Email Migration: Moving Your Mail to KapsuleHost

How to copy existing mailboxes from another provider into KapsuleHost, mailbox by mailbox, without losing mail or taking your email offline.

Email migration is a self-serve wizard in KPanel. It connects to your current provider over IMAP, copies every folder and message into a KapsuleHost mailbox, and keeps running until you are ready to switch your incoming mail across. It is free on every plan. Your existing mail keeps working the entire time.

Contacts come across too, where your current provider runs a contacts server (CardDAV) that accepts the same mailbox password. The wizard finds your address book, copies every contact into the address book on your new KapsuleHost mailbox, and tells you per mailbox what it found. Gmail and Microsoft 365 keep contacts behind a Google or Microsoft sign-in rather than your mailbox password, so contacts do not come across from those two yet and the migration monitor says so on the mailbox rather than leaving you to notice. Calendars are not part of an IMAP migration and are not moved.

What You Need Before You Start

  • The domain on your KapsuleHost account. See Adding and Connecting Your Domain.
  • A list of the mailboxes you are moving, and the address each should land on here.
  • Login credentials for each source mailbox. Most providers now require an app-specific password rather than the account password, and the wizard shows you the exact steps for yours.
  • Room on your plan. The wizard compares the number of mailboxes you are adding against your plan's mailbox capacity and will tell you if you are over.

The email migration wizard in KPanel

Step 1: Your Domain

Go to Migrations, choose the email option, and enter your email domain. The wizard looks up your current MX records and works out who you are moving from, so you usually do not have to tell it. It shows the detected provider and how confident it is.

Step 2: Connect to Your Current Host

Pick your provider from the list. Google Workspace, Microsoft 365, iCloud, Yahoo, Zoho and Fastmail are all recognised, along with a generic cPanel option and a plain IMAP option for anything else.

Choosing a known provider fills in the IMAP host, port and encryption for you, and tells you whether that provider needs an app password. If it does, the wizard gives you the steps and a direct link to the right settings page. For a generic IMAP source you supply the host yourself, normally port 993 with implicit TLS.

Generate the app passwords before you start the wizard, not during it. Several providers make you log in again and confirm a second factor to create one, which is annoying halfway through a form.

Step 3: List the Mailboxes

One row per mailbox. Each row has three fields:

  • Source address, the address as it exists on your old host.
  • Destination on KapsuleHost, where it should land here. It does not have to be the same local part, so you can tidy up naming as you move.
  • Source password or app password, for that specific mailbox.

Then test each row. The test makes a real IMAP connection and reports back how many folders and how many messages it found. This is the most useful thing in the whole wizard: it proves the credentials work before you commit, and the message count tells you roughly how long the copy will take.

You cannot continue until every row tests successfully. A failed test names the reason, and the usual causes are an ordinary password used where an app password is required, IMAP switched off on the source account, or the wrong host.

Passwords you enter are encrypted at rest and kept only while the migration needs them: for the copy, and for the 24 hours after you switch your mail across, while we keep collecting from your old mailbox. They are wiped the moment the migration completes, fails or is cancelled. Even so, revoke or change the app passwords at your old provider once the migration is done.

Step 4: Cutover

Cutover means changing the MX records for your domain so new mail starts arriving at KapsuleHost instead of your old host. It is a separate decision from the copy, and it should be.

You have two choices:

  • I'll change my domain's mail setting myself. The wizard recommends it, and it is the path that puts the timing under your control. You do the copy first, check the mail actually arrived, and only then change MX.
  • Change it for me. Offered when the domain is on your KapsuleHost account and uses Kapsule DNS. The moment the initial copy finishes, we point the MX at KapsuleHost and remove the records pointing at your old provider. Your SPF is added to rather than replaced, your DMARC is left as it is, and your website records are not changed. If the wizard cannot confirm that your domain qualifies, it tells you why and you choose the first option instead.

Step 5: Review and Launch

Confirm the summary and launch. You land on a monitoring page and the sync starts immediately.

Watching It Run

The monitor refreshes itself every few seconds and shows:

  • Mailboxes completed out of the total.
  • Messages copied.
  • Data transferred.
  • When the run started.
  • A progress row per mailbox, with the folders, messages and bytes done so far.

Things worth knowing about how the copy behaves:

  • It never writes to your source. Nothing is deleted, moved or marked read on your old host.
  • Read and flagged states are preserved, along with each message's original date, so your new mailbox looks like your old one rather than a wall of unread mail from today.
  • It is resumable. It checkpoints as it goes, so an interruption picks up where it stopped instead of starting the folder again.
  • A failing folder does not sink the mailbox. It is recorded and the rest continues.
  • Large mailboxes take hours, not minutes. Tens of thousands of messages is a long copy no matter who does it.

While your mail copies, the monitor shows one of three states: "Waiting for you to sign in" (only when a mailbox signs in with Microsoft), "Starting, copying begins within a few minutes", then "Copying messages". Each mailbox shows its own status: "Waiting for sign-in", "Starting", "Copying", "Catching up", "Done", "Partial", "Failed" or "Skipped".

Switching Your Mail Across

When the initial copy finishes, the run moves to Ready to switch.

If you chose Change it for me, we change the MX straight away and the run moves on by itself. If we could not (for example, because the domain has moved off Kapsule DNS since you launched), the monitor tells you why, nothing about your mail has changed, and you can ask us to try again or change the record yourself as below.

If you are changing the record yourself, the monitor shows you the exact MX record to publish, with a copy button.

  1. Publish that MX record for your domain and delete every other MX record. If your DNS is at KapsuleHost, do it on the domain's DNS tab. If your DNS is elsewhere, do it there. See MX Records. If your DNS provider supports our one-click email setup, the monitor also offers a button that makes the change there once you approve it.
  2. Watch the What your DNS says right now panel on the monitor. It asks your domain's own nameservers which MX records they publish, marks each one as KapsuleHost or not, and tells you what is still wrong. Press Check again after each change.
  3. Press I've changed my MX record, finish the migration.

We Check Your DNS Before We Finish

Pressing the button is not taken as proof. We ask your domain's nameservers first, and we go ahead only when every MX record they publish is ours. Otherwise we stop and tell you which case you are in:

  • Other MX records are still there. Ours is published, but so is at least one other. Senders can pick any of them, so some new mail would keep going to your old provider.
  • Your MX does not point at KapsuleHost yet. Every MX record published is someone else's, so new mail is still going to your old provider.
  • There is no MX record at all. Nobody can deliver mail to the domain until you add one.
  • We could not get an answer. That is a failed lookup on our side, not a sign that your records are wrong. Try again in a minute.

Each refusal lists the MX records we saw. Fix them and check again, or choose Finish anyway. If you finish anyway, that choice is recorded on the migration, and any mail that still reaches your old provider after the migration completes stays there and is not copied.

After the Switch: 24 Hours of Collecting

A changed MX record does not reach every sender at once. A mail server that looked up your domain before the change can keep delivering to your old provider for a while, so we keep collecting what it delivers:

  • For 24 hours after the switch, the run shows Copying the last new messages, and every 30 minutes we check your old mailbox and copy anything new that landed there. The monitor shows the time collecting stops.
  • When the 24 hours are up, one last pass runs, the migration is marked Completed, and we email you.
  • Your old mailbox passwords are kept for those 24 hours, because collecting needs them, and are wiped the moment the migration completes. If you cancel during the 24 hours, collecting stops and the passwords are wiped at once.
  • If a mailbox failed, the run does not wait out the 24 hours. It ends straight away, so the monitor can show you which mailbox needs attention.

You do not need to do anything during this time.

Do not change MX before the mailboxes exist and the initial copy has run. Mail sent during a gap where the domain points at a mailbox that does not exist is rejected, and it does not wait around for you.

After the Migration

  • Sign in to webmail and confirm the folder structure and message counts look right. See Webmail.
  • Set up the mailbox on phones and desktops. Use IMAP, not POP3. See Email Client Setup, Mobile Setup and IMAP vs POP3.
  • Check the Deliverability tab on the mailbox and publish SPF, DKIM and DMARC, or your outbound mail will land in spam folders. See SPF, DKIM and DMARC.
  • Recreate forwarders, aliases and any shared addresses. They are configuration, not mail, so they do not copy across. See Email Aliases, Email Forwarding, Distribution Groups and Shared Inboxes.
  • Keep the old account open for a few weeks. It costs little and it is the cheapest insurance there is.

If Something Goes Wrong

  • A connection test fails. Almost always the password type or IMAP being disabled at the source. Regenerate the app password and retest.
  • A mailbox shows Failed. Open the run and read the recorded reason, then start a new run for just that mailbox.
  • Mail stops arriving after cutover. Check the MX record actually published and that nothing else is still claiming the domain. See Email Not Receiving and MX Records.
  • Everything works but goes to spam. That is authentication, not migration. See SPF, DKIM and DMARC.

Quote your migration tracking ID when you open a ticket and support can look at the same run you are looking at. See Opening a Support Ticket.

Was this article helpful?

Still need help?

Our support team is here on business days.

Back to Help Centre