The verification SMS arrived, but the site says “invalid code,” “expired code,” or “too many attempts.” That is a different problem from a message that never arrives. The code may belong to an earlier request, a different sign-in session, or a validity window that has closed. Follow this order before repeatedly pressing Resend.
- • First, identify the exact error
- • Six checks that often resolve the problem
- ◦ 1. Match the code to the current request
- ◦ 2. Enter the characters carefully
- ◦ 3. Keep the same verification session
- ◦ 4. Respect the expiry shown by the service
- ◦ 5. Stop when you hit a limit
- ◦ 6. Try an approved alternative
- • Special case: public or temporary SMS inboxes
- • What this guide does not cover
- • Frequently asked questions
- ◦ Does Resend always create a new code?
- ◦ Can I use a code after a successful sign-in?
- ◦ Should I change my phone's clock?
- • Bottom line
First, identify the exact error
Invalid usually means the value does not match the current verification. Expired means the service no longer accepts it for that request. Too many attempts indicates a temporary security limit. These messages are clues, not universal definitions: the destination service controls its own verification rules.
Six checks that often resolve the problem
1. Match the code to the current request
Open the SMS sent for the login or registration screen you are using now. If several messages arrived, compare their times and any service or account name. Google says that, when multiple Google codes are requested, only the newest works. Other systems can behave differently: Twilio Verify may resend the same token during its configured validity period. Do not assume every new SMS invalidates the previous one.
2. Enter the characters carefully
Type the digits from the correct message into the correct field. Remove accidental spaces from copying, check that a browser or phone did not autofill an older code, and avoid mixing codes sent by different services. A code for email verification is not necessarily interchangeable with a code for phone sign-in.
3. Keep the same verification session
Codes are commonly associated with a particular account, phone number or transaction. Switching accounts, changing the number, opening several tabs or restarting the flow can leave you entering a valid-looking code into the wrong request. Return to one official page and complete one attempt at a time.
4. Respect the expiry shown by the service
Use the on-screen countdown if there is one. There is no universal SMS-code lifetime. Twilio Verify, for example, documents a default ten-minute validity period that can be configured differently. A message delayed by the network might arrive after the relevant window; request another code only when the service permits it.
5. Stop when you hit a limit
Rapid resends or repeated wrong entries can trigger rate limits. Follow the displayed wait period and do not keep cycling through numbers or sessions. More requests may make it harder to tell which code belongs to the active flow.
6. Try an approved alternative
If the service offers a passkey, authenticator app, backup code or official recovery process, use that option. If the error persists with a fresh request, contact the service through its own help page and describe the exact message. Never give support staff your one-time code.
Special case: public or temporary SMS inboxes
A shared inbox can display codes to other visitors. Someone else may enter a one-time code first, or the inbox may stop receiving messages. A platform may also reject a number type before sending anything. Public numbers are not appropriate for banking, primary email or permanent account recovery; use a number or stronger sign-in method you control for important accounts.
What this guide does not cover
If no SMS arrived at all, read our code-not-arriving guide. If the form rejects the phone number before sending a code, the problem is number eligibility rather than code validity. Keeping these cases separate helps you avoid unnecessary retries.
Frequently asked questions
Does Resend always create a new code?
No. It depends on the provider and its configuration. Follow the service's current instructions and use the code associated with the active request.
Can I use a code after a successful sign-in?
Usually not: a one-time code is intended for one verification. Start a new official request if another check is required.
Should I change my phone's clock?
For an SMS code, first check the code, request and expiry. Clock synchronization is more relevant to time-based authenticator apps; changing the phone clock is not a general fix for a rejected SMS.
Bottom line
Check the exact error, current message and session; respect expiry and retry limits; then use an official alternative if needed. Never share an OTP or assume a public inbox provides private access.