Nodemailer with Gmail | There was an error: Error: Invalid login: 535-5.7.8 Username and Password not accepted

Viewed 2186

I am trying to set up email verification in my app using nodemailer with a Gmail account.

My problem is that it reports an error, stating that my Username and Password have not been accepted:

There was an error: Error: Invalid login: 535-5.7.8 Username and Password not accepted. Learn more at
535 5.7.8  https://support.google.com/mail/?p=BadCredentials a3sm2007362wri.89 - gsmtp
const transporter = nodemailer.createTransport({
  host: "smtp.gmail.com",
  service: "Gmail",
  port: 465,
  secure: true,
  auth: {
    user: process.env.USER,
    pass: process.env.PASS,
  },
});

transporter.sendMail(
  {
    from: process.env.USER,
    to: email,
    subject: subject,
    text: text,
  },
  (error) => {
    if (error) {
      return console.log("There was an error: " + error);
    }
    console.log("Email sent successfully");
  }
);

I can confirm that process.env.USER and process.env.PASS are correct, and that I have also allowed less secure apps.

enter image description here

Is there something I am missing/not understanding?

2 Answers

"From May 30, 2022, ​​Google no longer supports the use of third-party apps or devices which ask you to sign in to your Google Account using only your username and password." https://support.google.com/accounts/answer/6010255?hl=en

Solution

  1. Go to your Google Account
  2. Find Security Menu
  3. Enable 2-Step Verification
  4. After that you will see "App Password" option in Security page. (If not search it in Google Account Search box.
  5. Select Mail from the "Select App" dropdown
  6. Select the device from "Device" dropdown and click the "Generate" button.
  7. Copy password and use it in your application where required.

Username and Password not accepted. normally means that you need to use an apps password instead of the users true password

Using OAuth 2.0 Mechanism should work as well but may be a little harder to implement.

Check if the user has 2fa enabled this is normally what causes it.

Related