How to Connect Gmail to a Desktop Client with an App Password
2026-08-09
"I tried to add Gmail to my desktop mail app and the password was rejected." That's a common moment of confusion. Since 2022, as part of strengthening security, Google no longer accepts your ordinary account password for IMAP/SMTP connections. So how do you connect Gmail to a third-party mail client? The answer is a dedicated app password — a 16-character code you generate on an account with two-step verification enabled. This article explains how to create one and why the method works this way.
Why your normal password no longer works
There used to be a setting like "allow less secure app access" that let you connect with your ordinary password. But handing your normal password to each app carries big risk if it leaks, and Google phased it out. In its place came app passwords. These can be issued per app, disabled individually at any time, and — even if one leaks — your account's main password stays protected. It's a safer mechanism.
"Making a separate dedicated password" may sound like a chore, but once set up you never have to think about it again. And thanks to this method, your account is protected more firmly. A little initial setup buys both security and convenience — hardly a bad trade. Let's walk through the concrete steps.
The steps to create one
- Enable 2-Step Verification. App passwords can only be issued on an account with two-step verification on. If you haven't yet, turn it on in your Google Account security settings.
- Open the app passwords page and generate a new password. Give it a purpose name (e.g. Zephmail) so it's easy to manage later.
- Copy the displayed 16 characters and paste them into your mail client's password field.
That's it. No OAuth consent-screen setup, no Google Cloud developer console, no complex per-app configuration. It usually takes a few minutes.
Common stumbling points
- The app passwords page doesn't appear: Two-step verification is probably not enabled. Complete step 1 first.
- Pasting the 16 characters with spaces: Google shows them space-separated, like "abcd efgh ijkl mnop." Pasting with spaces can cause a login failure, so it's safer to enter them without spaces (some clients strip them automatically).
- It stopped working after a password change: Changing your account's main password invalidates app passwords. Re-issue one in that case.
Why an app password instead of OAuth
"Sign in with Google" (OAuth) may look sleeker. But for a small desktop client, full-mail-access OAuth has a big hurdle. Gmail's full-access scope falls under Google's "restricted scopes," and to offer it to the general public, the developer must pass Google's review plus a paid, annual security assessment (CASA). That's a heavy cost and time burden, often impractical for a small desktop app.
The app-password approach avoids that burden and lets you get started easily without fiddly OAuth setup. The user's effort is just "enable two-step verification and issue one password." And the credential is stored safely in the OS keychain (Windows Credential Manager), not in a plain-text config file or the cloud.
What is two-step verification, exactly?
A brief word on two-step verification, the prerequisite for app passwords. It protects login with "another factor" in addition to your password — a code sent to your phone, an authenticator app display, or a physical security key. Even if your password leaks, no one can log in without the second factor, so security rises sharply. Google requiring two-step verification as a prerequisite for app passwords is sound design: "if we're handing out dedicated passwords, keep the account itself doubly protected." For those who haven't enabled it, this is a good chance to raise your security baseline.
A checklist for when the connection fails
If mail won't arrive or send after setup, check these in order. 1. Are you using the app password? Not your normal login password, but the issued 16 characters. 2. Are stray spaces mixed in? Not pasting "abcd efgh ..." with its spaces (remove them). 3. Is two-step verification on? If off, you can't even issue an app password. 4. Is IMAP enabled? Some accounts need IMAP access turned on in Gmail. 5. Did you recently change your password? A main-password change invalidates app passwords. Most trouble resolves at one of these five points.
Check sending as well as receiving
Right after setup, it's reassuring to confirm not just receiving (IMAP) but sending (SMTP). An easy test is to send one message to yourself. If you can receive but sending errors, the SMTP port or settings can be the cause — though if the app auto-configures from your address, it's usually not an issue. Zephmail has a "connection test" that verifies both receiving and sending before you save. Confirm the green check here first and you won't be caught off guard when it matters.
The security advantages of app passwords
An app password means more than "a substitute for your normal password." First, because it's issued and managed per app, when an app is no longer needed you can disable just that one password without affecting your account's main password or other apps. Second, even if an app password leaks, all it can do is send and receive mail — your whole Google account (YouTube, Drive, payment info) stays protected. Third, changing your account's main password invalidates issued app passwords. So a safety valve works: "if something feels off, change the main password and all app passwords cascade to invalid."
IMAP and SMTP basics
Mail-client setup brings up the words "IMAP" and "SMTP." Roughly, IMAP is the mechanism for receiving and viewing mail; SMTP is for sending. For Gmail, IMAP uses imap.gmail.com (port 993) and SMTP uses smtp.gmail.com (port 587, among others). You don't need to memorize the numbers — many clients auto-detect them from your email address. The app password is used for logging into this IMAP/SMTP; that's the whole picture.
Review your app passwords periodically
An app password isn't "issue and forget" — an occasional inventory keeps you safe. Disable passwords for apps or devices you no longer use. From your Google Account security settings you can see the list of issued app passwords and delete unneeded ones individually. Issuing with a purpose name makes this review much easier. If a password is left where "I can't tell which app it's for," that's a candidate for deletion. Periodic tidying is a simple, effective habit for the just-in-case.
How this relates to passkeys and security keys
Newer authentication methods like passkeys and physical security keys have spread recently. These mainly strengthen browser sign-in and serve a different role from connecting a mail client over IMAP/SMTP. For connections from mail software, app passwords remain the standard means. So you protect the browser with the latest authentication while connecting the mail client with an app password — a division of labor. They don't compete; think of it as using the right key for each situation.
The same idea in other mail software
The flow described here isn't specific to Zephmail — it's common to many desktop and mobile mail apps, Thunderbird included. "Enable two-step verification, issue an app password, paste it into the client" is a standard practice for using Gmail with third-party software. Learn it once and you can set up the same way even after switching apps.
What about iCloud and other providers?
The idea is shared. iCloud has "app-specific passwords," and other services support their own app passwords. All follow the same flow: "enable two-step verification, issue a dedicated password, paste it into the client." The location of the issuing page differs by provider, but the purpose and steps don't change.
Frequently asked questions
How many app passwords can I create? You can issue several, one per purpose. Splitting them by device or app makes it easy to disable individually later.
Can I view a password again after issuing it? No. It's shown only once at issuance, so set it in the client on the spot. If you forget it, disable it and re-issue.
Won't enabling two-step verification make login a hassle? Your everyday browser login stays as usual. An app password is just an extra key for individual apps like a mail client.
Does it work with a company Google Workspace account? Often the same steps apply, but some organizations have administrators restricting two-step verification, app passwords, or IMAP access. If it doesn't work, check the settings policy with your internal administrator. In restricted environments, one approach is to try a personal account first to gauge the experience.
Isn't it dangerous if someone learns my app password? Yes, so handle it with care. An app password is a key that can access the target mail account, so don't share it. If you suspect a leak, immediately disable that app password in your Google Account settings and access with it is cut off at once. In Zephmail, pasted credentials are stored in the OS keychain and never remain in plain text in a file.
Wrapping up
To use Gmail in a desktop mail client, use an app password predicated on two-step verification, not your normal password. The steps are just three: "enable two-step verification, issue the 16 characters, paste them into the client." No complex OAuth setup is needed, and the credential is stored safely in the OS keychain. The usual snags — "entering the normal password," "pasting with spaces," "two-step verification not set" — are all solved by this article's checklist. Learn it once and the same idea carries to other mail software and other providers. Get past the first few minutes of setup and you can keep using mail comfortably without ever thinking about the password. With Zephmail, even those few minutes are shortened further by guidance and one-click helpers. Don't overthink it — follow the on-screen guidance and you'll reach a working connection without getting lost.
Zephmail guides it with one click
Zephmail makes this process as easy as possible. Type a Gmail address in account setup and a guide with buttons that open the exact Google pages for "Open two-step verification" and "Issue an app password" appears automatically, and the IMAP/SMTP server settings are filled in for you. Then just paste the issued 16 characters and save. In a few minutes, you're up and running — AI integration included.
Zephmail