Gmail SMTP Settings: Server, Ports, and App Passwords (2026)

A settings gear, an envelope, and a padlock with a key beside a server, with a blue cable plugged into the server's port.

Gmail’s SMTP server is smtp.gmail.com. Use port 587 with STARTTLS or port 465 with SSL, sign in with your full email address, and supply an app password or an OAuth 2.0 token instead of your normal password.

SettingValue
Outgoing (SMTP) serversmtp.gmail.com
Port, STARTTLS587 (TLS)
Port, implicit SSL465 (SSL)
AuthenticationRequired
UsernameYour full Gmail or Google Workspace address
PasswordAn app password (needs 2-Step Verification) or an OAuth 2.0 access token
Incoming (IMAP) serverimap.gmail.com, port 993, SSL
Incoming (POP) serverpop.gmail.com, port 995, SSL

Sources: Google’s Gmail POP settings page (SMTP on 587, POP on 995), Google Workspace’s printer, scanner, or app article (465 for SSL, 587 for TLS), and the third-party email client guide (IMAP on 993).

Not sure which port to pick? See port 587 vs 465. Deciding between the two incoming protocols? See IMAP vs POP3.

Why your Gmail password stopped working: app passwords and OAuth

Plain username-and-password sign-in no longer works for third-party apps. Google’s transition guide says access to less secure apps was turned off for all Google Accounts on March 14, 2025, covering CalDAV, CardDAV, IMAP, SMTP, and POP with legacy passwords. It adds: “You will no longer use a password for access (with the exception of app passwords).” For Google Workspace, the printer and app article states that “Starting May 1, 2025, Google Workspace accounts no longer support less secure apps, third-party apps, or devices that ask you to sign in to your Google Account with your username and password.”

You have two ways to authenticate SMTP today.

Option A: OAuth 2.0 (Google’s preferred route). Google’s XOAUTH2 documentation says applications must use the scope https://mail.google.com/ for IMAP, POP, and SMTP access. For SMTP, the client sends AUTH XOAUTH2 followed by the base64-encoded string user= plus the address, auth=Bearer plus the access token, each separated by a Control+A character.

Option B: an app password. Google’s app password page describes it as “a 16-digit passcode that gives a less secure app or device permission to access your Google Account” and adds that “App passwords aren’t recommended and are unnecessary in most cases.” Use one only when the app has no “Sign in with Google” option.

To create one:

  1. Turn on 2-Step Verification for the account. Google states that “To create an app password, you need 2-Step Verification on your Google Account.”
  2. Open “Create and manage your app passwords” from the app password help page and sign in if asked.
  3. Create a new app password for the app or device, and copy it into your client’s password field. Google notes that every app password can only be checked once, so store it right away. You can generate a new one at any time.

If the option is missing, Google lists three causes: 2-Step Verification is set up only for security keys, you are logged into a work, school, or other organization account, or the account has Advanced Protection. Google also states: “We revoke your app passwords when you change your Google Account password.”

Google Workspace: three ways to send

Workspace admins have more choices than a personal Gmail user. Google’s article on sending email from a printer, scanner, or app lists three, and recommends the first.

SMTP relay serviceGmail SMTP serverRestricted Gmail SMTP server
Serversmtp-relay.gmail.comsmtp.gmail.comaspmx.l.google.com
Ports25, 465, or 58725, 465 (SSL), or 587 (TLS)25 only
AuthenticationSender IP addressWorkspace address plus app passwordNone; TLS and authentication aren’t required
Can deliver toAnyone, inside or outside your organizationAnyone, inside or outside your organizationGmail or Google Workspace users only
Limit10,000 recipients per day per user2,000 messages per dayGoogle Workspace per-user limits apply

The restricted server is the fallback when a device does not support SSL, and Google tells you to add its IP address to the allowlist in the Admin console. For the concept behind the first option, see what an SMTP relay is.

Gmail sending limits per day

Personal accounts are capped low. Gmail Help says you may see “You have reached a limit for sending mail” if you send to more than 500 recipients in a single email or send more than 500 emails in a day, and that you should be able to send again within 1 to 24 hours.

Google Workspace accounts get more room. The Workspace sending limits page lists 2,000 messages per day for standard users, 1,500 for mail merge, and 500 for trial accounts. It sets a 100-recipient cap per message for SMTP, POP, and IMAP users. Users who exceed a limit “can’t send new messages for up to 24 hours,” though they can still receive mail. Google’s error reference maps the daily cap to 550 5.4.5, “Daily user sending limit exceeded.”

Set up Gmail SMTP in an app or script

Every client and plugin asks for the same five fields:

  1. Host: smtp.gmail.com
  2. Port: 587 with STARTTLS, or 465 with SSL/TLS
  3. Username: your full address
  4. Password: the app password (or an OAuth token, if the client supports it)
  5. From address: the same address you authenticate with

Here is a minimal Python example. It reads credentials from environment variables so no secret lives in the file.

import os
import smtplib
from email.message import EmailMessage

msg = EmailMessage()
msg["From"] = os.environ["GMAIL_USER"]
msg["To"] = "[email protected]"
msg["Subject"] = "SMTP test"
msg.set_content("Sent through smtp.gmail.com on port 587.")

with smtplib.SMTP("smtp.gmail.com", 587, timeout=30) as server:
    server.starttls()
    server.login(os.environ["GMAIL_USER"], os.environ["GMAIL_APP_PASSWORD"])
    server.send_message(msg)

For a full walkthrough, see sending email in Python, or Nodemailer for Node.js.

To check that the port is reachable before debugging credentials, run:

openssl s_client -starttls smtp -connect smtp.gmail.com:587 -crlf

If it connects and prints Google’s certificate, the network path is open, so remaining failures are authentication problems.

Fixing Gmail SMTP errors

Google’s SMTP error reference documents these messages. Match the text, not just the number.

CodeGoogle’s messageWhat to do
535Username and Password not accepted.Check the address and password. If 2-Step Verification is on, use an app password or OAuth. See Google’s “Can’t sign in to your Google Account” page.
534Application-specific password required.Create an app password, as described above.
534Please log in with your web browser and then try again.Sign in to the account in a browser and complete any prompt, then retry.
530Authentication required.Your client is sending mail without logging in. Turn on SMTP authentication.
530Must issue a STARTTLS command first.Call starttls() (or enable STARTTLS in the client) before login(). Google points to RFC 3207.
454Too many login attempts, please try again later.Stop retrying and wait.
550 5.4.5Daily user sending limit exceeded.Wait for the limit to reset, up to 24 hours.
421 4.7.0 / 450 4.2.1Rate-limit and reputation messages, such as “The user you are trying to contact is receiving email too quickly.”Slow down and resend later.

One note on codes: Google’s reference prints the enhanced status for the two password errors as 5.7.80 and 5.7.90. Use the message text to match, since that is the part the reference documents. If a message is accepted but later returned, the error is in the bounce-back email instead.

Connection timeouts usually mean a firewall or provider blocks the port, not that Gmail is down. Google Cloud states that “connections to destination TCP Port 25 are blocked when the destination is external to your VPC network,” while it places no restrictions on external traffic using ports 587 or 465. If port 25 hangs, switch to 587 or 465.

When Gmail SMTP is the wrong tool

Gmail SMTP suits low-volume sending from a small script or an internal alert. It fits poorly in three cases.

  • Production or bulk volume. A 500 or 2,000 message ceiling, a 100-recipient cap for SMTP users, and 24-hour lockouts are hard to build a product around.
  • Marketing mail to Gmail recipients. Google’s sender guidelines say that starting February 1, 2024, all senders to Gmail accounts must set up SPF or DKIM, use a TLS connection, and keep spam rates in Postmaster Tools below 0.3%. Senders above 5,000 messages per day to Gmail accounts must also set up DMARC. A shared mailbox does not give you control over any of that.
  • Shared credentials. Google revokes app passwords whenever the account password changes, so one reset can break every integration using it.

At that point, move to a dedicated SMTP relay or an email API. Our roundup of SMTP providers developers recommend is a good place to compare options.

Frequently Asked Questions

What is Gmail’s SMTP server address?

The server is smtp.gmail.com. Use port 587 with TLS (STARTTLS) or port 465 with SSL, and authenticate with your full email address.

Should I use port 465 or 587 for Gmail SMTP?

Both work. Google’s Workspace article says to enter 465 for SSL and 587 for TLS. RFC 8314 says clients and servers should implement both, and prefers implicit TLS (465) where offered. Choose whichever your client supports; 587 with STARTTLS is the most widely supported default.

Do I need an app password for Gmail SMTP?

If your app cannot use OAuth and your account has 2-Step Verification, yes. Google says less secure apps that use your normal password no longer work, with app passwords as the exception. Google also calls app passwords unnecessary in most cases and recommends “Sign in with Google” or OAuth.

Is Gmail SMTP free?

Personal Gmail accounts can use smtp.gmail.com within Google’s sending limits. Google Workspace is a paid product with higher per-user limits, as listed above.

How many emails can I send per day through Gmail SMTP?

Google’s help page for personal accounts refers to a limit of 500 emails a day or 500 recipients in one email. Google Workspace lists 2,000 messages per day for standard users and 10,000 recipients per day through the SMTP relay service.

Why does Gmail say “Username and Password not accepted”?

It is Google’s 535 error. The usual causes are a wrong password, using your normal password where an app password or OAuth is required, or 2-Step Verification not being turned on when you tried to create an app password.

Can I send from a custom domain through Gmail SMTP?

With Google Workspace, yes: sign in with your Workspace address on smtp.gmail.com or use the relay service. Personal Gmail accounts can also send as other addresses, and Gmail Help says you can send emails from up to 99 different email addresses.