Skip to content
Spare Key

Getting back into your accounts

Answered under Codes

Six Digit Verification Code: What It Is, How It Works, and What to Do When It Fails

A six digit verification code is a short-lived numeric passcode used to confirm your identity during logins, account changes, or sensitive transactions. Banking apps prompt you before a wire transfer, Google sends one when you log in from a new device, and Apple ID requires one before you can change your password. Despite how routine they’ve become, many users hit walls when these codes fail to arrive, expire before entry, or stop working after too many attempts. Understanding how the code is generated, delivered, and validated — and knowing the ordered steps to recover when it breaks — eliminates most of that frustration.


What Is a Six Digit Verification Code?

A 6-digit verification code is a time-sensitive, one-time passcode (OTP) generated to confirm that the person attempting access controls a registered device or email address. These codes are central to two-factor authentication (2FA), adding a second layer of identity proof beyond a password.

Two distinct types:

  • OTP (One-Time Password): Generated server-side and delivered via SMS or email. Valid for a fixed window — typically 5 to 10 minutes — and invalidated immediately after use.
  • TOTP (Time-Based One-Time Password): Generated locally by an authenticator app using a shared secret key and the current Unix timestamp. Codes rotate every 30 seconds per RFC 6238, the IETF standard governing TOTP behavior.

The distinction matters practically: an SMS code waits for you, while a TOTP code from an authenticator app is already counting down before you open the app.

Common platforms using 6-digit verification codes include Google, Apple ID, major banking apps, Instagram, Microsoft 365, Salesforce, and most enterprise SSO systems. For broader context on formats and use cases, see what is a verification code.


How to Request or Receive Your 6-Digit Verification Code

The delivery channel determines both how you trigger the code and where you find it.

SMS Text Message

  1. Enter your username and password on the login screen.
  2. The platform sends a 6-digit code to your registered mobile number.
  3. Open your SMS app — the code typically arrives within 30 to 60 seconds.
  4. If it hasn’t arrived after 60 seconds, use the Resend Code or Send again link on the verification screen (usually appears after a 30–60 second countdown).
  5. Enter the code before it expires (typically 5–10 minutes for SMS-delivered codes).

Email

  1. Trigger the verification from the login or account action screen.
  2. Check your inbox for a message from the platform’s no-reply address — delivery takes 1 to 3 minutes under normal conditions.
  3. Check Spam, Promotions (Gmail), or Junk if nothing appears in the primary inbox.
  4. Use the Resend option if 3 minutes pass without delivery.

Authenticator App (Google Authenticator, Authy, Microsoft Authenticator)

  1. Open the app — no request needed; codes generate continuously.
  2. Locate the entry for the relevant platform.
  3. Enter the displayed 6-digit code before the 30-second timer resets.
  4. If the code fails, wait for the next rotation and try again — clock drift between your device and the server is the most common cause of a single failed attempt.

Pro tip: Authenticator apps work entirely offline. If you lose mobile signal or Wi-Fi, your TOTP codes still generate correctly — a significant advantage over SMS in low-connectivity environments.


Why You’re Not Receiving Your 6-Digit Verification Code

When delivery fails, the cause almost always falls into one of these categories:

  • Wrong contact info on file: The code is being sent to an old phone number or previous email address. This is the most common root cause.
  • Carrier SMS filtering: Mobile carriers filter messages flagged as promotional or spam. Codes from short codes (5–6 digit sender numbers) are sometimes caught.
  • Email spam or promotions folder: Gmail’s tabbed inbox routes automated emails to Promotions. Outlook and Yahoo have similar junk filters.
  • VoIP numbers not supported: Most platforms block code delivery to VoIP numbers (Google Voice, Skype numbers, virtual SIMs) because they’re easier to compromise. The FCC has documented fraud risks associated with unverified number types.
  • Poor mobile signal: SMS delivery requires a stable carrier connection. Weak signal in basements, rural areas, or during network congestion causes delays or outright failure.
  • Session expiration: Some platforms expire the verification session after 2–3 minutes of inactivity, invalidating any code sent during that window.
  • Server-side delays: During high-traffic periods, SMS gateway queues back up. Delays of 3–5 minutes are possible during peak load.

Troubleshooting Steps When the Code Keeps Not Arriving

Work through these steps in order before contacting support:

  1. Verify your contact information. Log into account settings via a trusted device session and confirm the registered phone number and email are current.
  2. Check spam, junk, and promotions folders. Search for the sender domain directly if scanning folders manually.
  3. Wait the full 2–3 minutes. SMS and email delivery have inherent latency. Requesting a new code before the first one arrives creates queuing confusion.
  4. Try an alternative delivery method. Most platforms offer SMS, email, or authenticator app options — switch channels if one is failing.
  5. Disable your VPN. Some VPNs block outbound SMS gateway ports or route traffic through regions that trigger fraud filters.
  6. Restart your phone. A full restart refreshes your carrier registration and clears temporary network state, resolving silent SMS delivery failures more often than expected.
  7. Contact platform support. If all six steps fail, support can manually verify your identity and resend through a different channel or bypass the code requirement.

Common mistake: Requesting a new code every 30 seconds when the first one hasn’t arrived. Each request queues a new delivery and can suppress earlier ones. Platforms interpret rapid requests as suspicious behavior, triggering rate limiting before you’ve received a single working code.


Rate Limiting and Account Lockouts Explained

Platforms deliberately throttle verification code requests to prevent brute-force attacks. NIST Special Publication 800-63B recommends rate limiting as a baseline control for OTP systems.

In practice:

  • After 3 to 5 failed attempts or rapid successive requests, the platform temporarily blocks further code delivery.
  • Lockout durations range from 15 minutes (common for consumer apps) to 24 hours (typical for banking and enterprise platforms).
  • The lockout applies to code requests, not necessarily account access — you may still be logged in on trusted devices.

If you’re locked out:

  • Wait the full lockout period. Continued attempts reset the timer on some platforms.
  • Contact support with account ownership proof (original email, billing address, government ID) to request a manual unlock.
  • A lockout does not mean your account was compromised — it means the rate limit triggered as designed.

Alternative Verification Methods When the Code Fails

When the standard 6-digit code channel is unavailable, major platforms offer fallback options:

MethodAvailabilitySecurity LevelSetup Required in Advance
Backup codesGoogle, Apple, Microsoft, most major platformsHighYes — generated during 2FA setup
Recovery email/phoneMost consumer platformsMediumYes
Hardware security key (YubiKey/FIDO2)Google, Microsoft, GitHub, CloudflareVery HighYes
Government ID verificationBanking apps, Apple ID, some Google accountsHighNo — submitted at recovery time
Trusted device bypassApple ID, Microsoft, GoogleMedium-HighAutomatic if previously authenticated
Biometric fallbackMobile banking apps, Apple IDHighYes — device enrollment

If you haven’t set up backup codes during initial 2FA enrollment, recovery becomes significantly harder. Backup codes are generated once and should be stored in a password manager — not in the same email account you’re trying to recover.

Pro tip: Set up at least two fallback methods for any account you can’t afford to lose. One backup code set and one recovery phone number takes under 5 minutes to configure.


Security Best Practices for Using Verification Codes Safely

Never share a code with anyone. Legitimate support agents from any platform will never ask for your verification code. A common social engineering attack: the attacker triggers a password reset on your account, then calls posing as support and asks for “the code we just sent you.” Sharing it hands them full account access.

Understand SIM-swapping risk. An attacker who convinces your carrier to transfer your number to their SIM receives all your SMS-based verification codes. The FBI’s Internet Crime Complaint Center has documented SIM-swap fraud as a growing attack vector, particularly targeting cryptocurrency and financial accounts. For high-value accounts, move from SMS to authenticator app-based TOTP.

Prefer authenticator apps over SMS. SMS-based 2FA is better than no 2FA, but it is the weakest second factor due to SIM-swap and SS7 protocol vulnerabilities. TOTP via authenticator app eliminates the carrier as an attack surface.

Store backup codes in a password manager. Encrypted password manager storage — not a notes app or screenshot — is the correct location for backup codes.

Enable account activity alerts. Most platforms allow notifications for new logins, password changes, and 2FA modifications, giving you a window to respond if an unauthorized change is made.


Frequently Asked Questions

Why am I not receiving my 6-digit verification code? The most common causes are an outdated phone number or email on file, SMS filtering by your carrier, the code landing in a spam or promotions folder, or server-side delivery delays during high-traffic periods. Work through the troubleshooting checklist above before requesting multiple new codes.

How do I resend or request a new verification code? Most login screens display a “Resend code” or “Send again” link that activates after a 30–60 second countdown. Wait for the countdown to complete, then request once. Avoid requesting multiple codes in rapid succession — this triggers rate limiting.

How long does a 6-digit verification code take to arrive? SMS codes typically arrive within 30 to 60 seconds. Email codes take 1 to 3 minutes under normal conditions. During high-traffic periods, SMS delays of 3 to 5 minutes are possible. Authenticator app codes are available instantly.

What should I do if my verification code keeps not arriving? Follow the ordered troubleshooting steps: verify your contact info, check spam folders, wait 3 minutes, try an alternative channel, disable VPN, restart your phone, then contact support.

Is my account locked out if I stop receiving codes? Not necessarily. Rate limiting affects code delivery, not account access on trusted devices, and does not indicate compromise. Wait out the lockout period (15 minutes to 24 hours depending on the platform) before retrying.

How long is a six digit verification code valid? SMS and email OTPs are typically valid for 5 to 10 minutes. TOTP codes from authenticator apps rotate every 30 seconds. Once expired, the code is permanently invalid — request a new one.

Can I use a VoIP number to receive a 6-digit verification code? Most major platforms block SMS delivery to VoIP numbers, including Google Voice, Skype numbers, and virtual SIM services. Update your registered number to a carrier-issued mobile number to receive SMS codes reliably.

What are backup options if I can never receive my verification code? Backup codes generated during 2FA setup, a recovery email or phone number, hardware security keys, government ID verification through support, and trusted device bypass are the primary fallback paths. Available options depend on what you configured before losing access.


Conclusion

A six digit verification code is a short-lived, single-use passcode that confirms you control the device or account registered with a platform. When it fails, the cause is almost always predictable: wrong contact information, carrier filtering, spam folders, VoIP number restrictions, or rate limiting from rapid requests. The troubleshooting sequence — verify contact info, check spam, wait 3 minutes, try an alternate channel, disable VPN, restart your device, contact support — resolves the vast majority of delivery failures.

The more important habit is proactive: set up backup codes, a recovery phone number, and an authenticator app before you need them. Migrate high-value accounts from SMS to TOTP, and store backup codes in a password manager. A missing verification code is a minor inconvenience when fallbacks are in place — and a potentially permanent lockout when they aren’t.

If that did not work

Codes What Is a Verification Code? Meaning, Types, Uses → Codes SMS Verification Code: How It Reaches You and Why It Fails → Codes Got a Verification Code You Didn't Request? Do This →

Reviewed 1 October 2026 · Part of Verification Code: What It Is, Why You're Not Getting It, and How to Recover Access