Finocket can send on its own included accounts with nothing to set up. When you'd rather use your own provider accounts — your sender identity, your reputation, your provider bill — those keys live in one place: Settings → Connected keys. That screen lists every provider account this workspace holds, tells you whether each one still works, and lets you revoke any of them.
Why a key that says “verified” can still be broken
A key is proven the day you save it. If you later rotate or delete it at the provider, nothing in Finocket changes on its own — the row still says verified, and the first sign of trouble is a campaign that quietly didn't send. That's the gap Connected keys closes. Check it still works asks the provider, right now, and records the answer: when it last verified, when it last carried real traffic, and what the provider said if it refused.
- Email is checked by sending one short test message to your own address — never to a customer.
- WhatsApp and SMS are checked without sending anything: Finocket asks the provider about the account, which proves the key without spending a message or needing an approved template.
- Mailboxes are checked by logging in over IMAP and SMTP, exactly as when you connected.
Nobody can read your keys — including us
Keys are encrypted before they are stored and are never shown again after saving. Connected keys shows the provider name, the connection method, and the dates — never the key itself. That is true for Finocket support and platform administrators too: the internal view they have shows exactly the same information you see here and nothing more. If you lose a key, you replace it; there is no way to look it up.
Accountants and read-only team members never see this screen's actions at all, and a workspace-wide key can only be changed by the workspace owner.
Two ways to connect a mailbox
Under Settings → Sending & deliverability you can connect a mailbox either way. They are alternatives, not replacements — an existing connection keeps working exactly as before.
Signing in (OAuth)
You sign in on Google's or Microsoft's own screen and Finocket receives an encrypted token. Your password is never seen or stored, and you can cut Finocket off instantly from your Google or Microsoft account's security settings. This route is send-only: it does not read your mailbox.
An app password (IMAP/SMTP)
You give Finocket a mail server, a username and an app password. This is the only route for Zoho Mail, Fastmail and your own mail server, which sign-in never covered, and it is the route that can read a mailbox as well as send from it.
- Gmail needs 2-Step Verification switched on. Google only offers app passwords to accounts with 2-step verification enabled — with it off, there is no app password to generate. Turn it on first, then create one.
- Outlook and Microsoft 365 cannot use an app password. Microsoft has retired basic authentication for Exchange Online, so IMAP and SMTP with a password no longer work there at all. Use the Microsoft sign-in button — it is the only route that works, and Finocket won't offer you a form that can't succeed.
- Other mailboxes: ask your mail host for the IMAP and SMTP server names. They are usually not the same as your website's domain.
Nothing is saved until it is proven. Connecting performs a real IMAP login and a real SMTP login; if either is refused, nothing is stored and you see the mail server's own reason so you can fix it. Finocket also refuses to send your password over an unencrypted connection, so a server that won't use TLS is rejected rather than quietly downgraded.
Replacing and revoking
- Replace a key on the screen that owns it (outreach providers, AI providers, sending & deliverability). Saving a new key over an old one clears the verified flag, so the new one has to prove itself before anything sends on it.
- Revoke deletes the key from Finocket immediately. Sending falls back to the included transport — it does not stop. Revoking here does not cancel the key at the provider; do that in the provider's own dashboard if you want it dead everywhere.
- Consent, unsubscribe and suppression checks are identical whichever account you send from. Bringing your own key changes the transport, never the rules.
