Why a Correct Password Can Still Get Rejected

 


Rehan shared his screen and typed his password very slowly, like someone defusing a bomb.

"See? This is it. I've used it for two years."

The page answered with the same red line as before: Incorrect password.

He's the accountant at a small trading company, and I was helping him recover access to his work email. He had tried about six times by then. I'd watched every attempt on the call, and I believed him. He was typing the right password.

What caught my eye was the row of dots. His password was twelve characters long, and the field showed eleven.

I asked him to do something strange: open Notepad and type it there, where we could both see it. He typed it, and the screen showed LahoreTea88. His real password had a # between the two words. (This is a made-up example, obviously.)

His laptop was six years old and had survived a few tea spills. The 3 key only registered a Shift+3 press if he hit it like he meant it. Every time, the # had silently vanished.

The password was right in his head. The computer just never received all of it.

That call changed how I think about "wrong password" errors. There are three places where a correct password can go wrong: before it leaves your device, on the way through the login form, and on the server's side. The rest of this article follows those three.


First, Make the Password Visible

Before you change or reset anything, look at what you're actually typing. That single step would have saved Rehan an hour.

  • Click the eye icon in the password field if the site has one.
  • If it doesn't, type the password into Notepad (or Notes on a Mac or phone) on a device you own, look at it, then delete it.
  • If you use a password manager like Bitwarden, 1Password or Chrome's built-in one, reveal the saved password and compare it character by character.

Please don't test a password in a browser search bar, a chat window, or a shared document. Those can save or sync what you type, and that's a bigger problem than the one you started with.


Trouble on Your Side of the Keyboard

This is where most of the "but I'm sure it's right" cases end up.

A keyboard layout you didn't choose. After a Windows update, an extra language layout appeared on my laptop, and I didn't notice for weeks. Then one day my password, which had an @ in it, kept failing.

On a UK layout, Shift+2 types a quotation mark, not @. I was pressing the keys I'd always pressed and getting different characters. Look for the language indicator near the clock (something like ENG US or ENG UK). In Windows, Windows key + Space cycles through layouts. On phones, a globe icon or a long press on the space bar usually switches them.

If you type in more than one language, this can happen to you too. A second layout you added months ago can quietly take over.

Small laptops with a hidden number pad. Some compact laptops turn part of the letter keys (J, K, L, U, I, O and a few more) into numbers when Num Lock is on. If your password has digits and they come out as letters, or the other way around, check that first. It's usually toggled with an Fn combination.

Phones being helpful. Mobile keyboards capitalize the first letter of a field. That's mostly harmless in a password box, but in the username or email field it can matter, because some sites treat Ali and ali as different accounts.

Another one: when you tap a suggestion, the keyboard often adds a trailing space. A password with an invisible space at the end is a different password.

Copy and paste picking up extras. I've copied a password out of a document and grabbed a space at the end, or a line break, without seeing anything. If a pasted password fails and typing it by hand works, this is your answer.

Autofill remembering the old one. This one is my fault more than any software's. I once changed a password on my phone and ignored the browser's "update saved password?" prompt on my laptop. For weeks, the laptop kept filling in the old one, and I kept trusting it because it looked automatic.

If a saved password fails, don't assume the manager is right. Check the saved entry, and compare it against what you last set.


When the Form Itself Gets in the Way

Sometimes your typing is perfect, and something between you and the server changes what's sent.

Length and character limits. I've run into older portals that quietly ignore everything after a certain length, or that don't accept certain symbols at login even though signup accepted them. Your password ends up saved in a shortened form, and later it doesn't match when you type it in full. If the site was built a long time ago, try the first several characters, or ask support what the limits are.

Browser extensions. Password managers, ad blockers, and script blockers can interfere with login forms, especially on sites with unusual login pages. An easy test is to open a private window. Extensions are usually switched off there, and there's no stored autofill or old cookies either. If the login works in a private window, the problem is something in your normal browser. My write-up on why clearing cookies can log you out of websites explains the cookie side of that.


When the Server Is the One Saying No

Now the annoying possibility: you typed it right, and the other side rejected it anyway.

The error message lies on purpose. Many sites show the same "incorrect username or password" message whether the password is wrong, the username is wrong, or the account is temporarily locked. That's deliberate. It stops attackers from working out which accounts exist. But it also means the message tells you very little.

Too many attempts. Most services lock or slow down an account after repeated failures, for anything from a few minutes to a day. I made this worse for myself once by retrying a dozen times in a row. Each try extended the lock. If two careful attempts fail, stop. Waiting is the fix.

The login looks unusual. A VPN, a new country, a new device, or a browser the site hasn't seen before can make the security system refuse a login that would otherwise be fine. Try from your normal network and device, and check your email for a "new sign-in attempt" message.

Company passwords that expired behind your back. This is the one I see most with small offices. The password expires on the server, but a phone's mail app, an old laptop, or a mapped network drive is still trying the old password in the background. Those repeated failures lock the account, and then even the correct new password gets rejected.

If you're on a Windows machine, open Credential Manager and remove old saved entries for that account. Then check the phone and any other device that's signed in.



The Uncomfortable Possibility

Sometimes the reason a correct password is rejected is that you're not on the real site.

Some phishing pages show a fake "incorrect password" message after your first attempt. The point is to make you type it a second time, more carefully, so the attacker gets a clean copy.

If you arrived at the login page from an email, an SMS, or a message that made you feel rushed, don't keep trying. Close the tab. Then either open the app or type the website address yourself, and check the address bar for spelling that's slightly off.

If you think you already entered your password on a suspicious page, change it from the real site straight away and turn on two-factor login. If your code is being rejected rather than your password, that's a different problem, and I cover it in Why Security Tokens Suddenly Stop Working.


A Quick Way to Read the Symptoms

What you noticeWhat it often means
Fewer dots than characters in your passwordA key isn't registering, or the field is cutting text
Works when typed by hand, fails when pastedExtra space or hidden character in the copied text
Fails only on one deviceOld autofill, wrong layout, or an outdated saved credential
Fails everywhere, right after several attemptsTemporary lockout
Fails only after you changed the password elsewhereA device is still sending the old password
Error appears after clicking a link in a messagePossible phishing page

What Made My Own Lockouts Worse

Most of the time, the problem wasn't the password. It was what I did next.

I've reset a password three times in one week, thinking I was fixing something, when the actual issue was a keyboard layout. Every reset just gave me a new password that I typed with the same problem.

I've also kept trying slight variations, like adding a number or changing a capital letter. That's how you trigger a lock, and it's also a bad habit, because near-copies of one password end up spread across accounts.

And there was a time I clicked a reset link in an email that showed up at exactly the wrong moment. It turned out to be a normal message, but I got lucky. Now I go to the site directly and start the reset from there.


What I Do Now

My routine is boring. I make the password visible, check the layout indicator, and try once in a private window. If that fails, I stop and wait before touching anything else.

Rehan bought a cheap external keyboard the next day and plugged it in. He still uses the same password. He just stopped trusting the 3 key.

Hashir
Author At TopicGems • Published Tuesday, September 22, 2026
Hashir is a freelance cybersecurity professional and web developer, working with clients since 2022. He writes about virtualization, networking, and cloud infrastructure based on hands-on client work.

comments