This guide shows you how to change the password on an existing email mailbox in the ISPConfig control panel on your Noiz hosting account, and, more importantly, what to do straight afterwards so that your mail keeps arriving. The mailbox password is the one credential that every device and app uses to collect and send mail for an address such as [email protected] (an example: use your own address). You may see it called the email password, the IMAP or POP password, the SMTP password or the webmail password. They are all the same single password, which is why changing it has a wider reach than most people expect. If you are creating a mailbox for the first time rather than changing one, start with How to Create an Email Mailbox in ISPConfig instead.
This is not your ISPConfig panel password. Your ISPConfig login, each mailbox, and your Noiz client area (billing) login are three separate credentials that only match if somebody deliberately set them the same. Changing one does not change the others. To change the password you use to sign in to the control panel itself, see How to Change Your ISPConfig Password and Interface Language.
Last reviewed: 27 July 2026, against ISPConfig 3.3.1p1 (the version Noiz runs). This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.
Official Documentation Reference
- ISPConfig documentation overview: the official documentation index.
- ISPConfig 3 User Manual: a paid PDF download from the ISPConfig project, which in the publisher's words "includes a reference for all forms and form fields in ISPConfig together with examples of valid inputs". Worth knowing before you click: it is sold rather than published on the web, and the current edition covers ISPConfig 3.1, so the Email Mailbox form it describes is a few releases behind the one you will see. The steps below are written against the version Noiz runs.
- NCSC: Three random words: sound, practical guidance on choosing a password that is both strong and memorable.
Prerequisites
- Access to the ISPConfig control panel for the account the mailbox belongs to. If you have not signed in before, see How to Log In to the ISPConfig Control Panel.
- A place to record the new password before you save it, such as a password manager. ISPConfig stores mailbox passwords in a form it cannot read back, so nobody, including Noiz support, can retrieve the old or the new value for you later.
- A few minutes with the devices that use the mailbox. Read the next section before you change anything.
Read This First: Everything Using the Mailbox Stops Collecting Mail
This is the part that catches people out, so it comes before the steps rather than after them. The moment the new password takes effect, every device and program that still holds the old one is refused by the mail server. Nothing is deleted and no mail is lost: messages simply queue on the server until something signs in successfully and collects them. But until you enter the new password everywhere, those devices are quietly failing.
"Everywhere" is usually longer than the list people have in their heads. Before you change the password, write down every place the mailbox is signed in:
- Phones and tablets, including a second phone in a drawer and a family member's device that was set up years ago. Phones are the single most common thing forgotten, because the mail app keeps showing the old messages it already downloaded, so the account looks fine at a glance.
- Desktop mail clients such as Outlook, Apple Mail or Thunderbird, on every computer where the mailbox was added.
- Websites that send mail as this address. If a contact form, an order confirmation or a WordPress SMTP plugin authenticates with this mailbox, it will stop sending, and it will usually fail silently. Nobody notices until a customer says an enquiry was never answered.
- Office equipment and line-of-business software: scan-to-email on a printer, a booking or CRM system, a backup or monitoring tool that emails its reports.
- Anything collecting from this mailbox on a schedule, for example another mail system set to fetch from this address and pull the mail elsewhere.
There is a second, less obvious consequence. A device left holding the old password does not give up; it retries every few minutes, around the clock. Enough failed logins from the same connection can cause the server's brute-force protection to block your internet address, which then breaks webmail and the panel for you as well, from that location, even with the correct password. If that happens, see What to Do If Your IP Address Is Blocked by an ISPConfig Server. The way to avoid it entirely is to update the devices promptly, or to switch a device you cannot get to right away off automatic checking until you can.
Find the Mailbox
- Sign in to ISPConfig and click Email in the top menu.
- In the left sidebar, under Email Accounts, click Email Mailbox.
- Click the address you want to change in the list. That opens the same form the mailbox was created on, with its existing settings loaded.
If the list is long, the filter row at the top of the table narrows it by address or domain. If the mailbox you expect is not listed at all, you are either signed in as the wrong ISPConfig user or the address is an alias or a forwarder rather than a real mailbox. Aliases and forwarders have no password of their own, because they hold no mail: they hand delivery to a real mailbox, and it is that mailbox's password that matters. See How to Set Up Email Forwarding in ISPConfig if you are not sure which you have.
Change the Password
On the Mailbox tab, the Password field is blank, even though the mailbox obviously has a password. That is expected and is not a fault: ISPConfig never displays a stored mailbox password, and there is no way to reveal it. It also means the field is safe to leave alone. If you save the form without typing anything in it, the existing password is kept, so you can edit the quota or the name of a mailbox without disturbing its password.
- Type the new password in Password, then the identical value in Repeat Password. Save the new password to your password manager before you go any further.
- Watch the Password strength field, which sits between the two password boxes. Noiz servers enforce a minimum password length and strength for mailboxes, so a weak entry is rejected when you save rather than silently accepted. Aim well past the minimum, and do not reuse the mailbox password from any other account. A long passphrase of several unrelated words is the sound choice, with one caveat: the meter scores the mix of character types as well as the length, so plain lowercase words can be graded weak however long the phrase is. A capital, a digit and one punctuation mark inside the passphrase clears the check without making it harder to remember.
- If you use the Generate Password button, it fills both password fields for you and shows the value in plain text so you can copy it. Take that copy before you save, because once the form is saved the value cannot be read back.
- Click Save.
Two practical points about what you type. Avoid a leading or trailing space, which is easy to pick up when copying and pasting and impossible to see afterwards; it is a genuine password character and will be rejected by mail clients that trim it. And keep in mind that a phone keyboard will have to reproduce whatever you choose, on the small screen, at least once per device.
Changing the password affects nothing else about the mailbox. The address, its stored mail, folders, quota, aliases, forwarders and any autoresponder all stay exactly as they were. If you are changing the password because the mailbox was compromised, though, do check those settings as a separate exercise: anything an attacker left behind keeps working regardless of the new password. Three tabs on the mailbox form are worth checking. Send copy to and Send outgoing BCC to, both on the Mailbox tab, quietly copy every incoming or outgoing message to another address. The Autoresponder tab holds any automatic reply. The Mail Filter tab holds rules that can move or redirect mail as it arrives.
Confirm It Worked
Allow up to a minute or two before testing. ISPConfig hands changes to the mail server on a short cycle rather than instantly, so a login attempt in the first few seconds can still be judged against the old password.
- Open webmail in a private or incognito browser window and sign in with the full email address and the new password. See How to Access Your Webmail in ISPConfig for the address to use. Webmail is the cleanest test because it authenticates against the mailbox on every login and holds no saved credentials of its own; a private window makes sure a stored password in the browser is not doing the work for you.
- Send a message to the mailbox from an outside address and confirm it arrives, then reply to it. That proves collecting and sending are both healthy.
- Now work through the list you wrote earlier and enter the new password on each device and app. On phones this normally appears as a prompt to sign in again on the mail account; on a desktop client it is in the account settings for that mailbox. If you need the incoming and outgoing server details while you are in there, How to Add an Email Account in Mozilla Thunderbird sets out the pattern those settings follow.
Do not read "my laptop is still receiving mail" as proof that the change did not apply. A mail client that is already connected can stay connected on its existing session for a while and only fail when it next reconnects. Webmail in a fresh private window is the reliable answer.
Troubleshooting
Symptom: ISPConfig will not save the form and complains about the password. Either the two fields differ, or the password is below the minimum length or strength the server requires. Clear both fields and retype the value carefully, or use Generate Password and copy the result.
Symptom: the new password is rejected everywhere, including webmail. Confirm the username is the full email address and not just the part before the @. If that is right, wait two minutes and try once more, in case you tested before the change was applied. If it still fails, reopen the mailbox in ISPConfig and set the password again, this time using Generate Password so there is no chance of a typo or a stray space.
Symptom: webmail works but a phone or mail client keeps asking for the password. The app is still sending the old one. Some mail apps hold a separate password for outgoing (SMTP) mail as well as incoming, and both need updating. Some cache the old value stubbornly: if repeated attempts fail with a password you know is correct, remove the account from the device and add it again.
Symptom: mail stopped arriving, or the website stopped sending, and nothing was changed on that device. Something was almost certainly configured with the mailbox password and then forgotten. Work back through the list above, giving particular attention to website contact forms, SMTP plugins and office equipment.
Symptom: everything is refused from one location, including the correct new password. That is the pattern of a brute-force block triggered by a device retrying the old password. See What to Do If Your IP Address Is Blocked by an ISPConfig Server, and find the device that is still using the old password before the block simply returns.
Symptom: you have forgotten the current password and cannot get into the mailbox. There is nothing to recover, because the stored password cannot be read back. Setting a new one from ISPConfig, as above, is the fix; no old password is needed to do it.
If a mailbox still refuses the new password after you have worked through the above, open a support ticket with the Noiz support team. Include the mailbox address, the domain, roughly when the password was changed, and which device or app is failing. Noiz managed plan clients can also ask the support team to make the change on their behalf. Never send a password in a support ticket.
Related Articles
- How to Create an Email Mailbox in ISPConfig
- How to Change Your ISPConfig Password and Interface Language
- How to Access Your Webmail in ISPConfig
- How to Add an Email Account in Mozilla Thunderbird
- What to Do If Your IP Address Is Blocked by an ISPConfig Server
- How to Set Up Email Forwarding in ISPConfig
