I thing I found the use for loginrealms option. I works like a filter. Imagine you have an authentication infrastructure for multiple domains: example.com, example.net ..... I could be running on ldap, kerberos, .... Then you have an imap server that manage users only for domain example.com. If you set loginrealms: example.com, example.net then user from example.net will be able to authenticate, but any operation on a mailbox will fail because they don't have one (or access to any one). If you set loginrealms: example.com then the same user will be rejected at authentication ! -- Alain Spineux aspineux gmail com May the sources be with you ---- Cyrus Home Page: http://cyrusimap.web.cmu.edu/ Cyrus Wiki/FAQ: http://cyrusimap.web.cmu.edu/twiki List Archives/Info: http://asg.web.cmu.edu/cyrus/mailing-list.html