If you see “email authentication failed on iPhone,” the Mail app has been denied access to an email account. The fastest fix is to confirm the account works in a browser, then sign back in through the correct provider option—not by repeatedly entering a password into a generic IMAP form.

What “email authentication failed” on iPhone actually means

The error is about the connection between the iPhone and the email provider. Apple Mail tries to authenticate—prove that it is allowed to read or send mail for your address—and the provider rejects that attempt. The rejection can happen before Mail downloads messages, when it checks incoming mail, or only when it tries to send through the outgoing SMTP server.

That distinction matters. A password can be correct for the provider’s website but still fail in Mail because the account requires a browser-based Google, Microsoft, Yahoo, or Apple sign-in flow; a one-time verification code; an app-specific password; a company security policy; or different incoming and outgoing server credentials. Apple’s troubleshooting guidance specifically points to checking the account on the provider’s website, verifying security restrictions such as two-step verification, and checking server settings with the provider or system administrator. (support.apple.com)

This is also different from email authentication in the deliverability sense—SPF, DKIM, and DMARC records that help receiving providers evaluate a sender’s domain. Those DNS records affect whether messages are trusted after they are sent. The iPhone error concerns your mail client signing in to a mailbox.

Start with a two-minute diagnosis

Before deleting anything, identify which of these situations matches what you see:

  1. Mail asks for your password repeatedly. This commonly follows a password change, an expired login token, a blocked legacy sign-in method, or a required MFA approval.
  2. You can receive but cannot send. The incoming IMAP or Exchange login may work while the outgoing SMTP server has a bad password, wrong port, disabled SSL/TLS, or an unverified From address.
  3. You cannot receive or send. Treat this as an account-login, provider-outage, or network problem first.
  4. Only a work or school account fails. Your organization may require a managed device, a device-compliance check, Microsoft Authenticator, Company Portal, or the Outlook app.
  5. The error started after changing a password or enabling two-factor authentication. Reauthenticate the account using the provider’s official sign-in screen. For older/manual connections, you may need an app password instead.

Do one decisive test: open Safari or a computer browser and sign in directly at the email provider’s website. Send a message to yourself and confirm it arrives. If the web login fails, fix the provider account first; changing iPhone settings cannot correct a locked account, wrong password, or unfinished security challenge. Yahoo uses the same “sign in on the web, send yourself a test, then troubleshoot the client” sequence in its official guidance. (help.yahoo.com)

The safest fix order for iPhone Mail

Work through these steps in order. They move from low-risk checks to changes that can remove locally downloaded mail.

1. Confirm the iPhone has a working connection

Open a normal website in Safari on both Wi-Fi and cellular data, if available. A captive Wi-Fi portal, VPN, filtering service, or unstable network can prevent Mail from reaching the provider even though the phone appears connected.

Apple recommends confirming that the device is online and checking whether the email provider has an outage before changing mail settings. If the account starts working on cellular but not Wi-Fi, the evidence points to the network rather than credentials. (support.apple.com)

2. Verify the mailbox in a web browser

Sign in to Gmail, Outlook.com, Yahoo Mail, iCloud Mail, or your company’s webmail page. Complete every prompt: password reset, account recovery, suspicious-login review, multi-factor challenge, terms acceptance, or CAPTCHA.

Then send a test email to your own address. A successful browser sign-in proves the account exists and the current credentials work, but it does not prove the iPhone is using the right authentication method. That is why the next step is important.

3. Re-enter credentials from the account settings screen

On current iPhone software, go to Settings > Apps > Mail > Mail Accounts, select the failing account, and look for a password or sign-in prompt. Apple documents this path for managing accounts and for removing and adding accounts. On older iOS versions, the labels can appear as Settings > Mail > Accounts instead. (support.apple.com)

If the iPhone opens the provider’s real login page, use that page. Complete MFA there and approve the requested access. Do not paste a temporary verification code into the normal password field unless the provider explicitly calls it an app password.

4. Restart Mail, then restart the iPhone if needed

Close Mail from the app switcher, reopen it, and pull down to refresh. If authentication still fails, restart the iPhone and retry once. Restarting does not cure an incorrect server configuration, but it removes a stuck session or temporary network state from the equation.

5. Update iOS and retry

An up-to-date operating system helps ensure Mail supports the provider’s current sign-in requirements. This is particularly relevant when a provider has retired older password-only authentication methods or changed its authorization pages. Google advises upgrading older email clients when sign-in errors occur because older clients may not support the security standards it recommends. (support.google.com)

Add the account using the correct provider type

When re-adding an account, the provider choice is not cosmetic. It determines whether Mail uses the provider’s modern authorization flow or asks you for manual server details.

Go to Settings > Apps > Mail > Mail Accounts > Add Account. For a mainstream personal account, select the matching option:

  • iCloud for an @icloud.com, @me.com, or @mac.com mailbox.
  • Google for Gmail or a Google Workspace mailbox.
  • Outlook.com for Outlook.com, Hotmail, Live, or MSN personal accounts.
  • Microsoft Exchange for most Microsoft 365 work or school mailboxes, unless your IT team says otherwise.
  • Yahoo for Yahoo Mail.
  • Other only for a provider that gives you explicit IMAP/SMTP or POP settings.

Apple supports automatic setup for common providers such as iCloud, Google, Microsoft Exchange, and Yahoo. Choosing the provider’s tile lets Mail use its intended setup process, rather than forcing a basic username-and-password connection. (support.apple.com)

A common mistake is selecting Other for Gmail, Outlook, or Yahoo because the email address uses a custom domain. For example, you@yourcompany.com can still be hosted by Google Workspace or Microsoft 365. Ask the domain administrator which service hosts the mailbox; do not infer it from the address alone.

Fix Gmail authentication failures on iPhone

For Gmail and Google Workspace, begin by removing the failed account from Mail and adding it again through Add Account > Google. Look for “Sign in with Google” and complete the Google web sign-in and MFA flow.

Google states that password-only third-party connections are no longer its preferred model and recommends the Sign in with Google option. For personal Gmail accounts, IMAP access is always on; there is no longer an Enable IMAP/Disable IMAP switch to turn on. Google also notes that a changed Google password may require you to re-enter account information or repeat setup in the email client. (support.google.com)

When a Gmail app password is appropriate

An app password is a 16-digit code generated for an app or device that cannot use the normal Google sign-in flow. It is not the first choice for current iPhones using the Google account option. Google says iPhones and iPads running iOS 11 or later do not require app passwords when you use Sign in with Google. (support.google.com)

Use an app password only when all of these are true:

  • You have two-step verification enabled on the Google account.
  • You are configuring a legacy or manual IMAP/SMTP connection that does not offer Sign in with Google.
  • Your Google account actually permits creating app passwords; workplace administrators can restrict this.

If you change the main Google Account password, Google revokes existing app passwords. Generate a replacement only if a manual client truly needs one. (support.google.com)

Gmail manual settings: use only if your provider requires them

For a generic manual client, Gmail’s incoming server is imap.gmail.com on port 993 with SSL. The usual SMTP host is smtp.gmail.com; the provider’s preferred setup route remains its Google sign-in flow rather than a manually stored password. Use your full Gmail address as the username where a manual form asks for one. (support.google.com)

If the iPhone account was configured manually and starts rejecting a correct password, deleting that setup and re-adding it as Google is usually cleaner than trying to convert individual fields in place.

Fix Outlook, Hotmail, Microsoft 365, and Exchange failures

First determine whether this is a personal Microsoft account or an organization-managed account.

For Outlook.com, Hotmail, Live, and MSN, add the mailbox through Outlook.com rather than Other. Microsoft has retired Basic Authentication access for Outlook.com, so password-only configurations can produce repeated password prompts or fail to connect. Microsoft’s support guidance directs users to newer clients or Outlook.com/Exchange syncing that supports modern authentication. (support.microsoft.com)

For Microsoft 365 or Exchange work accounts, use Microsoft Exchange when adding the account unless your IT administrator gives different instructions. The iPhone may redirect you to your organization’s Microsoft sign-in page, require an MFA prompt, or ask you to install a management profile.

Why a work account can work on the web but fail in Apple Mail

A company can enforce Conditional Access rules that limit which apps and devices may access Exchange Online. Microsoft documents configurations that require an iOS device to be enrolled and compliant in Intune and that require the Outlook app for access to company email. In that setup, Apple Mail can be rejected even when the username, password, and MFA approval are all correct. (learn.microsoft.com)

The practical fix is not to keep retrying the password. Contact IT and ask these exact questions:

  • Is Apple Mail / Exchange ActiveSync allowed for my account?
  • Does my iPhone need to enroll in Intune or install Company Portal?
  • Is Outlook for iOS required by Conditional Access?
  • Is there a device-compliance, app-protection, or MFA policy blocking this sign-in?

If the answer is that Outlook for iOS is required, that is an organization policy decision—not a fault in iPhone Mail.

Fix Yahoo Mail authentication failures

For Yahoo Mail, delete the failed account only after confirming your messages are visible on Yahoo’s website, then add it back using Add Account > Yahoo. Complete the Yahoo sign-in and any verification prompts.

Yahoo says that third-party apps such as Apple Mail use IMAP or POP to connect, and that an app password is required when Yahoo Account Key or two-step verification is enabled. Its guidance also says stored connection data can be corrupt even where the visible settings look correct, which is a reason to remove and re-add the account after verifying web access. (help.yahoo.com)

For a manual Yahoo setup, use the full address as the username and an app password as the password when one is required. Yahoo publishes these settings:

SettingValue
Incoming serverimap.mail.yahoo.com
IMAP port993
Incoming securitySSL required
Outgoing serversmtp.mail.yahoo.com
SMTP ports465 or 587
Outgoing securitySSL required
SMTP authenticationRequired

Those values are Yahoo-specific. Do not reuse them for another host just because the address ends in a custom domain. (help.yahoo.com)

Fix iCloud Mail authentication failures

If your iPhone is signed in to the Apple Account that owns the iCloud mailbox, iCloud Mail should normally be configured through the iCloud account rather than manually as Other. Confirm you can sign in to the Apple Account and that iCloud Mail is enabled for it.

When a third-party or manual mail client must access iCloud Mail, Apple requires an app-specific password. Generating these passwords requires two-factor authentication on the Apple Account. Apple also notes that supported third-party apps may authorize through the Apple Account instead, avoiding the need for an app-specific password. (support.apple.com)

iCloud manual settings

Apple publishes the following iCloud Mail settings for manual clients:

SettingValue
Incoming serverimap.mail.me.com
IMAP port993
Incoming securitySSL required; TLS can help if SSL errors
Outgoing serversmtp.mail.me.com
SMTP port587
Outgoing securitySSL required; TLS or STARTTLS can help if SSL errors
SMTP authenticationRequired
PasswordAn Apple app-specific password

iCloud Mail supports IMAP and SMTP, not POP. Apple says the incoming username is usually the mailbox name portion but advises trying the full address if the shorter form fails; the SMTP username is the full iCloud address. (support.apple.com)

Check the outgoing SMTP server when receiving works but sending fails

An authentication error that appears only after pressing Send is often an SMTP issue. Mail can authenticate to the incoming server successfully, display your inbox, and then fail when the outgoing server rejects the credentials or the sender identity.

Open the affected account in Settings > Apps > Mail > Mail Accounts, then inspect its outgoing mail server settings if iOS exposes them for that account type. Compare every value with your provider’s official documentation:

  • SMTP hostname
  • Port number
  • SSL/TLS or STARTTLS requirement
  • Authentication enabled or disabled
  • Full email address versus mailbox-only username
  • Password or app-specific password
  • Default From address and any sending alias

For manually configured accounts, an incoming IMAP password and an outgoing SMTP password are sometimes stored separately. Update both. If the account uses an alias such as sales@domain.com, confirm the provider has authorized that address to send; Yahoo, for example, notes that an unverified extra email address can trigger a 553 sending error in third-party apps. (help.yahoo.com)

Worked example: Gmail starts failing after a password change

Assume Maya uses maya@example.com, hosted on Google Workspace. She changes her Google password on a laptop. The iPhone Mail app then displays an authentication error and asks for the old password repeatedly.

Step 1: Prove the account is healthy

Maya signs in to her organization’s Google webmail page using the new password and approves her MFA prompt. She sends a message to a personal address and receives it. That rules out a disabled mailbox and a wrong new password.

Step 2: Avoid manual IMAP repair

Her iPhone account was added years ago as Other with imap.gmail.com. Rather than inserting the new password into fields that may be using an old authentication model, she goes to Settings > Apps > Mail > Mail Accounts, selects the account, and chooses Delete Account.

Before deleting, she checks that important messages are visible in webmail. Apple warns that changing or deleting an account can remove emails previously downloaded to the device, even though the account settings themselves are backed up. (support.apple.com)

Step 3: Add it through Google

Maya returns to Mail Accounts > Add Account > Google, enters the email address, and completes the Google sign-in page with MFA. She enables Mail when iPhone asks what to sync.

This produces a Google-authorized connection instead of relying on a generic password-only setup. Google recommends this route and specifically advises removing Gmail information and signing in again with Sign in with Google when an email client cannot authenticate. (support.google.com)

Step 4: Verify both directions

Maya opens Mail, pulls down to refresh, and confirms a new webmail message appears. She then sends a fresh email from the iPhone to a second account and confirms it arrives. The fix is complete only when both receive and send work without another password prompt.

When to remove and re-add the account

Removing an account is often the most effective repair, but it should not be the first reflex. Use it when you have confirmed web access and one of the following is true:

  • Re-entering the password does not stop the prompt.
  • The account was added using the wrong provider type.
  • The provider recently changed the password or MFA requirement.
  • IMAP/SMTP fields may contain old or corrupt saved data.
  • The same account works in webmail but will not renew access in Mail.

Before removal, make sure mail is stored on the provider’s server and visible in webmail. Apple cautions that deleting or changing an email account can remove previously downloaded mail from the device. After removal, add the account through the named provider option whenever one exists. (support.apple.com)

Do not remove a work account if your organization manages it and you are unsure whether it installs a profile, certificate, VPN, contacts, calendars, or compliance settings. Ask IT first.

Problems that look like authentication but are not

Not every missing-email problem is a sign-in failure. Sorting the symptom prevents unnecessary account deletion.

Mail works only when you open the app

This can be a Fetch or Push schedule issue, not authentication. Apple explains that Fetch New Data settings determine how the iPhone receives mail and that some accounts default to Fetch when Push is unavailable. In the current settings path, open Settings > Apps > Mail > Mail Accounts > Fetch New Data and choose a suitable schedule. (support.apple.com)

New messages are delayed but no error appears

Check Wi-Fi, Low Power Mode behavior, Fetch settings, provider status, and mailbox size. Authentication is less likely if you can refresh successfully by hand.

Only old messages are missing

That is usually a sync-window, folder, archive, label, or account-retention issue. It is not proof of a rejected login. For Gmail, remember that labels and folders are mapped into the IMAP client experience, which can make message location look different from Gmail on the web. (support.google.com)

You receive but messages will not leave Outbox

Treat it as an outgoing SMTP or network problem first. Test by sending a plain-text message to yourself with no attachment, then inspect the outgoing server and sender alias settings.

How to know the problem is fixed

Do not stop when the red error banner disappears. Confirm the whole mail flow:

  1. Pull down to refresh Mail and verify a newly sent webmail test arrives on the iPhone.
  2. Send a new message from the iPhone to a separate address you can check.
  3. Confirm the sent message appears in Sent and the recipient receives it.
  4. Lock and unlock the iPhone, reopen Mail later, and ensure it does not immediately request the password again.
  5. For work accounts, verify Calendar and Contacts too if they are meant to sync.

A stable fix has three characteristics: no recurring sign-in prompt, new inbound mail syncs, and outbound mail sends. If only one direction works, keep troubleshooting the specific server path rather than treating the account as fully repaired.

FAQ

Why does my iPhone say authentication failed when my password is correct?

The provider may require a browser-based OAuth sign-in, MFA approval, an app-specific password, or a company device policy. A correct website password does not always work in an old manual IMAP/SMTP configuration. Google and Microsoft both direct users toward modern authentication rather than password-only access for supported clients. (support.google.com)

Will deleting an email account delete my emails?

It can remove messages that were downloaded only to the iPhone. Check the provider’s webmail first and confirm important messages are present there or backed up elsewhere. Apple explicitly warns that deleting or changing an email account may remove previously downloaded device mail. (support.apple.com)

Should I use an app password on my iPhone?

Usually not for a current iPhone when the provider offers its own account option and web sign-in. Use an app password only for a manual or legacy connection that the provider says requires one. Gmail recommends Sign in with Google for iOS 11 and later; Yahoo and iCloud document app passwords for applicable third-party access cases. (support.google.com)

Why does my work Microsoft 365 email work in Safari but not Apple Mail?

Your employer may block native mail clients or require a compliant, managed device and Outlook for iOS through Microsoft Intune and Conditional Access. Ask IT whether Apple Mail is permitted and what enrollment or app requirements apply. (learn.microsoft.com)

Is “email authentication failed” related to SPF, DKIM, or DMARC?

No. The iPhone message is normally about logging in to a mailbox. SPF, DKIM, and DMARC are domain-level systems used by receiving services to evaluate messages after they are sent.