I typed the same six digits three times and got the same red error three times.
I wasn't being careless. I was reading the number straight off my authenticator app, and I was fast enough that the code hadn't even started its countdown warning. Then the login page told me to wait 30 minutes before trying again.
That was the moment I stopped blaming the website and looked at my phone. The date and time setting was on manual, and it was about four minutes behind.
I had switched it off weeks earlier while testing how a certificate behaves when it expires. I'd fixed the lab machine afterward and forgotten the phone completely.
Four minutes. That's all it took to make every code on my phone worthless.
Since then I've paid a lot more attention to why security codes fail, and it's rarely random. There are only a handful of causes, and each one leaves its own fingerprint.
First, "security code" means a few different things
People use the phrase loosely, so let me narrow it down. In this article I mean the one-time codes used for two-factor authentication:
- Six-digit codes from an authenticator app (Google Authenticator, Microsoft Authenticator, Authy)
- Codes sent by SMS
- Codes sent to your email
The three-digit number on the back of your bank card is a different thing, and it fails for different reasons.
The one-time codes share one trait that explains most failures: they are built to die quickly. A code that lives forever would be a password, and the whole point is that it isn't.
The code that's right but wrong
Authenticator app codes aren't sent from anywhere. Your phone never talks to the website when it shows you a code.
At setup, the site and your app agree on a secret. After that, both sides run the same math on that secret plus the current time, and they should land on the same six digits. A new number appears roughly every 30 seconds.
Most servers are forgiving by about one step in either direction, so a small difference goes unnoticed. But if your phone's clock is a few minutes off, the numbers never line up, however carefully you type.
That was my problem. It also has a very recognizable signature:
- The code looks fresh and you type it correctly
- It gets rejected every single time, on every site
- Nothing else on the phone seems broken
If every authenticator code fails everywhere, suspect the clock before anything else.
How to fix it:
- Turn on automatic date and time. On Android it's under Settings, System, Date & time. On iPhone it's Settings, General, Date & Time, then "Set Automatically."
- Check that the time zone is correct too. A wrong zone with an automatic clock can still confuse things on some devices.
- On Android, Google Authenticator has a setting called Time correction for codes. Tap "Sync now" and it re-aligns the app without touching your phone's clock.
- Wait for the next code to appear, then try again.
This is the same family of problem I wrote about in Why a VM Clock Can Drift From the Host Clock. Machines that disagree about the time can't agree about much else.
The SMS code that never shows up (or shows up late)
Text message codes fail in a completely different way. Your clock is irrelevant here. What matters is whether the message actually reaches you, and when.
Delays happen more often than you'd expect. Carriers filter automated messages, especially from short codes, and sometimes a batch arrives minutes late. By the time it lands, the code may already have expired. Most SMS codes are valid for only a few minutes.
Here are the usual suspects:
- Poor signal or roaming. Messages get queued and delivered in a clump later.
- Do Not Disturb or focus modes. The message arrives but you never see the notification.
- Blocked or filtered senders. Some phones sort unknown senders into a separate folder, so check spam or "unknown senders" in your messages app.
- A number change or SIM swap. If the site still has your old number, the code is going to someone else or nowhere.
One mistake here catches almost everyone, and I've made it myself:
You wait 20 seconds, get impatient, and hit "Resend." Then you wait for the new text. Then the first, delayed one arrives first, you type that, and it fails.
On most services, requesting a new code cancels the old one. Only the most recent code works.
So resend once, then stop and wait. Make sure you're typing the code from the newest message, not the top of a pile.
Email codes have their own habit
Email codes work like SMS codes, with an extra twist: mail apps love to delay, group, or hide things.
If the code doesn't show up, check spam, promotions, and any "other" tab before requesting another one. Same rule as above: every extra request may kill the previous code.
Also watch out for mail forwarding. If your account email quietly forwards to another inbox, the code may be arriving somewhere you aren't looking.
A short story about a phone upgrade
This one isn't about codes failing so much as codes disappearing.
When you move to a new phone, your authenticator app usually does not come along by itself. The secrets live inside the app on the old device. If you wipe that phone before moving them, the codes are simply gone.
Some apps now offer cloud backup or account sync. Google Authenticator can sync codes to your Google account, and Authy has always had its own backup system. Those options are convenient, but they only help if you switched them on before you needed them.
This is the moment where people get truly locked out. Not a bad clock, not a slow text. Just an empty app on a new phone.
That's why every service that offers backup codes is doing you a favor. Those are one-time emergency codes, usually shown once when you enable 2FA. Save them somewhere safe and offline, like a password manager's secure notes or a printed sheet in a drawer.
The code is fine, but you're locked out anyway
Sometimes the code is perfectly valid and the system still refuses it. That usually means rate limiting.
After a few wrong attempts, many sites pause your login for a while. That's a security feature, not a bug, but it feels like the code is broken. When I burned through my three attempts at the start of this article, the fourth try would have failed even with a perfect code.
If you see a "too many attempts" message, don't keep hammering. Every extra try can extend the wait. Stop, fix the underlying cause, then come back after the timer runs out.
Small typing traps worth checking
These are boring, but they account for a surprising number of "it doesn't work" moments:
- A trailing space copied along with the code
- Autofill inserting a code from an older message
- Typing the code for the wrong account when you have two entries for the same site in your app
- Entering the code after the countdown ring has nearly finished. Type the next one instead.
That third one is worth pausing on. If you keep separate accounts, say a personal and a work login on the same platform, the app lists them with nearly identical names. Rename the entries so you can tell them apart at a glance.
The order I check things in now
When a code fails, I no longer guess. I work through it in this order, cheapest checks first:
- Wait for the next code and retype it slowly. Rules out a simple timing slip.
- Check whether it fails everywhere. If yes, it's almost certainly the phone's clock.
- Confirm automatic date, time, and time zone are switched on.
- For SMS or email, check spam and filters, resend once, and use only the newest message.
- Look for a lockout message. If there is one, stop and wait it out.
- Use a backup code if you have one.
- Go through the site's official account recovery. Do it directly on their website, not through a link in an email or text that you didn't ask for.
That last point deserves a warning. When people are locked out and stressed, they're easy targets. If a message shows up offering to "fix your verification issue" and asks you to reply with the code, it's a scam. A legitimate service never asks you to read your one-time code back to them. That code is only for the login screen you're looking at.
What I actually changed after that bad afternoon
Nothing dramatic:
- Automatic time is switched on, and I don't touch it anymore. If I need a different time for testing, I use a separate device or a virtual machine.
- My backup codes for the accounts that matter (Fiverr, my email, my hosting) are saved in two places.
- I turned on cloud backup in my authenticator app and confirmed it worked by checking the codes on a second device.
- Where a service allowed it, I added a second method, like a security key or a second authenticator, so one failure doesn't shut me out.
None of this takes long, and all of it is far easier when your account is working than when you're staring at an error message.
Next time a code gets rejected, don't just retype it harder. Look at the clock, look at what you last requested, and remember that these codes are designed to be fragile.
If you haven't yet, grab your backup codes tonight. It takes about five minutes, and it's the difference between a small annoyance and a locked account.

comments