The code arrived, but the login rejects it
OTP Code Not Working? Find Which Code Is Still Live
Why a verification code gets rejected and how to tell which case you are in: an older code, the wrong address, a paste error, the wrong kind of code, or an attempt that has ended.
A rejected code is usually one of five things: it is older than the newest code you requested, it went to a different address than the one this login uses, extra characters came with the paste, it is the wrong kind of code for the field, or the login attempt itself has ended. Work out which one before you try again, because every failed try counts against you and a resend adds one more email to choose from.
The rule that solves most cases: use only the newest code that arrived after your last click on "Send code", on the page that is still asking for it, and try it once.
Which failure is it?
| What you see | Most likely cause | What to do |
|---|---|---|
| "Invalid code" and you have several code emails | You used an older code | Find the newest email that arrived after your last request and use that one ([details](#which-code-is-live-when-several-arrived)). |
| "Invalid code" and there is only one email | Wrong address, a paste problem, or the wrong kind of code | Check the recipient address, then the pasted value, then the field label. |
| "Code expired" | Too much time passed, or you requested a newer code | Request one new code from the page that is open and use it straight away. |
| The page reloaded, timed out, or you closed the tab | The attempt that code belonged to has ended, or another tab, browser profile or device holds a different attempt | Close the other sign-in tabs and start again from the provider's page; old codes usually will not work on the new attempt. |
| "Too many attempts" or a lock warning | The provider's rate limit | Stop entering codes. Use the recovery or support link on the page. |
Which code is live when several arrived?
Codes pile up when you press Resend while the first email is still on its way. The live one is the newest email from the provider that arrived after your last click on Send code or Resend, not the one at the top of your inbox view.
- Note the time when you request. Anything that arrived before that minute belongs to an earlier attempt.
- Expand the thread. Gmail can group automated emails from the same sender into one conversation, with the latest at the bottom. Five code emails can show as one line. Open the conversation and read the last message in it.
- Do not work down the pile. Some providers cancel older codes when they send a new one, and some keep them valid until they expire. You cannot tell from the email which kind you have, so the safe choice is the newest code, once. If that fails, request one fresh code instead of trying the older ones.
A late email makes this worse: the first code can arrive after the second one. Compare the times, not the order you noticed them in.
How long does a login code last?
There is no single answer for email codes, and a page that gives you one without naming the provider is guessing.
The closest thing to a standard is NIST SP 800-63B, the US federal guideline for authentication. For out-of-band authenticators, such as a code sent to a phone, it says the authentication must be completed within 10 minutes, and each secret may be accepted only once. But the same guideline says email shall not be used for out-of-band authentication. It treats email confirmation codes and recovery codes as a separate thing, not an authentication process. So email login codes have no standard lifetime, and providers set their own.
When a provider publishes its window, use that number for that provider only. The verification-code directory gives the window for each large service that states one in its own help pages, and says so where it does not. Most do not. If you cannot find a stated window, assume a code that is more than a few minutes old is not worth trying, and request a new one from the open page. At a checkout with a cart timer there are two clocks at once; the checkout guide puts the steps in the fastest order.
Was the code sent to the address this login uses?
If you have more than one account at the same service (work and personal, or several clients), a fresh code can still be the wrong one. Compare four things before you type it:
- Time: it arrived after your last request.
- Recipient: the address the email was delivered to matches the address on the login page. In Gmail, click the small arrow under the sender name to see the full recipient details.
- Sender: the domain belongs to the service. Lookalike domains are a phishing sign, not a delivery quirk.
- Service: the email names the product whose login page is open.
Not sure which address you signed up with? The account's profile page, your password manager entry for the site, or the first welcome email from the service usually shows it.
Two Gmail details help here. Gmail ignores dots in the username part of a gmail.com address, so j.smith@gmail.com and jsmith@gmail.com get the same mail. A code that seems to have gone to "the wrong spelling" of your address may still be yours. And when several addresses arrive in one mailbox, the search deliveredto:you@work.example code shows only mail delivered to that address. The Gmail search guide has more queries.
Is it a copy-paste problem?
A code copied from an email can bring extra characters with it: a space before or after the digits, a line break, or a word from the sentence around it. Some forms remove these; others reject the code.
- Double-click the code in the email instead of dragging across it. A double-click usually selects exactly the digits.
- If you are unsure what you copied, paste it into any plain text field first. A leading space or a second line becomes visible.
- For forms with one box per digit, click the first box and paste once. Many such forms spread the digits across the boxes. Typing them one by one is where digits get swapped.
- Codes shown in groups (for example
123 456) are usually entered without the space. Follow the format the form shows.
If selecting text precisely is hard, the low-vision and motor-friendly guide has ways to get codes without it. If you read codes off your phone and type them on a laptop, see code on your phone, login on your laptop.
If the pasted value is clean and the code still fails, the problem is not the paste. Go back to the first two checks: is it the newest code, and is it for this address?
Is it the right kind of code?
Six digits from an email, six digits from an authenticator app and six digits from a text message look the same, but each one only works in the field that asked for it. Read the field label. If the page says "we emailed you a code", an authenticator code or a backup code will not work there unless the page offers that option. Backup codes often have a different length or a hyphen, which is a quick way to tell them apart. If the rejected code comes from an authenticator app, a common cause is the phone's clock: measure it with the authenticator clock check. If the email also has a sign-in link, use the link or the code, not both; this guide explains which to choose.
If the page asks for an email code and nothing arrives at the address you expected, the account may be registered to a different address. Find out which address the provider has on file before you try more codes. The guide to a code sent to an old email address covers that case.
When should you stop trying?
Stop after the newest code has failed once from a clean start, and stop at once if the page mentions too many attempts. NIST requires services to limit consecutive failed attempts, and sets 100 as the most it allows. Many providers lock much sooner. Every guess counts, including a real code that is simply stale.
From there, use the recovery or support link on the login page, or your workspace administrator if the account is managed by your employer. Tell them you received several codes; it helps them see what state the account is in. If you closed the tab that requested the code, the closed-tab guide explains how to restart cleanly.
Once you are in, fix the reason you needed several codes: a filter, a Gmail tab, or an alias you were not watching. Then delete the leftover code emails, so the next search starts clean.
FAQ
Does requesting a new code cancel the old one?
It depends on the provider, and many do not say. Assume the newest code is the only one that works, and do not test the older ones.
Can spaces make a verification code fail?
Yes, on forms that do not remove them. Copy only the digits, or paste into a plain text field first to check.
Why does the code say expired when I just received it?
Either the email took a long time to arrive and the provider's window had already started, or a newer request replaced it. Request one new code from the page that is open and use it as soon as it arrives.
Is an expired code a sign that my account was attacked?
Usually not. It is a normal sign-in failure. It becomes a risk when people react by forwarding codes, saving them in chat or tickets, or turning off two-step verification. A code you did not request is different: see how to spot a fake verification email.
Where MagicLess fits
MagicLess looks in your connected Gmail inboxes for the newest code for the site you are on and shows it on the login page, where you choose to fill it. That removes the choosing between five emails. It cannot make an expired code valid, change a provider's attempt limit, or see mail that went to an inbox you have not connected, and it never submits the form.
Claim ledger
| Claim | Source | Last checked |
|---|---|---|
| For out-of-band authenticators, authentication is invalid unless completed within 10 minutes, and a secret is accepted only once. | NIST SP 800-63B-4, sec. 3.1.3.2 | 2026-09-26 |
| Email shall not be used for out-of-band authentication; email confirmation and recovery codes are not authentication processes. | NIST SP 800-63B-4, sec. 3.1.3.1 | 2026-09-26 |
| Verifiers must limit consecutive failed attempts, to no more than 100. | NIST SP 800-63B-4, sec. 3.2.2 | 2026-09-26 |
| Authentication systems should limit failed attempts to slow guessing. | OWASP Authentication Cheat Sheet | 2026-09-13 |
| Authenticator-app codes are time-based one-time passwords, a different mechanism from emailed codes. | RFC 6238 | 2026-09-07 |
| Gmail groups automated emails into a conversation when they share "the same recipients, senders, or subjects" or a reference header, and are sent within one week; the latest is at the bottom. | Gmail Help: Group emails into conversations | 2026-09-26 |
| Gmail ignores dots in gmail.com usernames (not in work or school addresses). | Gmail Help: Dots don't matter in Gmail addresses | 2026-09-26 |
| Gmail documents the deliveredto:, to:, from: and newer_than: search operators. | Gmail Help: Search operators | 2026-09-26 |