← Back to Learning Hub

Email Delivery • Beginner • 7 min read

Email App Passwords: How to Set Them Up on Every Major Client (and Fix the "App Password Needed" Error)

Getting an "app password required" error in your mail app? Here is what an app password is, how to create one for Gmail, Outlook, iCloud, and Yahoo, and how to enter it in every major client.

An app password is a one-time code your email provider generates so an app can sign in without your real password or your two-factor code. If your mail program suddenly stopped connecting and threw an error like "app password required" or "your regular password will not work here," this is why, and the fix takes about five minutes. Here is what is happening and exactly how to sort it on every major email service and client.

Why you are seeing the "app password needed" error

The error almost always appears right after you turn on two-factor authentication, or after your provider tightened its security. Older mail programs sign in with just a username and password, a method called basic authentication. Once two-factor is on, that simple sign-in is not enough on its own, and the provider will not let the app in with your normal password anymore. Rather than break the app entirely, providers let you generate a special app password that stands in for the normal one for that single app.

So the error is not a sign that something is broken. It is the provider telling you: this app needs its own dedicated password now.

A real scenario

You enabled two-factor on your Google account last week, which was the right move. This morning, Outlook on your desktop keeps popping up a login box, rejecting your password every time, and the status bar reads "app password required." Your webmail works fine, so you know the account itself is healthy. What changed is that Outlook is still trying the old basic sign-in. You generate a Google app password, paste it into Outlook once, and it connects and stays connected. Nothing else needed to change.

How to create an app password

The steps differ slightly per provider, but the idea is identical: find the security settings, confirm two-factor is on, and generate the code.

  • Google (Gmail): Go to your Google Account, Security, and confirm 2-Step Verification is on (app passwords only appear once it is). Then open App passwords, name it after the app, and Google shows a 16-character code.
  • Microsoft (Outlook.com, Microsoft 365): Go to your Microsoft account Security, Advanced security options, and under App passwords choose Create a new app password.
  • Apple (iCloud Mail): Sign in at the Apple Account site, go to Sign-In and Security, and select App-Specific Passwords to generate one.
  • Yahoo Mail: Go to Account Security and choose Generate app password (or Generate and manage app passwords).

Copy the code exactly. It usually has no spaces, and you only see it once, so paste it straight into your mail app.

How to enter it in every major client

Wherever your mail app asks for your password, you use the app password instead of your real one. The username, server names, and ports do not change.

  • Outlook (desktop): When the login box appears, or under File, Account Settings, enter the app password in the password field. Remove the account and re-add it if it keeps prompting.
  • Apple Mail (Mac): Mail, Settings, Accounts, select the account, and replace the stored password with the app password.
  • iPhone or iPad Mail: Settings, Mail, Accounts, tap the account, and update the password field with the app password.
  • Thunderbird: When prompted, paste the app password. If it does not ask, go to Account Settings, Server Settings, and update it, or clear the saved password under Settings, Privacy, Passwords.
  • Android (Gmail app or built-in Mail): Remove and re-add the account, and enter the app password when asked for the password.

A cleaner long-term option

Where a provider supports it, choosing the modern sign-in method, often labeled OAuth or "sign in with Google/Microsoft," skips app passwords entirely. The app hands you off to the provider's own login page, you approve it once, and there is no code to manage. Newer versions of Outlook, Apple Mail, and Thunderbird support this for the big providers. If your client offers it, use that instead, and keep app passwords as the fallback for older software.

Frequently asked questions

Why does my normal password no longer work in my mail app?

Because two-factor authentication is on, and your provider no longer accepts the basic username-and-password sign-in that older apps use. It wants an app password or a modern OAuth sign-in instead.

Do I need a separate app password for each device?

It is good practice. Generate one per app or device and name it clearly, so if you lose a phone you can revoke just that one without disturbing the others.

Is an app password less secure than my real password?

No, and in some ways it is safer. It only works for mail, it does not unlock your whole account, and you can revoke it instantly without changing your main password.

I do not see the app password option anywhere.

Two-factor authentication must be turned on first. The app password setting is hidden until it is. Enable two-factor, then the option appears in your security settings.

What if the app still will not connect after I enter it?

Remove the account from the app entirely and add it back fresh, entering the app password when prompted. A stale saved password is the most common reason it keeps failing.

Troubleshooting box

If results look inconsistent, compare authoritative nameservers first, then recursive resolvers by region. Capture snapshots every 10 minutes for deterministic incident timelines.

Try VallaDNS free →

Beginner • 9 min

DKIM: Why Messages Fail Without It

Learn why emails fail without DKIM, how DKIM signatures are validated, and the exact DNS and server checks to fix spam placement and authentication rejections fast.