535 5.7.8 Authentication credentials invalid / Username and Password not accepted

The server rejected the login. The username or password is wrong, or the account requires a different kind of credential than the one the client sent. Nothing about the message was examined; the session failed at AUTH.

What the server replies

535-5.7.8 Username and Password not accepted. For more information, go to 535 5.7.8 https://support.google.com/mail/?p=BadCredentials a1b2c3d4e5f6-sm.google.com

Sent by
Any mail server
Type
PermanentRetry fails
About
Authentication
Enhanced code
5.7.8

Who sends it

Any submission server. Gmail's wording is "Username and Password not accepted"; Microsoft 365 says "535 5.7.139 Authentication unsuccessful, the user credentials were incorrect" or "basic authentication is disabled"; Postfix with SASL says "535 5.7.8 Error: authentication failed: authentication failure".

Why it happens

  • A mistyped or recently changed password.
  • The account has two-factor authentication and needs an app password rather than the account password.
  • The provider disabled basic (password) SMTP authentication, as Microsoft 365 did for most tenants, and the client must use OAuth or an app password.
  • The username is the short name when the server wants the full address, or vice versa.
  • The account is locked after too many failed attempts, which some servers report with the same code.

How to fix it

  1. Re-enter the credentials

    Use the full email address as username. Paste the password rather than retyping it, and check for trailing spaces.

  2. Create an app password

    For Gmail and most providers with two-factor authentication, generate an app password in the account's security settings and use that in the client.

  3. Check whether basic auth is allowed

    Microsoft 365 tenants must enable SMTP AUTH per mailbox and the tenant's security defaults may block it. Ask the admin, or switch the application to OAuth.

  4. Test outside the application

    An SMTP test with the same host, port and credentials tells you whether the login itself works, separating a credential problem from an application bug.

Check it yourself

These free tools show the records and connections behind this code for your own domain or server.

Related codes

Sources

Fewer bounces to look up.

Faivelo sends from authenticated, warmed infrastructure, turns permanent bounces into one clean event for your application and keeps the address out of future sends.

Send with Faivelo

Free tier included. No card needed.