Email authentication is the process an email service uses to confirm that a mail client is allowed to access an account or send a message. A normal password, an app password, OAuth 2.0, and SMTP AUTH are related, but they do not describe the same part of the connection. This difference explains why a password can work in webmail while an email app rejects it.
Table of Contents
Why webmail and an email app can behave differently
Webmail and a mail app do not use the same connection path. Webmail handles sign-in inside the provider’s website. A mail app must connect to the relevant mail server and authenticate through the protocol used for receiving or sending mail.
For outgoing mail, the app must authenticate with the SMTP server. If it tries to send without being properly logged in to that server, the sender address can be rejected even when the account password works in webmail. mybox describes this error as a sign that the application is not correctly logged in to the outgoing SMTP server. Read the mybox explanation of the “sender address rejected: not logged in” error.
Normal passwords
A normal password is the account credential used to prove identity during sign-in. In a mail app, the password is submitted as part of the authentication exchange with the mail server. The app must also use the account’s correct email address and connect to the correct server service.
A successful webmail login does not by itself prove that the mail app has authenticated to SMTP. The app may be using a separate outgoing-mail setting, an old saved password, or a connection that is not logged in. In that situation, entering the correct password again may not resolve the problem until the SMTP authentication setting is corrected.
Passwords should be protected carefully. A strong password and Two-Step Verification reduce the risk created by brute-force attacks and phishing. mybox recommends strong passwords and Two-Step Verification.
App passwords
An app password is a separate password created for use by a specific application or connection. It is not the same as the account’s main password. Its purpose is to let a mail app authenticate when the app cannot complete the account provider’s normal sign-in process.
Use an app password only when the provider supports it and the mail client requires it. It is not a general replacement for a normal password, and creating one does not correct an SMTP connection that is pointed to the wrong service or is not configured to authenticate.
Because an app password is still a credential, it must be treated as sensitive account information. Do not reuse it for another service or share it with another person. Credential security matters because weak or exposed credentials can put website files, customer data, and professional email at risk. Read mybox’s guidance on credential security.
OAuth 2.0 sign-in
OAuth 2.0 is a sign-in method in which the mail app sends the user through the provider’s authorization screen instead of asking the app to store or submit the account’s normal password directly. After authorization, the provider gives the app an access token. The app uses that token to access the permitted mail service.
OAuth 2.0 requires support from both the email provider and the mail client. If either side does not support the required OAuth sign-in flow, the app cannot use it for that account. In that case, the available method depends on the provider’s supported authentication options and the client’s capabilities.
SMTP AUTH
SMTP AUTH is authentication for the outgoing SMTP connection. It tells the outgoing mail server which account is sending the message and proves that the mail client is allowed to submit mail through that server.
SMTP AUTH is not a separate type of password. It is the authentication step used by the SMTP connection. That step may use a normal password, an app password, or another supported method. A mail app can therefore have a valid account password and still fail to send if SMTP authentication is disabled, incomplete, or connected to the wrong outgoing-mail service.
How to choose the authentication method
- Use a normal password when the provider and mail client support direct password authentication and the account does not require another sign-in method.
- Use an app password when the provider supports app passwords and the mail client cannot use the provider’s normal protected sign-in flow.
- Use OAuth 2.0 when both the provider and the mail client offer OAuth sign-in for the account. This keeps the main password out of the mail app’s password field.
- Check SMTP AUTH whenever outgoing mail fails. Confirm that the app is set to authenticate to the SMTP server. A sender rejection can mean that the app is not logged in to the outgoing server, rather than that the account password is invalid. See the mybox SMTP authentication error guidance.
Practical checks when credentials are rejected
- Confirm that webmail sign-in works with the account credentials.
- Check whether the mail app is asking for a normal password, an app password, or an OAuth sign-in.
- Review the outgoing SMTP account and confirm that authentication is enabled.
- Replace an old saved credential in the mail app if the account password or app password has changed.
- If the app still cannot send, treat the problem as an SMTP authentication issue rather than repeatedly weakening account security or sharing credentials.
The appropriate method is the strongest method supported by both the provider and the mail client. A normal password can be valid but used in the wrong connection. An app password can help an older client, while OAuth 2.0 uses a separate authorization flow. SMTP AUTH remains the key check for outgoing-mail failures because it controls whether the app is authenticated to the sending server.