{"id":14103,"date":"2026-09-21T09:28:38","date_gmt":"2026-09-21T07:28:38","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=14103"},"modified":"2026-09-21T09:28:42","modified_gmt":"2026-09-21T07:28:42","slug":"oauth-sign-in-loops-in-outlook-apple-mail-and-thunderbird-causes-and-fixes","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/en\/knowledgebase\/oauth-sign-in-loops-in-outlook-apple-mail-and-thunderbird-causes-and-fixes\/","title":{"rendered":"OAuth Sign-In Loops in Outlook, Apple Mail, and Thunderbird: Causes and Fixes"},"content":{"rendered":"\n<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">An OAuth sign-in loop occurs when Outlook, Apple Mail, Thunderbird, or another email client repeatedly opens a sign-in window, rejects credentials that work elsewhere, or returns to the login screen after authentication. The mailbox may still be available in webmail. In that situation, the email application is not completing its separate sign-in to the mail server.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The cause can be on the provider side or in the email client. A changed password, outdated authentication data, an incomplete browser approval, or a security policy that requires an extra sign-in method can interrupt the authorization process.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/oauth-sign-in-loops-in-outlook-apple-mail-and-thunderbird-causes-and-fixes\/#How_an_OAuth_sign-in_loop_works\" >How an OAuth sign-in loop works<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/oauth-sign-in-loops-in-outlook-apple-mail-and-thunderbird-causes-and-fixes\/#Provider-side_causes\" >Provider-side causes<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/oauth-sign-in-loops-in-outlook-apple-mail-and-thunderbird-causes-and-fixes\/#Client-side_causes\" >Client-side causes<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/oauth-sign-in-loops-in-outlook-apple-mail-and-thunderbird-causes-and-fixes\/#Steps_to_stop_the_sign-in_loop\" >Steps to stop the sign-in loop<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/oauth-sign-in-loops-in-outlook-apple-mail-and-thunderbird-causes-and-fixes\/#What_differs_between_Outlook_Apple_Mail_and_Thunderbird\" >What differs between Outlook, Apple Mail, and Thunderbird<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/oauth-sign-in-loops-in-outlook-apple-mail-and-thunderbird-causes-and-fixes\/#When_to_contact_the_provider_or_administrator\" >When to contact the provider or administrator<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_an_OAuth_sign-in_loop_works\"><\/span>How an OAuth sign-in loop works<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<\/div>\n\n<div id=\"mybox-467943933\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Early access<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Still need help?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contact our customer service team.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Message us<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">OAuth sign-in normally moves between the email client and a browser-based sign-in page. The client starts authorization, the browser handles the account sign-in and any required consent, and the client receives the result. If that result is not returned or accepted, the client can start the same process again.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The visible error does not always mean that the password is invalid. If webmail works but Outlook, Apple Mail, or Thunderbird keeps asking for credentials, the mailbox is reachable and the email application is failing to complete its separate sign-in to the mail server. <a href=\"https:\/\/mybox.com\/help\/knowledgebase\/email-client-keeps-asking-for-your-password-causes-and-fixes\/\">mybox explains this distinction in its email client troubleshooting article<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Provider-side_causes\"><\/span>Provider-side causes<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A provider-side security requirement can prevent the client from completing authorization even when the account credentials are correct. The provider may require browser consent, a new authentication step, an app password, or an administrator action before the application can connect.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These requirements are controlled by the mailbox provider or administrator. An email client cannot bypass a policy that blocks its sign-in method. If the browser sign-in completes but access is still refused, the next step is to check whether the account needs an additional approval or whether an administrator must allow the application.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Client-side_causes\"><\/span>Client-side causes<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The email client can also retain outdated authentication data. This may happen after a password change, an account security change, or an interrupted browser redirect. The client then retries with stale authorization data instead of starting a clean sign-in.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Outlook, Apple Mail, and Thunderbird all use their own account and credential storage. The exact screens differ, but the useful test is the same: remove the stored sign-in state for the affected mailbox, then add or authenticate the account again. Do not remove the mailbox until you have confirmed that the account can be added again and that any local mail is safe to remove.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Steps_to_stop_the_sign-in_loop\"><\/span>Steps to stop the sign-in loop<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Test webmail first.<\/strong> Sign in to the mailbox through webmail. If webmail also rejects the sign-in, the issue is not limited to the email client and may require account or provider support.<\/li>\n\n\n\n<li><strong>Check the account password.<\/strong> A changed password is a common reason for repeated prompts. Update the saved password in the email client rather than continuing to retry the old one. <a href=\"https:\/\/mybox.com\/help\/knowledgebase\/email-client-keeps-asking-for-your-password-causes-and-fixes\/\">A changed password is listed as a cause of repeated email client prompts<\/a>.<\/li>\n\n\n\n<li><strong>Complete the browser sign-in fully.<\/strong> When the client opens a browser, finish the sign-in and any consent or approval screen. Return to the email client only after the browser confirms the process.<\/li>\n\n\n\n<li><strong>Clear stale authorization data.<\/strong> Remove the saved credentials or account authorization entry for the affected mailbox from the email client, then start the account sign-in again. This gives the client a new authorization attempt instead of reusing an expired or rejected result.<\/li>\n\n\n\n<li><strong>Update the email client.<\/strong> Install the available update for Outlook, Apple Mail, or Thunderbird before trying again. An older client may not complete the current authentication flow correctly.<\/li>\n\n\n\n<li><strong>Check the outgoing sign-in separately.<\/strong> Sending mail uses authentication to the outgoing mail server. If sending fails with a message such as \u201csender address rejected: not logged in\u201d, the client is not correctly authenticated to SMTP. <a href=\"https:\/\/mybox.com\/help\/knowledgebase\/sender-address-rejected-not-logged-in\/\">The mybox troubleshooting article describes this outgoing-server authentication error<\/a>.<\/li>\n\n\n\n<li><strong>Use an app password only when required.<\/strong> If the provider or administrator requires an app password for the client, use the app password supplied through that account&#8217;s security process. An app password is not a replacement for a normal password unless the provider specifically requires it.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_differs_between_Outlook_Apple_Mail_and_Thunderbird\"><\/span>What differs between Outlook, Apple Mail, and Thunderbird<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Email client<\/th><th>What to check<\/th><\/tr><\/thead><tbody><tr><td>Outlook<\/td><td>Complete the browser sign-in, then clear the stored account authentication if Outlook returns to the login window.<\/td><\/tr><tr><td>Apple Mail<\/td><td>Complete the browser approval and remove the affected saved account authorization if Mail repeatedly requests sign-in.<\/td><\/tr><tr><td>Thunderbird<\/td><td>Complete the browser authorization, then replace stale saved credentials or account authentication data before trying again.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">These clients use different account interfaces, but the diagnostic order remains useful for each: confirm webmail access, complete browser authorization, clear stale sign-in data, update the client, and then check whether the provider requires an app password or administrator approval.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"When_to_contact_the_provider_or_administrator\"><\/span>When to contact the provider or administrator<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Contact support or the account administrator when webmail works but every sign-in attempt from the client is rejected after the browser process completes. This is especially important when the account is subject to a security policy or when an app password, application approval, or administrator permission is required.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For a manual account setup, the email client needs the correct server addresses and ports for the mailbox. <a href=\"https:\/\/mybox.com\/help\/knowledgebase\/how-to-configure-the-email-client\/\">mybox provides the required server settings for manual email client configuration<\/a>. A successful webmail sign-in does not by itself confirm that the client has the correct server settings or that its outgoing server authentication is complete.<\/p>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[41],"manual_kb_tag":[],"class_list":["post-14103","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-email"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/14103","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/14103\/revisions"}],"predecessor-version":[{"id":14104,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/14103\/revisions\/14104"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/media?parent=14103"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manualknowledgebasecat?post=14103"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb_tag?post=14103"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}