My Gmail App Password says "authentication failed" on the first tries — where's the problem?
If you turned on 2-Step Verification, created a Google App Password, and your mailbox still shows "authentication failed" on the first few tries — here's the short, reassuring version: a brand-new App Password almost always works, and the most common reasons it reads as failed at first are easy to fix. None of them mean you did the setup wrong. In nearly every case it comes down to one of three things: the spaces Google shows in the password got pasted in along with it, Google is running a quick one-time security check on the brand-new password, or the everyday Google login password was used instead of the App Password. This page walks through each one and exactly how to fix it.
WarmySender is a 4-pillar outreach platform — Cold Emailing, Email Warmup, LinkedIn Outreach, and Multichannel sequences. This guide covers connecting a Gmail or Google Workspace mailbox with an App Password, and why a first-try "authentication failed" is almost always a quick fix rather than a sign anything is broken.
The short answer first
A freshly created Google App Password is correct the moment Google shows it to you. So when a mailbox reads "authentication failed" on the first attempts, the password itself is usually fine — something small is getting in the way of it being accepted, and it clears in a minute or two. The three usual culprits, in the order we see them most:
- The spaces in the App Password got pasted in. Google shows the password in four blocks with spaces; those spaces are only there to make it readable. Paste it as one continuous 16-character string instead.
- Google is running a quick one-time security check. Right after you turn on 2-Step Verification and create the App Password, Google sometimes holds the very first sign-in for a short review. Waiting about 10–15 minutes and approving Google's "new sign-in" email usually clears it.
- The normal login password was used by mistake. With 2-Step Verification on, your everyday Google password won't connect an app — you have to use the 16-character App Password.
Work through the three sections below and your mailbox should connect. You don't need to delete it, change any server settings, or start the Google setup over.
Cause A — the spaces in the App Password were pasted in
When you create an App Password, Google displays it as four groups of four characters with spaces between them, like abcd efgh ijkl mnop. Those spaces are there purely to make the 16-character password easier to read off the screen — they are not part of the password. Some setups accept the password with the spaces and some reject it, which is exactly why a perfectly correct password can read as "authentication failed" the first time you try.
The fix: enter the App Password as one continuous 16-character string with no spaces — for example abcdefghijklmnop rather than abcd efgh ijkl mnop. If you already pasted it with the spaces, just clear the field, type or paste the 16 characters without spaces, and try connecting again.
Good news: WarmySender now removes those spaces for you automatically when you paste, so this is far less likely to trip you up than it used to be. Even so, removing the spaces yourself before you paste is the surest way to rule this cause out.
Cause B — Google is running a quick one-time security check
Right after you turn on 2-Step Verification and create a brand-new App Password, Google sometimes treats the very first connection from a new place with extra caution and holds it for a short security review. While that review is in progress, the connection can read as "authentication failed" for a few minutes even though your password is completely correct. This is the single most common reason a setup that was done perfectly still fails on the first try and then works a little later.
The fix:
- Wait about 10–15 minutes after creating the App Password.
- Open the inbox of the Google account you're connecting and look for a "security alert" or "new sign-in" email from Google. Open it and confirm "Yes, it was me" (or approve the sign-in / tap Yes on any prompt Google sent to your phone).
- Go back to WarmySender and connect the mailbox again.
This is precisely why "I tried again a little later and it just worked" is such a common outcome — the security check finishes, Google starts accepting the App Password, and the mailbox connects normally. Nothing about your setup changed; Google simply needed a moment to clear the first sign-in.
Cause C — the normal login password was used instead of the App Password
Once 2-Step Verification is turned on, your everyday Google login password will no longer work for connecting an app — Google requires a dedicated App Password for that. So if "authentication failed" keeps showing and you've ruled out the spaces and the security check, double-check that you pasted the 16-character App Password, not your day-to-day Google password.
The fix: generate (or re-open) the App Password at myaccount.google.com/apppasswords, copy the 16-character value, and paste that into the password field. Two things to know:
- 2-Step Verification has to be on first. The App Password page won't appear until 2-Step Verification is enabled on the account. If myaccount.google.com/apppasswords shows a message about needing 2-Step Verification, turn it on at myaccount.google.com/security first, then create the App Password.
- Google only shows it once. Copy the 16-character App Password as soon as Google displays it — if you've lost it, just create a fresh one (it only takes a few seconds) and use that.
Still stuck? A couple of quick things to check
If you've ruled out all three causes above and a mailbox still won't connect, two more quick checks clear up almost everything that's left:
- Double-check the email address. A small typo in the email address will read as "authentication failed" even when the App Password is perfect. Make sure the address is spelled exactly right.
- For a Workspace alias mailbox, check the Username. If you're connecting a Google Workspace alias (you send from one address but the inbox is owned by a different primary Google account), the Username must be the primary Google account that owns the App Password — not the alias address. This is the most-missed step for alias setups; the full walkthrough is in Connect a Gmail or Google Workspace alias.
If it still fails after waiting, approving Google's sign-in email, and confirming the address and password, just reply to support and we'll look at that specific mailbox for you — see Still seeing it? below.
What this means for your warmup and campaigns
A first-try "authentication failed" while you're setting the mailbox up has no effect on your warmup history or your campaigns — there's simply nothing to affect yet, because the mailbox hasn't started running. As soon as it connects, warmup begins on its normal gentle ramp and the mailbox becomes available for your cold email campaigns. Your other mailboxes that are already connected keep running as usual, and your LinkedIn outreach is separate and unaffected.
Separately, if a mailbox that was already connected and working suddenly shows a connection problem, that's a different situation — usually a brief, temporary hiccup on your provider's side rather than anything to do with your password. See Why did several of my mailboxes suddenly show "Reconnecting"? for that one.
Frequently asked questions
I set up 2-Step Verification and an App Password but it still says "authentication failed" — what's wrong?
Almost always something small and quick to fix, not a mistake in your setup. The three usual causes are: the spaces Google shows in the App Password got pasted in (enter the 16 characters with no spaces), Google is running a quick one-time security check on the brand-new password (wait about 10–15 minutes, approve Google's "new sign-in" email, then try again), or the everyday Google login password was used instead of the App Password (use the 16-character App Password from myaccount.google.com/apppasswords). Work through those three and your mailbox should connect — you don't need to delete it or start over.
Do I need to remove the spaces in my App Password?
Yes, that's the safest way to enter it. Google shows the 16-character App Password in four blocks with spaces, like abcd efgh ijkl mnop, purely so it's easy to read — the spaces aren't part of the password. Some setups reject it if the spaces are included, so enter it as one continuous string: abcdefghijklmnop. WarmySender now strips those spaces for you automatically when you paste, but removing them yourself is the surest fix.
It failed at first but worked a little later — why?
Because of Cause B above: right after you create a new App Password, Google sometimes holds the very first sign-in for a short security review, which can read as "authentication failed" for a few minutes. Once that review clears — and especially once you've approved Google's "new sign-in" email — Google starts accepting the App Password and the mailbox connects normally. Nothing about your setup changed; Google just needed a moment to clear the first connection. That's why trying again a little later so often simply works.
Which password do I use — my normal Google password or the App Password?
The 16-character App Password, every time. Once 2-Step Verification is on, your everyday Google login password won't work for connecting an app. Generate an App Password at myaccount.google.com/apppasswords (2-Step Verification has to be turned on first, or Google won't show that page) and paste the 16-character value into the password field.
How long should I wait before trying again?
About 10–15 minutes after creating the App Password is usually enough for Google's one-time security check to clear. It helps to open the "security alert" or "new sign-in" email Google sends to that account and confirm "Yes, it was me" before you reconnect — that tells Google the sign-in is expected and tends to clear it faster.
Is my account broken — did I do something wrong?
Almost certainly not. A brand-new App Password is correct the moment Google shows it to you, so a first-try "authentication failed" is almost always one of the three small, easy-to-fix things above — pasted-in spaces, Google's quick one-time security check, or the wrong password — rather than a broken account or a setup mistake. Most mailboxes that fail on the first try connect fine within a few minutes once you've removed the spaces and approved Google's sign-in email.
Does this affect my warmup or my campaigns?
No. A first-try "authentication failed" during setup happens before the mailbox starts running, so there's no warmup history or campaign activity to affect yet. Once the mailbox connects, warmup begins on its normal gentle ramp and the mailbox is ready for your campaigns. Your already-connected mailboxes and your LinkedIn outreach carry on as normal throughout.
I'm connecting a Workspace alias and it still fails — what should I check?
For a Google Workspace alias (you send from one address but the inbox belongs to a different primary Google account), the Username must be the primary Google account that owns the App Password, not the alias address. Putting the alias in the Username field reads as "authentication failed" even with a correct password. The full alias walkthrough — including the exact field mapping — is in Connect a Gmail or Google Workspace alias.
Still seeing it after trying the steps above?
If a mailbox still won't connect after you've removed the spaces, waited about 10–15 minutes and approved Google's "new sign-in" email, and confirmed you're using the 16-character App Password with the right email address, we'd be glad to look at that specific mailbox for you. Email [email protected] with the email address you're trying to connect and we'll help you get it working — just reply there and we'll take it from your message.
Related reading
- Connect a Gmail or Google Workspace alias — the full step-by-step connection guide, including the alias-vs-primary Username mapping
- Why did several of my mailboxes suddenly show "Reconnecting"? — when an already-connected mailbox briefly shows a connection problem (different from a first-try setup error)
- Connected but not sending — why a mailbox can show connected while sending is briefly paused
- Your mailboxes — connect a mailbox and check its status
- Full documentation — Cold Emailing, Email Warmup, LinkedIn Outreach, and Multichannel guides
Still have questions? Email [email protected] — we respond within 24 hours on business days.