Gmail App Password Not Working: Every Cause, Checked
App passwords are Google’s escape hatch for apps that can’t do OAuth — email clients, scanners, old CRMs. When one doesn’t work, it’s almost always one of the causes below. Work through them in order; the first three cover most cases.
The option doesn’t exist without 2-Step Verification
App passwords are only offered on accounts with 2-Step Verification turned on. No 2FA, no app passwords — the page simply won’t appear, and there is no override. Turn on 2-Step Verification at myaccount.google.com/security first, then look again. Accounts enrolled in Advanced Protection are the exception in the other direction: they can’t create app passwords at all, by design.
You can’t find the page (Google hid it)
Google removed app passwords from the visible security menu, which convinces many people the feature is gone. It isn’t. Go to myaccount.google.com, type “app passwords” into the search box at the top, and the page appears. Bookmark it — you will not stumble onto it by browsing.
You’re typing the spaces
Google displays the password as four groups of four characters with spaces between them: abcd efgh ijkl mnop. The spaces are cosmetic. Many apps reject the 19-character pasted version but accept the 16 characters with spaces removed — and a few do the opposite and strip spaces themselves. If it fails, retype it as 16 characters, no spaces, no autocorrect (mobile keyboards love to capitalize the first letter).
You’re using it in the wrong field
An app password replaces your account password in the app — nothing else changes. The username stays your full Gmail address. If the app has separate incoming and outgoing server settings, the app password goes in both. And it never works on the Google login web page itself; it’s only for third-party apps.
Workspace: your admin decides
On Google Workspace accounts, an administrator can block app passwords (and less-secure protocol access generally). If the page says the setting is unavailable, that’s policy, not a bug — only the admin can change it, under security settings in the Admin console. IMAP itself can also be disabled org-wide, in which case a perfectly good app password still can’t connect a mail client.
“Less secure apps” is dead — this is not that
Google shut down the old “allow less secure apps” toggle, which used to let apps sign in with your real password. Guides that tell you to enable it are outdated; the setting no longer exists for consumer accounts. App passwords are the supported replacement. If your app only supports plain password login and refuses even an app password, the app itself is the problem.
It worked, then stopped
Two usual suspects. First: changing your Google account password revokes every app password, silently — you must generate new ones. Second: Google sometimes revokes app passwords after suspicious-activity events. Either way the fix is the same: delete the old entry, generate a fresh one, and update the app. Also check IMAP is still enabled in Gmail’s settings under Forwarding and POP/IMAP.
If the goal was just getting other addresses into Gmail
A lot of app-password pain comes from one specific goal: wiring info@yourdomain into Gmail with send-as and SMTP. If that’s you, two honest options. The DIY route works — our guides on Gmail forwarding and sending from Gmail document every trap we hit setting it up for real. Or skip the plumbing: All Your Inboxes delivers mail for your domain addresses as notifications into the Gmail you already check, and replying sends from your own domain — no app passwords, no SMTP settings. There’s a free plan for one address; the rest is on the pricing page. If the app password route is what you need, though, the checklist above is the whole debugging tree.
All your email. One place.
Connect any inbox. Send from the right address automatically. Free plan forever, paid from $6.99/mo, and it never touches how your mailboxes are set up.
Try it free