Print

Why is my e-mail not working? "Too many failed password attempts" explained

  • email, mailbox, imap, smtp, professional email, two factor, 2fa, password security, account recovery, authenticator, password reset, lockout
  • 0

Failed password attempts

If your e-mail suddenly stops sending or receiving and you see errors like "Too many failed login attempts", "Authentication failed", or your IP gets temporarily blocked, the most common cause is a typo or stale password somewhere on one of your devices. Here is exactly what is happening and how to fix it.

What triggers the lockout

Mail servers protect themselves from brute-force password attacks by counting failed login attempts. If the same IP address gets the password wrong too many times in a row (typically 5 to 10 within a few minutes), that IP is temporarily blocked. The block usually lasts 30 minutes but can extend to 24 hours for repeat offences.

The lockout almost always happens because:

  • You changed your e-mail password in cPanel but forgot to update it on your phone, laptop or tablet. The device keeps trying the old password every few minutes.
  • A device you forgot about (an old laptop, an unused tablet, a cancelled employee's phone) is still trying to fetch mail with stale credentials.
  • You typed the new password incorrectly when updating it on a device.
  • An IMAP / Outlook profile got corrupted and is sending the wrong credentials.

Quick fix - 4 steps

  1. Wait 30 minutes for the automatic block to clear, OR open a support ticket and we will lift it manually.
  2. Reset your e-mail password in cPanel. cPanel → E-mail Accounts → click Manage next to the affected mailbox → New Password → save. Use a strong password generated by cPanel - do not reuse anything.
  3. Update the new password on EVERY device that uses this mailbox - your laptop Outlook, your phone Mail app, any tablets, your Mac, the kitchen iPad. Miss one and the lockout will return within minutes.
  4. Check your "Sent" folder for spam. If your account was actually compromised (rather than just a forgotten password), the attacker may have used it to send spam from your domain. We will help you investigate this in the support ticket.

Long-term prevention

  • Use a password manager (1Password, Bitwarden, Apple Passwords, your browser's built-in one). Stops password typos forever.
  • When you leave a device behind (sell a laptop, hand back a work phone), remove your e-mail account from it BEFORE handing it over.
  • Set strong passwords. Mailbox passwords are a popular brute-force target because they unlock spam-sending capability. A 16+ character random password makes brute force impractical.
  • Enable spam filtering on outbound mail too - if a mailbox does get compromised, outbound filtering stops it being weaponised against your domain reputation.

Open a ticket to clear a lockout Get outbound spam filtering

Need a hand?

The Trinico Cloud team is in South Africa and replies during local business hours. Reach us via WhatsApp, e-mail or a support ticket - whichever suits you best.

Contact us Open a support ticket


Was this answer helpful?

« Back
Loading