535 5.7.8 Authentication credentials invalid / Username and Password not accepted
The server rejected the login. The username or password is wrong, or the account requires a different kind of credential than the one the client sent. Nothing about the message was examined; the session failed at AUTH.
What the server replies
535-5.7.8 Username and Password not accepted. For more information, go to 535 5.7.8 https://support.google.com/mail/?p=BadCredentials a1b2c3d4e5f6-sm.google.com
- Sent by
- Any mail server
- Type
- PermanentRetry fails
- About
- Authentication
- Enhanced code
- 5.7.8
Who sends it
Any submission server. Gmail's wording is "Username and Password not accepted"; Microsoft 365 says "535 5.7.139 Authentication unsuccessful, the user credentials were incorrect" or "basic authentication is disabled"; Postfix with SASL says "535 5.7.8 Error: authentication failed: authentication failure".
Why it happens
- A mistyped or recently changed password.
- The account has two-factor authentication and needs an app password rather than the account password.
- The provider disabled basic (password) SMTP authentication, as Microsoft 365 did for most tenants, and the client must use OAuth or an app password.
- The username is the short name when the server wants the full address, or vice versa.
- The account is locked after too many failed attempts, which some servers report with the same code.
How to fix it
Re-enter the credentials
Use the full email address as username. Paste the password rather than retyping it, and check for trailing spaces.
Create an app password
For Gmail and most providers with two-factor authentication, generate an app password in the account's security settings and use that in the client.
Check whether basic auth is allowed
Microsoft 365 tenants must enable SMTP AUTH per mailbox and the tenant's security defaults may block it. Ask the admin, or switch the application to OAuth.
Test outside the application
An SMTP test with the same host, port and credentials tells you whether the login itself works, separating a credential problem from an application bug.
Check it yourself
These free tools show the records and connections behind this code for your own domain or server.
Related codes
- 530 5.7.0 Authentication required / Must issue a STARTTLS command firstThe server will not go any further until the client does something it has not done yet.
- 550 5.7.1 Relay access denied / relaying deniedYou asked a mail server to deliver to a domain it does not host, and it refused because you are not an authorised client.
- 550 5.4.5 Daily sending quota exceededThis one comes back when you send through Gmail, not to it.
Sources
Fewer bounces to look up.
Faivelo sends from authenticated, warmed infrastructure, turns permanent bounces into one clean event for your application and keeps the address out of future sends.
Free tier included. No card needed.
Other free tools
All tools- Email DNS checkerCheck MX, SPF, DKIM, DMARC and reverse DNS for any domain and get the exact records to add or fix.
- DMARC checkerLook up a domain's DMARC record, read every tag in plain words and see what to tighten next.
- DMARC record generatorBuild a valid DMARC record from a few choices and copy the host and value into your DNS.
- DMARC report analyzerDrop in a DMARC aggregate report and see who is sending as your domain and whether they pass.
- SMTP connection testerConnect to any SMTP server, check TLS and the login step, and see each stage with its timing.
- Email header analyzerPaste raw headers to see every hop, where the delay was, and whether SPF, DKIM and DMARC passed.
- Email address validatorCheck whether an address is well formed, whether its domain accepts mail, and whether it is disposable or a role account.