multiple = automatic fail). Make sure both DKIM CNAMEs are published. MXToolbox's SPF and DKIM lookup tools will tell you exactly what's wrong.
Real talk: JustEmails doesn't replace these. We're email hosting, not a productivity suite. If you've been using Zoho Calendar heavily, you'll need to export and move that elsewhere.
Export Zoho Calendar: Calendar → Settings → Export → Download ICS. Import that ICS into Google Calendar, Apple Calendar, Outlook, whatever you're using next.
Export Zoho Contacts: Contacts → Settings → Export → CSV. Import into your new contacts app.
This is the honest tradeoff. Zoho bundles a lot of productivity tools. We bundle transactional email API instead. Different use cases. If calendar integration is critical, you might want to evaluate that before migrating — I'd rather you know that now than resent us later. We cover this tradeoff in more detail in our Zoho Mail comparison post.
Don't cancel Zoho Mail immediately. Even after MX cutover, some slow mail servers might still deliver to Zoho. Keep your Zoho account active (free tier is fine — downgrade if you want to stop paying) and run imapsync weekly for a month.
At day 30, log into Zoho, verify no new mail is arriving, revoke those app passwords you created, and close the account. Feel that tiny dopamine hit of canceling yet another subscription.
Once the migration settles:
p=quarantine to p=reject once you've confirmed everything's authenticating cleanlyFor analytics across your domains, JustAnalytics gives you a unified view — track email opens and engagement alongside your web traffic. And if you're spending on paid ads, ClickzProtect handles click fraud detection — we built it after watching bot traffic drain ad budgets across client domains. Need a secure browser for managing client credentials during migrations? JustBrowser isolates sessions so you're not accidentally logged into the wrong Zoho account.
Questions? support@justemails.app. We answer email. (That's kind of our thing.)
Yes. If you have two-factor authentication enabled on your Zoho account (and you should), regular passwords won't work with IMAP. Go to Zoho Account → Security → App Passwords and generate one specifically for imapsync. Label it something like 'migration-imapsync' so you remember to revoke it after the move is done.
Plan for 4-5 days total. Day 1 is account setup and initial IMAP sync. Day 2 is TTL lowering and DNS prep. Day 3 is the MX cutover. Days 4-5 are delta sync, verification, and cleanup. Actual hands-on work is 2-3 hours spread across that window — the rest is waiting for DNS propagation and catching any mail that sneaks through to Zoho.
No — imapsync preserves folder hierarchy. Zoho uses standard IMAP folder names, so the mapping is cleaner than Gmail. Your Inbox, Sent, Drafts, and custom folders transfer directly. The only edge case is Zoho's 'Views' feature (smart folders like Unread, Flagged) — those are server-side filters and won't migrate as folders, but your actual mail and folder structure stays intact.
JustEmails is email-only — we don't include calendar or contacts sync. Export your Zoho Calendar to ICS and import it into Google Calendar, Apple Calendar, or whatever you're moving to. Export contacts as a CSV from Zoho Contacts and import them into your new contacts app. This is the tradeoff: Zoho bundles productivity tools, JustEmails focuses purely on email hosting. If you rely heavily on Zoho Calendar for scheduling, plan that migration separately.
Unlimited custom domain email hosting for $49/year flat — unlimited domains, unlimited mailboxes, 10 GB storage, full IMAP/SMTP. Built for agencies, freelancers, and anyone managing email across more than one domain.