If Outlook, Apple Mail, Thunderbird, or another email client keeps asking for a password while webmail works, the mailbox is reachable but the email application is not completing its separate sign-in to the mail server. The cause may be a changed password, an outdated authentication method, an expired app password, an incomplete OAuth sign-in, or an account lockout.
Table of Contents
Why webmail works while the email client does not
Webmail and an email client use separate connections and sign-in settings. A successful login at mybox Webmail confirms that the mailbox can be reached through the browser. It does not confirm that Outlook, Apple Mail, or Thunderbird has the correct server addresses, ports, password, or authentication method. See the client connection checks.
Common causes of repeated password prompts
The account password changed
After a mailbox password change, the email client may continue using the previous password. The client then retries the old credentials and shows the password prompt again. Sign in to webmail with the current password first. Then update the saved password in the email client. If the client offers to remember the password, save the current value only after the sign-in succeeds.
The stored credentials are incorrect
A password prompt does not always mean that the password itself has changed. The client may have an incorrect account name or an old saved credential. Check that the account uses the complete mailbox address where the client asks for the username, and enter the same current password that works in webmail. Avoid repeated attempts when the account may be locked.
Legacy authentication is blocked
Some email clients or older account profiles use a legacy authentication method. If the mail service no longer accepts that method, entering the correct password will not complete the sign-in. This creates a repeated prompt even though the password works in webmail.
Use the client’s current sign-in option when it is available. If the client supports a modern authorization window, complete that sign-in instead of entering the password into an older prompt. If the client has no supported authentication option, contact mybox support before changing the mailbox password again.
An app password has expired or is no longer valid
An app password is a separate credential used by an email application when the normal account password cannot be used for that sign-in method. If an app password has expired or been revoked, the client can keep rejecting it and asking for another password.
Replace the expired app password with a current one through the account’s approved security process, then update the saved credential in the email client. Do not use an old app password together with a newly changed account password. If the client supports OAuth sign-in, use OAuth instead of an app password when that option is provided.
OAuth authorization is incomplete
OAuth is a sign-in method that sends the user through an authorization window instead of asking the email client to store the account password directly. A repeated prompt can occur when the authorization window was cancelled, did not finish, or is no longer linked to the account profile in the client.
Start the sign-in again from the client’s account settings and complete every authorization step. If the client continues to return to the password prompt, remove the incomplete account profile only if the client allows it without deleting mailbox data, then add the account again using its supported OAuth option. Check the client’s server addresses and ports as part of this process. The client diagnostic steps are listed here.
The account is locked
An account lockout can prevent a valid password or app password from being accepted. Repeated attempts from an email client can continue to produce password prompts while the lockout is active.
Stop repeated sign-in attempts, confirm that webmail access is available, and contact mybox support if the account remains locked or the client continues to reject the known valid credentials. Support can check the account status and advise on the next safe step.
Safe order for fixing the sign-in
- Open mybox Webmail and confirm that the current mailbox password works in the browser.
- Close the repeated password prompt in the email client instead of submitting the same credentials many times.
- Check the client’s account name, server addresses, ports, and authentication setting.
- If the password was recently changed, replace the saved client password with the current one.
- If the client uses an app password, replace an expired or revoked app password with a current credential.
- If OAuth is available, start the authorization flow again and complete it in the sign-in window.
- Send a test message after the client accepts the sign-in. If sending fails with a message that the sender address was rejected because the user is not logged in, the client has not authenticated correctly to the outgoing SMTP server. See the SMTP authentication explanation.
When to contact mybox support
Contact mybox support when webmail accepts the current credentials but the email client keeps rejecting them after its account settings and authentication method have been updated. Include the email client name, the exact error message, and whether the client uses the normal password, an app password, or OAuth. Also contact support if the account may be locked or if the client cannot complete the outgoing-server sign-in.
What to expect after the fix
Once the client uses the correct credentials and a supported authentication method, the repeated prompt should stop. Messages sent from an email client may not appear in the Webmail Sent folder if the client stores sent messages locally or uses a different sent-mail setting. Learn why sent messages may be stored separately.