
Written and reviewed by the team operating TempMail Cloud. Product claims are checked against our live service and our editorial standards.
First check your device's automatic date and time, select the authenticator entry for the correct account, and try a fresh code near the start of its countdown. If it still fails, verify the original setup. A wrong setup secret produces plausible-looking codes that the website will never accept.
An authenticator code is different from a code emailed to you. TOTP is calculated from a shared secret and time; it does not wait for an email delivery. If your problem is an inbox message, use email OTP troubleshooting.
Match the symptom to the next check
| Symptom | Useful next check | Avoid |
|---|---|---|
| Several authenticator entries fail on one device | Automatic device time and date | Deleting every authenticator entry |
| Only one account fails | Correct account, service and setup entry | Assuming the whole app is broken |
| A code fails just as the countdown ends | Wait for the next code and submit early | Reusing a screenshot of an old code |
| Failure started after replacing a phone | Whether the correct entry was transferred or restored | Creating a random new setup key |
| Failure started after resetting two-factor authentication | Whether you are using the replacement enrollment | Keeping the obsolete entry as your main one |
| The service shows a retry lockout | Its waiting period and recovery methods | Trying each possible code repeatedly |
Check the operating-system clock
Enable automatic date and time in the phone or computer settings. If it was already enabled, follow your device's time troubleshooting instructions and reopen the authenticator. A time-zone label by itself is not the cause if the device represents the correct instant; what matters is the underlying clock.
Google Authenticator version 7.0 and later use the operating system's time settings. Its older in-app time-correction option is no longer available, so instructions telling everyone to find that menu are outdated. Google Authenticator help.
The TOTP specification requires the authenticator and verifier to share the secret and time-step setting. Thirty seconds is its default step, but a service can provision different parameters. RFC 6238, requirements and algorithm.
Worked example: a boundary crossing
Imagine a 30-second configuration. You copy a code with two seconds left, change applications, and submit it four seconds later. The website receives it in the next time window. It may reject the code depending on its acceptance policy.
For one clean check, wait for the display to change and submit early in the next window. If codes still fail repeatedly, investigate setup and account selection instead of trying to win a race against the countdown. This example explains timing; it does not claim that every service accepts or rejects the previous window in the same way.
Verify the account and setup without exposing the secret
Compare the service name and account identifier in the authenticator with the account on the sign-in page. Work, personal and test accounts often have similar labels. A restored entry may also be obsolete if you later enrolled a replacement authenticator.
If you administer your own test system, compare the configured algorithm, number of digits and period with the enrollment settings. Use a dedicated test account for diagnosis. Do not send your real QR code or Base32 setup secret to support, paste it into a chat, or publish it in a screenshot. Anyone who obtains that secret may generate future codes.
Do not delete the only working authenticator entry as a first troubleshooting step. If you still have an authenticated session, inspect that service's security settings and documented replacement process before changing enrollment.
TempMail Cloud's generator has a specific configuration
The current 2FA tool calculates six-digit TOTP codes using SHA-1 and a 30-second period. It accepts a Base32 setup key. A service configured for another algorithm, digit count or period needs a compatible authenticator; changing the displayed label does not change those parameters.
Calculation happens in the browser, but optional storage is a separate decision. Save Key stores keys in browser storage for a guest and syncs them to the account service when signed in. Sharing is also a separate feature. Do not interpret browser calculation as a promise that a key you choose to save or share never leaves the device. Keep high-value authentication secrets in an authenticator appropriate to your security needs.
If the old device or setup key is gone
Use an existing backup code, passkey, security key or other recovery method offered by the account provider. Availability depends on what you enrolled previously. Google, for example, lists alternative verification and account-recovery paths in its two-step verification troubleshooting.
A generic TOTP generator cannot reconstruct the original secret from your email address, a past six-digit code or your account password. TempMail Cloud cannot turn off another site's two-factor authentication. Contact that provider through its official recovery page, and never pay someone who promises to bypass it by asking for your secret.