Email Client Setup (Outlook, Mobile)

How to Use App Passwords and OAuth 2.0 in Google Workspace: A Complete Setup Guide

By the Domain India teamPublished 9 min read
Knowledge base article
Contents (9 sections)

Google Workspace no longer accepts a plain username and password from mail apps. If Outlook, Thunderbird, a phone or a scanner keeps asking for your password or reports "incorrect password" even though it is right, this is almost always why. This guide explains the two methods that work now, OAuth 2.0 sign-in and app passwords, and how to set up each one.

This guide is for Google Workspace

It does not apply to Domain India Business Email, which is a separate product with its own settings. See Business Email vs the email included with your hosting.

Key takeaways

Google has turned off "less secure app" access for Workspace accounts, so mail apps must sign in with OAuth 2.0 (the app opens a Google sign-in window) or, for older apps and devices that cannot do that, an app password. Use OAuth wherever the app supports it. App passwords work only when 2-Step Verification is on, and you create them at myaccount.google.com/apppasswords. Devices such as scanners are often better served by Google's SMTP relay, set up by your Workspace admin.

1. What changed in Google Workspace sign-in

For years, mail apps could connect to Gmail over IMAP, POP and SMTP with just your email address and password. Google called these "less secure apps", because a stolen password was all an attacker needed.

Google phased this out for Workspace accounts, and the final step took effect in 2025. Today:

  • Password-only sign-in from mail, calendar (CalDAV) and contacts (CardDAV) apps is refused.
  • OAuth 2.0 ("Sign in with Google") is the standard method.
  • App passwords remain as a fallback for apps that cannot do OAuth, and only for accounts with 2-Step Verification.
  • The old "Less secure app access" setting no longer exists, for users or admins.

2. OAuth 2.0 or app password: which to use

QuestionOAuth 2.0App password
How you sign inA Google sign-in window opens; you approve accessYou paste a 16-character code instead of your password
Needs 2-Step VerificationNo (but strongly recommended)Yes, always
Works withCurrent Outlook, Apple Mail, iPhone and iPad Mail, Thunderbird, Gmail appOlder apps, some devices and scripts that ask only for a password
Password stored in the appNo, a revocable tokenYes, the app password
Changing your Google passwordMail apps may ask you to sign in againGoogle revokes your app passwords
RecommendedYes, first choiceOnly when OAuth is not available

3. Set up a mail app with OAuth 2.0

In current apps, OAuth is automatic when you choose the right account type.

  1. Add a new account
    in your mail app.
  2. Choose "Google"
    (Apple Mail, iPhone, iPad) or just enter your Workspace address (Outlook, Thunderbird). The app detects Google and opens a sign-in window.
  3. Sign in with your normal Google password
    and complete 2-Step Verification if it is on.
  4. Approve the access
    the app asks for, such as mail, contacts and calendar.
  5. Finish.
    The app stores a token, not your password. You can remove its access at any time in your Google Account under Security.

If you add the account manually in Thunderbird, choose OAuth2 as the authentication method, not "Normal password". The server settings are:

ServiceServerPortSecurity
IMAP (incoming)imap.gmail.com993SSL/TLS
POP (incoming)pop.gmail.com995SSL/TLS
SMTP (outgoing)smtp.gmail.com465 or 587SSL/TLS on 465, STARTTLS on 587

If the app never opens a Google window and only offers a password box, it is too old for OAuth. Update it, or use an app password.

4. Create and use an app password

An app password is a 16-character code that lets one app sign in without OAuth. It gives full access to your mailbox, so treat it like a password.

  1. Turn on 2-Step Verification.
    Go to myaccount.google.com, open Security, and set up 2-Step Verification if it is off.
  2. Open the App passwords page
    directly at myaccount.google.com/apppasswords. It is not always shown in the Security menu, so use the address or search "App passwords" in your Google Account.
  3. Type a name
    for the app, such as "Office scanner" or "Outlook 2016 on reception PC", and click Create.
  4. Copy the 16-character code
    shown. Google shows it only once.
  5. Paste it into the app's password field
    in place of your Google password. Use your full Workspace email address as the username.
If the App passwords page says the setting is not available

Google does not offer app passwords when 2-Step Verification is off, when your account uses only security keys for 2-Step Verification, or when Advanced Protection is on. In a Workspace organisation, your admin's security settings can also affect it. Ask your Workspace admin.

Remove app passwords you no longer use from the same page. Google also revokes them all when you change your account password, so you then need new ones.

5. What the Workspace admin needs to check

If users in your organisation cannot connect even with OAuth, an administrator should check these in the Google Admin console (admin.google.com). Menu names can move as Google updates the console.

  • IMAP and POP access: Apps › Google Workspace › Gmail › End User Access. Turn on IMAP and, if you use it, POP for the right organisational unit. You can also restrict IMAP to OAuth mail clients only.
  • Third-party app access: Security › Access and data control › API controls. If your organisation restricts unconfigured apps, the mail apps your staff use (for example Outlook or Thunderbird) must be allowed there.
  • 2-Step Verification: Security › Authentication › 2-Step Verification. Allow it for everyone, and enforce it if you can.
  • Sign-in events: Reporting › Audit and investigation › Login log events, to see failed sign-ins and the method used.

6. Scanners, printers and website forms that send email

Many multifunction printers, CCTV systems and older scripts only support a username and password for SMTP.

App password
Quickest fix for one device. The device signs in to smtp.gmail.com with the Workspace address and an app password.
SMTP relay
The Workspace admin sets up Google's SMTP relay service (Apps › Google Workspace › Gmail › Routing) and allows the office's public IP or requires SMTP authentication. Better for many devices.
Website mail
For a website on hosting, send through the hosting server's own mail or an OAuth-capable plugin instead of storing a Google password in site files.

For a website on Domain India hosting, see PHP sendmail settings.

7. Troubleshooting

SymptomLikely causeFix
"Incorrect password" with the right passwordThe app is using password-only sign-inRemove the account and add it again with OAuth, or use an app password
No Google sign-in window appearsApp version too old for OAuthUpdate the app, or use an app password
App passwords page not available2-Step Verification off, security keys only, or Advanced ProtectionTurn on 2-Step Verification with a phone or app method, or ask your admin
Worked for months, then stoppedGoogle password changed, so app passwords were revokedCreate a new app password
"IMAP access disabled" or similarIMAP turned off for your organisational unitWorkspace admin turns on IMAP in End User Access
Sending from a device failsDevice cannot do OAuthUse an app password or the SMTP relay service

For all Workspace server names and ports in one place, see Google Workspace email settings: ports, servers and SSL.

8. Good security habits

  • Use OAuth whenever the app supports it, and keep app passwords for the few devices that need them.
  • Give each device its own app password, named clearly, so you can revoke one without breaking the rest.
  • Turn on 2-Step Verification for every user; as an admin, enforce it.
  • Review connected apps and app passwords every few months and remove old ones.
  • Never put your main Google password in a script, a website config file or a shared device.

9. Email options at Domain India

If you want mailboxes on your own domain from Domain India itself, Business Email costs ₹60 per mailbox per month (Domain India list price on 19 September 2026, excluding 18% GST). It includes webmail with calendar and contacts, IMAP and SMTP over TLS for Outlook, Apple Mail, Thunderbird and phones, and two-factor authentication. Email accounts are also included with our shared hosting plans.

Business Email
₹60/mo + GST
  • Priced per mailbox - start with one
  • Email at your own domain ([email protected])
  • Add and remove mailboxes yourself
  • Webmail with calendar, contacts and tasks
See plan details
Why does Google Workspace say my password is incorrect in Outlook or Thunderbird?

Google Workspace no longer accepts password-only sign-in from mail apps. The app must use OAuth 2.0 (a Google sign-in window) or, if it cannot, an app password created at myaccount.google.com/apppasswords.

Do I need 2-Step Verification to use an app password?

Yes. App passwords are only available when 2-Step Verification is turned on. They are not offered if the account uses only security keys for 2-Step Verification or has Advanced Protection turned on.

How long is a Google app password?

It is 16 characters. Google shows it once when you create it. You enter it in the app's password field instead of your normal Google password.

Do app passwords stop working when I change my Google password?

Yes. Google revokes your app passwords when you change your account password, so you need to create new ones for each app or device.

What are the IMAP and SMTP settings for Google Workspace?

Incoming IMAP is imap.gmail.com on port 993 with SSL/TLS. Outgoing SMTP is smtp.gmail.com on port 465 with SSL/TLS or port 587 with STARTTLS. Use OAuth 2.0 or an app password to sign in.

How do I send email from a scanner or printer through Google Workspace?

Either give the device an app password for smtp.gmail.com, or have your Workspace admin set up Google's SMTP relay service, which can accept mail from your office's IP address without storing a password on the device.

Does this guide apply to Domain India Business Email?

No. Domain India Business Email is a separate product with its own webmail at mail.yourdomain.com on port 8443 and its own settings.

Ready to set up professional email on your own domain? Compare Business Email with the mailboxes included in cPanel hosting, or open a ticket if you need help choosing.

Email on your own domain

Mailboxes at your own domain with webmail, calendar, contacts and two-factor authentication, priced per mailbox.

See Business Email

Ready when you are

Get Business Email from ₹60/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app