GuidesMail providers
Gmail rejects your app password: what the error means and what to check
You created an app password and Gmail still says no. The error text tells you more than it seems to, and six checks in a fixed order find the cause. Checked against Google's and Microsoft's documentation in October 2026.
In short
- A 535-5.7.8 reply means the connection works and Google has refused this pair of address and password.
- Create a new app password instead of typing the old one again, and enter the full email address as the username.
- Changing your Google Account password revokes every app password on the account.
- On Google Workspace the admin has to allow IMAP for all mail clients, not only for OAuth clients.
- Microsoft mailboxes are a different matter: passwords are no longer accepted for reading mail, so no app password helps there.
When Gmail refuses an app password, check four ordinary causes first: the tool holds your normal Google password, Google revoked the app password when you changed your account password, a character went missing in copying, or the app password was created in a different Google account than the address you entered. A new app password, pasted together with the full email address, settles all four. On Google Workspace there is a fifth cause: the admin can close IMAP to password-based programs without touching your password.
The error texts, settings and quotes below were checked against Google's and Microsoft's documentation on October 5, 2026.
What the error messages mean
Many mail tools pass on what Google's server said. For the outgoing side, the SMTP server, a refused sign-in looks like this:
535-5.7.8 Username and Password not accepted. Learn more at
535 5.7.8 https://support.google.com/mail/?p=BadCredentials
The number 535 with the status 5.7.8 is the standard reply for “authentication credentials invalid”, defined in RFC 4954, the standard that specifies sign-in for SMTP. It tells you that the connection reached Google and that Google looked at the address and password and said no. The words after the first sentence vary. The line above is taken from a thread in Google's own Gmail community.
| What the tool shows | Direction | What Google means | What to do |
|---|---|---|---|
535-5.7.8 Username and Password not accepted | Sending (SMTP) | This pair of address and password is not valid | Checks 1 to 4 below |
534-5.7.9 Application-specific password required | Sending (SMTP) | You sent the normal password to an account with 2-Step Verification | Use an app password instead |
534-5.7.14 Please log in through your web browser and then try again | Sending (SMTP) | Google wants to see a normal sign-in first | Check 6 below |
| “Invalid credentials” | Reading (IMAP) | The same refusal, from the incoming server | Checks 1 to 5 below |
| “Too many simultaneous connections” | Reading (IMAP) | More than 15 mail programs are connected to the account at once | Disconnect programs you no longer use |
550 5.4.5 Daily user sending limit exceeded | Sending (SMTP) | Not a password problem. The account reached its daily sending limit | Wait; sending resumes within 24 hours |
The messages are listed in Google's reference Gmail SMTP errors and codes and in the Gmail help page Add Gmail to another email client, which is also the source for the limit of 15 programs.
Six checks, in order
- Make sure it is an app password. Gmail does not take the normal account password from mail programs and tools any more. Its help states that Gmail “no longer supports third-party apps or devices which require you to share your Google username and password”. An app password has 16 characters and was generated by Google, not chosen by you. Google shows it in four groups of four; the spaces are not part of it, and WarmupBay ignores them when you paste it.
- Create a new one instead of typing the old one again. Google shows an app password once, and it cannot be looked up later. Open myaccount.google.com/apppasswords, create a fresh one, and paste it without typing. If that page does not open for your account, see why the app passwords option is missing.
- Enter the full email address as the username. Google asks for the “complete” address, for example
your.name@example.com, and it must be the Google account in which you created the app password. With several accounts signed in to one browser, it is easy to create it in the wrong one. - Compare server names and ports with the table in the next section.
- On Google Workspace, ask whether IMAP is open to all mail programs. This is an admin setting, described further down.
- If Google asks for a browser sign-in, do that first. Sign in to the account at Google in a browser, deal with any security question it raises, and then try the tool again.
The server settings Gmail expects
Google documents them in its developer page on IMAP, POP, and SMTP. For Google Workspace mailboxes, the admin help page Send email from a printer, scanner, or app gives the same outgoing server and ports.
| Direction | Server | Port | Encryption |
|---|---|---|---|
| Incoming mail (IMAP) | imap.gmail.com | 993 | SSL/TLS |
| Outgoing mail (SMTP) | smtp.gmail.com | 587 | STARTTLS |
| Outgoing mail (SMTP), alternative | smtp.gmail.com | 465 | SSL/TLS |
The username is the full email address and the password is the app password. The Workspace page says so directly: for authentication, enter the complete address “and an app password”. A wrong server name or port normally leads to a timeout or a connection error, not to a 535. If you see 535, the connection itself is fine.
Why an app password that worked stops working
When a connection that ran for weeks suddenly fails, check whether its app password still exists. Google's documentation names four ways to lose one:
- You changed your Google Account password. Google's help on app passwords says: “we revoke your app passwords when you change your Google Account password.” Every tool needs a new one afterwards.
- The app password was removed on the app passwords page, by you or by someone else with access to the account.
- The account was enrolled in Advanced Protection. Enrolling revokes all existing app passwords and blocks new ones, according to Google's questions on the program.
- On Google Workspace, the admin began to enforce security keys. Google's admin help states that enforcing security keys “disables app passwords”.
One older case belongs here too. If the tool was connected with the normal Google password, not an app password, it stopped in spring 2025, when Google ended that kind of sign-in for Workspace accounts. Google's admin pages name March 14, 2025 in one place and May 1, 2025 in another. App passwords are named as the exception and still work.
Google Workspace: the admin can block IMAP for app passwords
In a Workspace organization, a valid app password is not enough. The admin also decides whether mail programs may read mail over IMAP at all, and which ones. Google describes the setting in Turn POP & IMAP on or off for users:
- In the Admin console, go to Menu → Apps → Google Workspace → Gmail → End User Access.
- Scroll to POP and IMAP access.
- Check Enable IMAP access for all users.
- Choose Allow any mail client.
- Save. Google notes that changes can take up to 24 hours but typically happen more quickly.
The fourth step matters for app passwords. The other option on that page is “Restrict which mail clients users can use (OAuth mail clients only)”. A program that signs in with an app password does not use OAuth, the sign-in method in which you approve access on a Google screen and no password is passed on. Google's wording: such clients “can be used with POP or IMAP but only when you allow all clients”. If IMAP is turned off altogether, the page says, “the sign-in fails”.
One hint that this is your case, though not proof: the tool reports that the outgoing server accepts the sign-in and the incoming server does not. The setting covers POP and IMAP, not sending.
Advice you can skip
Search results for these errors go back many years, and some of the advice no longer applies.
- Allow less secure apps. This was a switch that let programs sign in with the normal password. Google's page on less secure apps now says such apps are no longer supported for Google Workspace accounts, and the admin help says the setting can no longer be reached in the Admin console. Google's own help page for POP still lists the step, which is confusing, but there is nothing left to switch on.
- Enable IMAP in the Gmail settings. For personal accounts, Google's help says that since January 2025 the option is no longer available and “IMAP access is always turned on”.
- Turn off 2-Step Verification. It does not bring the old password sign-in back, and it removes the one condition for app passwords.
If the mailbox is at Microsoft, the cause is different
At Microsoft, a refused sign-in can have a cause that no new password will fix. Microsoft has stopped accepting passwords from mail programs for most of its mail service, and no setting in your account brings that back.
- Outlook.com, Hotmail and Live. According to Microsoft Support, sign-in with user name and password, which Microsoft calls Basic Authentication, has not been available for any Outlook account since September 16, 2024. Programs must use OAuth.
- Microsoft 365. Microsoft's documentation states that Basic authentication is disabled in all tenants for IMAP and POP, that nobody can re-enable it, and that this “also prevents the use of app passwords”. Only sending over SMTP still accepts a password where the admin has enabled it. Microsoft's timeline of January 27, 2026 says this will be disabled by default for existing tenants at the end of December 2026, with a final removal date to be announced in the second half of 2027.
A tool that reads the mailbox with a password over IMAP therefore cannot connect to a Microsoft mailbox, however correct the password is. That applies to WarmupBay as well: Microsoft 365 and Outlook.com mailboxes cannot be connected yet.
Once the sign-in works: what WarmupBay does next
WarmupBay is a free email warmup service, and for Gmail and Google Workspace it signs in the way this guide describes: with your address and an app password. If the sign-in fails there, the six checks above apply unchanged.
Once the connection stands, WarmupBay checks the SPF, DKIM and DMARC records of your domain, the DNS entries that let receiving servers verify your mail, and shows a ready-made DMARC record if yours is missing. Your mailbox then exchanges short emails with other mailboxes in the pool, starting with 3 a day and adding one a day up to the free limit of 10. If the records are still missing after 72 hours, warmup stops.
You can connect a mailbox for free, or read what the service does and does not promise first.
Questions people ask
Can I use the same app password in two tools?
Google's help does not forbid it, but give each tool its own. App passwords are listed by name on the app passwords page, so separate ones let you cut off one tool without disconnecting the others, and you can see which tools still have access.
How do I revoke an app password I no longer need?
Open myaccount.google.com/apppasswords, find the entry for the tool in the list and remove it. Google's help says that once an app password is revoked, the app cannot access the account again. You can create a new one at any time.
What are Gmail's daily sending limits?
As of October 2026, Google's help gives 500 emails a day for a personal Gmail account. For Google Workspace it gives 2,000 messages per user per day, and 500 for trial accounts. The limits apply over a rolling 24-hour period, and Google says they can change without notice.
Will Google switch off app passwords?
Google's help pages name no end date, as checked in October 2026. They call app passwords not recommended, and they list them as the exception where they describe the end of sign-in with the normal password in 2025. Where a tool offers Sign in with Google, Google prefers that.
Does WarmupBay need my normal Google password?
No. For Gmail and Google Workspace, WarmupBay asks for the email address and an app password. You can remove that app password at Google at any time, and the connection ends with it.
Sources
- Gmail SMTP errors and codes – Google Workspace Help
- Add Gmail to another email client – Gmail Help
- Sign in with app passwords – Google Account Help
- IMAP, POP, and SMTP – Gmail, Google for Developers
- Send email from a printer, scanner, or app – Google Workspace Help
- Turn POP & IMAP on or off for users – Google Workspace Help
- Transition from less secure apps to OAuth – Google Workspace Help
- How 2-Step Verification works with legacy apps – Google Workspace Help
- Common questions with Advanced Protection Program – Google Account Help
- Less secure apps & your Google Account – Google Account Help
- Read Gmail messages on other email clients using POP – Gmail Help
- Limits for sending & getting mail – Gmail Help
- Gmail sending limits in Google Workspace – Google Workspace Help
- RFC 4954: SMTP Service Extension for Authentication
- Need help with “Invalid login: 535-5.7.8 Username and Password not accepted” – Gmail Community thread, August 2023
- Modern Authentication Methods now needed to continue syncing Outlook Email in non-Microsoft email apps – Microsoft Support
- Deprecation of Basic authentication in Exchange Online – Microsoft Learn
- Updated Exchange Online SMTP AUTH Basic Authentication Deprecation Timeline – Microsoft Community Hub, January 27, 2026