You open Thunderbird, Apple Mail, or your favorite desktop client, and instead of your inbox you get a red banner: "Authentication failed." Your password is correct, nothing changed on your end, yet mail simply will not sync. If that sounds familiar, you are living the most common Gmail headache of the year. Gmail IMAP not working in a third-party app is now a daily complaint across r/Gmail and the Google Workspace forums, and almost none of it is caused by a wrong password.
The real cause is a quiet, multi-year tightening of how Gmail lets outside apps connect. Google has retired the old "just type your password" method and now demands modern, token-based sign-in. This guide walks through exactly why Gmail IMAP not working errors appear in 2026, the precise server settings and ports you need, and the two fixes — OAuth 2.0 sign-in and 16-character app passwords — that get your mail flowing again in minutes. Whether you run one personal inbox or a pool of aged Gmail accounts for outreach, this is the connectivity playbook to keep bookmarked.
What "Gmail IMAP Not Working" Really Means in 2026
IMAP (Internet Message Access Protocol) is the standard that lets an external email program read and manage the messages sitting on Gmail's servers. Its partner, SMTP (Simple Mail Transfer Protocol), handles sending. When people say their Gmail IMAP not working, they almost always mean one of three things: the client cannot log in at all, it connects but never downloads new mail, or it can receive but refuses to send.
Here is the crucial shift for 2026: in the vast majority of cases, the protocol itself is fine. Gmail's IMAP and SMTP servers are online and working normally. What has changed is authentication — the way your app proves it is allowed to open the mailbox. Google no longer accepts a plain username and password from most apps. If your client is still trying to log in the old way, Gmail slams the door and your app reports a generic sync failure. That mismatch is the single biggest reason for a Gmail IMAP not working message today.
Understanding this distinction saves hours. You do not need to reinstall your operating system, buy a new client, or abandon Gmail. You need to update how the connection authenticates. Once you do, the same app that was throwing errors a minute ago syncs instantly.
Why Google Blocked Your Third-Party App
For years, any app could sign in to Gmail with just your email address and password. Google called this "less secure app" access, and it was a phishing magnet — a single stolen password handed an attacker your entire inbox. Starting in late 2024 for personal accounts and reaching full enforcement across Google Workspace by May 2025, Google switched that method off permanently.
In its place, Google requires OAuth 2.0: a token-based system where you sign in once through Google's own secure window, and the app receives a revocable token instead of your actual password. The token can be limited in scope and cancelled at any time without changing your password. It is genuinely safer — but it also means every older app configured for "normal password" login suddenly stops working. That is why a client you used happily for a decade can produce a Gmail IMAP not working error overnight, with no action on your part.
This is part of a wider 2026 trend. Providers across the board are restricting free-tier, password-based IMAP access to cut down on automated abuse and credential-stuffing attacks. Google's move is the most visible because Gmail is the largest mailbox on earth, but the direction of travel is industry-wide. The same authentication tightening is why senders have to care more than ever about correct setup — a theme we covered in our guide to the Gmail 550-5.7.26 unauthenticated-sender error.
The Exact Error Messages You'll See
Gmail and your client rarely say "switch to OAuth." Instead you get vaguer warnings. Recognizing them tells you immediately that authentication — not the network — is the problem:
- "Authentication failed" when connecting to
imap.gmail.com— the classic Thunderbird message. - "Username or password is incorrect" even though it is correct — Gmail rejecting a legacy password login.
- "[AUTHENTICATIONFAILED] Invalid credentials" — the raw IMAP server response.
- "Cannot get mail — the connection to the server failed" on iPhone or Mac.
- "Web login required" or a prompt that never finishes — Gmail wants you to complete a browser sign-in.
Any of these is a strong signal that you are hitting the OAuth 2.0 wall. A true network outage looks different: timeouts, "server not found," or the same failure across every account and app at once. If only Gmail is affected and the password is definitely right, you are dealing with the modern Gmail IMAP not working pattern, and the fixes below will resolve it.
Step 1: Confirm IMAP Is Turned On in Gmail
Before touching your client, make sure Gmail is even offering IMAP. It is on by default for most accounts, but a toggle can be flipped off — especially on Workspace accounts governed by an admin.
- Open Gmail in a browser and click the gear icon → See all settings.
- Go to the Forwarding and POP/IMAP tab.
- Under "IMAP access," select Enable IMAP.
- Click Save Changes at the bottom.
If you manage a Google Workspace domain, IMAP and POP can also be controlled centrally in the Admin console under Apps → Google Workspace → Gmail → End User Access. If IMAP is disabled there, no client setting will help until an admin re-enables it. Confirming this first rules out the simplest cause of a Gmail IMAP not working complaint before you spend time on authentication.
Step 2: Use the Correct IMAP & SMTP Settings
A surprising share of sync failures come down to a mistyped port or the wrong encryption setting. Gmail's official server details have not changed, so copy these exactly:
| Setting | Incoming (IMAP) | Outgoing (SMTP) |
|---|---|---|
| Server | imap.gmail.com | smtp.gmail.com |
| Port | 993 | 465 (SSL) or 587 (TLS) |
| Encryption | SSL/TLS | SSL/TLS or STARTTLS |
| Username | your full address ([email protected]) | your full address |
| Authentication | OAuth 2.0 or app password | OAuth 2.0 or app password |
Two rules trip people up. First, the username must be your complete email address, not just the part before the @. Second, encryption must be SSL/TLS — never "none." If your client offers "Normal password" as the authentication type and you are not using an app password, that is very likely the source of your Gmail IMAP not working error. Correct ports with the wrong auth type still fail, so treat settings and authentication as two separate checks.
Fix A: Switch Your Client to OAuth 2.0 Sign-In
This is the cleanest, most future-proof fix, and it is what Google actually wants you to do. Modern clients — recent Thunderbird, Apple Mail, the new Outlook, Samsung Mail — all support it. The trick is that the account often needs to be re-added, because an old profile created under password login will keep trying the dead method.
- Remove the Gmail account from your client entirely (do not just edit it).
- Add it again as a new account, typing only your Gmail address.
- When Google's own sign-in window pops up, log in there and approve access.
- The client stores a revocable OAuth token and connects normally.
During re-adding, set the authentication type to OAuth2 (Thunderbird labels it exactly that) rather than "Normal password." If your client shows a "Sign in with Google" button, use it — that button is OAuth 2.0. This single change resolves the overwhelming majority of Gmail IMAP not working reports, because it replaces the rejected legacy login with the method Gmail now requires. If you have two-step verification and passkeys enabled, OAuth still works seamlessly; see our Gmail passkeys guide for how those pieces fit together.
Fix B: Create a 16-Character App Password
Some clients — older Outlook desktop builds, certain scanners, printers, CRMs, and scripts — cannot do OAuth 2.0 at all. For these, Google offers app passwords: a one-off, 16-character code that works in place of your real password for a single app. It is the sanctioned workaround when a Gmail IMAP not working error comes from a client that will never support modern sign-in.
The catch: app passwords require 2-Step Verification to be enabled on the account first. If you do not see the option, that is why. Here is the process:
- Go to myaccount.google.com → Security and turn on 2-Step Verification if it is off.
- Return to Security and open App passwords (search for it in the account search bar if hidden).
- Enter a name like "Outlook Desktop" and click Create.
- Copy the 16-character code Google shows (spaces do not matter).
- In your email client, paste that code into the password field instead of your normal password.
Treat the app password like a real credential — anyone with it can read your mail. Generate one per device so you can revoke a single lost laptop without disrupting everything else. For senders running SMTP at volume, app passwords are the backbone of the setup; we break that down fully in our guide to Gmail SMTP accounts for bulk sending.
Client-by-Client Fixes: Thunderbird, Outlook, Apple Mail
The exact steps differ slightly per app. Here are the specifics for the three that generate the most Gmail IMAP not working questions.
Mozilla Thunderbird. Thunderbird has excellent OAuth support. Right-click the account → Settings → Server Settings, and change "Authentication method" to OAuth2. If it still fails, remove the account and re-add it so Thunderbird triggers a fresh Google sign-in window. A revoked or expired OAuth token is the usual cause when Thunderbird worked yesterday and not today — re-authenticating fixes it.
Microsoft Outlook. This is the sharpest pain point. Legacy Outlook desktop does not support OAuth 2.0 for IMAP or POP connections, and Microsoft has said it has no plans to add it. Your two options are: (1) migrate the account into the new Outlook or Outlook on the web, which handle Google OAuth properly, or (2) stay on classic Outlook and authenticate with a 16-character app password. There is no third path — a classic-Outlook Gmail IMAP not working error will not clear with password tweaks alone.
Apple Mail (Mac & iPhone). Apple Mail supports OAuth, so the fix is usually to remove and re-add the account. Go to Settings → Mail → Accounts (or System Settings → Internet Accounts on Mac), delete the Google account, then add it back via "Add Account → Google," which launches the proper sign-in. This clears the vast majority of "Cannot get mail" errors on iOS and macOS.
Still Stuck? Deeper Causes and Fixes
If you have correct settings and modern authentication but the problem persists, work through these less obvious culprits:
- IMAP connection limit. Gmail allows a maximum of 15 simultaneous IMAP connections per account. If several devices and apps all hammer the same mailbox, new connections get refused. Close duplicate clients or reduce how many folders each device syncs.
- Revoked or expired token. A password change, security event, or long idle period can invalidate an OAuth token. Re-signing in issues a fresh one.
- Blocked sign-in attempt. Check myaccount.google.com → Security → Recent security activity. If Google flagged your client as suspicious, approve it there, then retry.
- Too many messages in one folder. A label or folder with tens of thousands of messages can stall the initial sync. Let it run, or limit which folders sync.
- Antivirus or firewall interference. Some security suites proxy email traffic and break SSL on ports 993/465. Temporarily disable email scanning to test.
- Workspace policy. On business domains, an admin may restrict IMAP or require specific apps. Confirm with your administrator.
Methodically ruling these out resolves the stubborn cases where the standard OAuth and app-password fixes were not enough on their own.
Keeping Bulk and Business Accounts Connected
If you operate many mailboxes — for outreach, support desks, or marketing — the authentication changes hit harder, because every account has to be reconnected the modern way. A few practices keep a large pool stable and prevent a wave of Gmail IMAP not working failures across your fleet:
- Standardize on OAuth 2.0 clients. Choose apps and tools that support Google sign-in natively so you are not managing dozens of app passwords by hand.
- One app password per device where OAuth is impossible, documented in a secure vault, so a single revocation never cascades.
- Enable 2-Step Verification everywhere — it is a prerequisite for app passwords and a baseline security control anyway.
- Respect the 15-connection limit by not pointing too many tools at one mailbox.
- Warm and age accounts properly so they are less likely to trip security flags that block sign-ins in the first place.
Account age and reputation matter here too: established, well-warmed mailboxes attract fewer suspicious-activity blocks than brand-new ones. That reliability is a core reason marketers choose aged Gmail accounts, and it pairs naturally with the connection discipline above. For the security side of running multiple inboxes, our Gmail account security tips cover the habits that keep large pools healthy. And if you rely on pulling mail from other providers, note the separate 2026 shift we documented in Gmail ending Gmailify and POP, which affects fetching in a different way.
Frequently Asked Questions
Why is my Gmail IMAP not working when my password is definitely correct?
Because Gmail no longer accepts a plain password from most apps. Since 2024–2025, Google requires OAuth 2.0 token sign-in and has switched off legacy "less secure app" access. Your password can be perfect and the login still fails. The fix is to re-add the account using "Sign in with Google" (OAuth 2.0), or, for clients that cannot do that, to use a 16-character app password with 2-Step Verification enabled.
What are the correct Gmail IMAP and SMTP server settings?
For incoming mail use imap.gmail.com on port 993 with SSL/TLS. For outgoing mail use smtp.gmail.com on port 465 (SSL) or 587 (TLS/STARTTLS). Your username is your full email address, and authentication should be OAuth 2.0 or an app password — never "normal password" without one. Using the right ports but the wrong authentication type is a common reason Gmail IMAP is not working.
Do I need an app password if I already use OAuth 2.0?
No. OAuth 2.0 and app passwords are two separate paths to the same goal, and you only need one. If your client supports "Sign in with Google," use OAuth — it is more secure and self-refreshing. App passwords exist only for older clients like legacy Outlook desktop, printers, or scripts that cannot perform modern sign-in. Never configure both for the same account.
Why does Outlook keep failing with Gmail when other apps work?
Classic Outlook desktop does not support OAuth 2.0 for IMAP and POP, and Microsoft has stated it will not add it. That is why a Gmail IMAP not working error can appear only in Outlook while Apple Mail and Thunderbird are fine. Either move the account to the new Outlook or Outlook on the web, which support Google sign-in, or authenticate classic Outlook with a 16-character app password.
Is Gmail IMAP being discontinued in 2026?
No. IMAP itself is not going away. What ended is password-based ("less secure app") login. IMAP and SMTP remain fully supported as long as your app authenticates with OAuth 2.0 or an app password. The 2026 story is about how you connect, not whether you can. Once you switch to modern authentication, IMAP works exactly as it always has.
Gmail IMAP not working is almost always an authentication problem in disguise, and it is fixable in minutes once you know that. Turn on IMAP, plug in the correct ports, and switch your client to OAuth 2.0 sign-in — or an app password for the stubborn legacy apps. Do that and your inbox syncs like it used to. Want personalized help getting your clients connected, or looking for reliable, well-aged Gmail accounts that stay stable across email apps? Message us on Telegram at @mixgmail and our team will point you to the right setup for your workflow.