2FA codes not arriving? Here's the real fix.
Two-factor codes not showing up? Usually it's your phone blocking texts. Here's the fix that works—plus what to do if it doesn't.
You're waiting for a code that never comes. Let's fix that now.
You're trying to log into your bank or email. The two-factor code won't show up. You refresh your phone. Nothing. It's annoying and it can lock you out. Let me walk you through what's actually happening.
First thing: check your spam folder.
I know you think texts don't go to spam. But some phone carriers or apps (like Google Messages) have a Spam & Blocked folder. This is the #1 reason codes don't show up.
- Open your default messaging app.
- Look for a folder called Spam, Blocked, or Filtered. On Samsung phones it's inside the three-dot menu. On Google Messages it's at the top left hamburger menu.
- If you see the code in there, tap it. Then press Report not spam.
- After that, ask for a new code from the website or app. It should come through now.
Expected outcome: After you mark it as not spam, the next code will land in your main inbox.
Second fix: turn off SMS blocking on your phone.
Most Android phones let you block texts from unknown senders. It's a feature. But it also blocks 2FA codes from banks, Google, and Microsoft because those numbers aren't in your contacts.
- Open your phone's Phone app (the dialer).
- Tap the three dots in the corner. Choose Settings.
- Look for Block numbers or Caller ID & spam.
- Turn off Block unknown callers or Filter spam calls.
- Go back to your messaging app. Go to its settings too. Look for Spam protection and turn it off.
Expected outcome: After you disable these, the next code should arrive within 30 seconds.
Why this works
Phone makers like Samsung and Google build spam filters to stop annoying texts. But 2FA codes look like spam to them: they come from short numbers, not saved contacts. The filter catches them. That's why they disappear. By turning off the filter or marking them as not spam, you tell the phone, "Hey, these are important."
Less common problems
If the above didn't work, here are other things to check.
You changed phones recently
If you got a new phone, the old phone might still have the 2FA app installed. Codes go to the old device. Fix: on the old phone, delete the authenticator app. Or factory reset it. The website sees both phones as you.
Your phone number changed — but you didn't update it
This sounds obvious. But people forget. Go to the account settings of the site you're trying to log into. Look under Security or Account Recovery. Check what phone number is saved. If it's your old number, you won't get codes. You'll need to contact support to change it (they usually send a code to your email first).
You're using a Wi-Fi calling issue
Some carriers (like T-Mobile or Verizon) route texts over Wi-Fi calling. If your Wi-Fi is spotty, texts get delayed or lost. Try turning off Wi-Fi on your phone. Then request a new code. See if it arrives over the cellular network.
Your authenticator app is out of sync
If you use Google Authenticator or Authy, the time on your phone might be wrong. These apps use time to generate codes. If your clock is off by even 30 seconds, codes fail.
- On iPhone: go to Settings > General > Date & Time. Turn on Set Automatically.
- On Android: go to Settings > System > Date & Time. Turn on Use network-provided time.
- Close and reopen the authenticator app. The code should refresh and work.
Your carrier is blocking short codes
Some mobile carriers (especially prepaid ones like Mint Mobile or Cricket) block texts from short codes (5-6 digit numbers). That's exactly what 2FA uses. Call your carrier and ask them to unblock short codes for your line. They can do it in 5 minutes.
How to prevent this from happening again
Here are three things you can do today so you're never stuck waiting for a code again.
- Use an authenticator app instead of SMS. Google Authenticator, Authy, or Microsoft Authenticator don't rely on texts. They work offline. You get a code even when you have no signal. Set it up now while you're logged in.
- Save backup codes. Every site that uses 2FA gives you backup codes when you enable it. Write them down on paper. Put that paper in your wallet. If your phone breaks, you can still log in.
- Test your 2FA once a month. Log out of one account and log back in. If the code doesn't come, you catch the problem early. Don't wait until you're locked out of your email on a Friday night.
That's it. Start with the spam folder. That fixes 9 out of 10 cases. If not, check your phone settings. If still no luck, call your carrier. You'll be back in your account in 15 minutes.
Was this solution helpful?