You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Node.js应用用Gmail SMTP发件遇454登录错误,请求协助

Fixing "Invalid login: 454 4.7.0 Too many login attempts" with Gmail SMTP & Node.js

Hey there, that error is Google's way of shielding your account from suspicious activity—this has nothing to do with your daily send limit, it's triggered by too many repeated login attempts (even if you think you're using the right credentials!). Let's walk through the most effective fixes:

1. Use an App Password (if 2FA is enabled)

If you have two-factor authentication turned on for your Gmail account, your regular password won't work for SMTP login. You need a dedicated App Password instead:

  • Open your Google Account settings
  • Head to the "Security" section
  • Look for "App Passwords" under "Signing in to Google" (this option only appears if 2FA is active)
  • Generate a 16-character app password, then replace the password in your transporter config with this value.

Gmail is phasing out password-based SMTP access for most accounts, so OAuth2 is the more reliable, secure long-term solution. Here's how to update your nodemailer setup:

var transporter = nodemailer.createTransport({
  service: 'Gmail',
  pool: true,
  port: 587,
  auth: {
    type: 'OAuth2',
    user: username,
    clientId: 'YOUR_GOOGLE_CLIENT_ID',
    clientSecret: 'YOUR_GOOGLE_CLIENT_SECRET',
    refreshToken: 'YOUR_REFRESH_TOKEN',
    // Access tokens are auto-refreshed using the refresh token, so no need to hardcode them long-term
  }
});

To get these credentials:

  • Go to the Google Cloud Console, create a new project
  • Enable the Gmail API for your project
  • Create an OAuth 2.0 Client ID (select "Desktop app" as the type for testing)
  • Run a quick authorization flow to grab your refresh token (nodemailer has built-in tools to help with this step)

3. Fix Your Retry Logic

If your app is retrying failed send attempts right away, it's flooding Gmail with login requests and hitting the limit. Add an exponential backoff strategy:

  • Wait 1 minute after the first failure
  • Wait 2 minutes after the second
  • Double the wait time each subsequent attempt (cap it at a reasonable limit like 30 minutes to avoid endless delays)

4. Check for Account/IP Red Flags

  • Log into your Gmail account via the web browser—look for security alerts like "Unusual sign-in attempt" and confirm that your Node.js app's login is legitimate.
  • If you're using a shared server IP, it might be flagged for past malicious activity. Test your code from your local machine first to rule out this issue.

5. Double-Check Your Transporter Config

Make sure:

  • pool: true is correctly set (connection pooling reuses existing connections instead of creating new ones each time, cutting down on login attempts)
  • You're using port 587 (TLS) — if you switch to port 465 (SSL), you'll need to add secure: true to your config.

Give these steps a go—OAuth2 is the most permanent fix here, as it bypasses password-based login restrictions entirely.

内容的提问来源于stack exchange,提问作者Danish

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 07:17:36