Buy Old Gmail Accounts With 2FA

Buy Old Gmail Accounts With 2FA

24h4.235.8% drop3.3k sold

5000 in stock

A Gmail account registered at least a year before delivery, with 2-Step Verification on and, on most batches, the authenticator key in your delivery. Replaced within 24 hours if the account or its second step fails as delivered.

Delivery format: email:password:recovery email:2fa key

Field order varies by batch, and not every line carries every field. An app password, backup codes or both can take the place of the key or follow it. Match each piece to the table lower on the page.

Google's six-digit prompt on a new device is answered from the key: paste it into the checkkit 2FA generator and type the number before its 30 seconds run out.

Authenticator, not SMS

Where the second step lives on a bought account

Google asks for a second step when a sign-in comes from a device it does not know. On an account that changes hands, the real question is where that step is kept. A text message goes to the phone number the seller registered, and you will probably never see it. An authenticator key is a line of text in your delivery. It makes the code on any device you choose.

  • 2-Step Verification on, on every account in the order
  • The authenticator key in the delivery on most batches, a set of backup codes instead on a few
  • Registered at least a year before delivery; batches aged in days never qualify
  • The key works in Google Authenticator, in any app that takes a standard TOTP key, and in the generator linked under the buy box
  • Not promised: a recovery email, a phone number, a particular year or an empty inbox
Need the account to be American as well? See old US Gmail

Why SMS is the weak link here

A code by text belongs to whoever holds the SIM. That is not you. A number that lapses or gets passed to someone new can leave the account stuck at the prompt for good. A key has no SIM behind it.

Treat the key like a password

Anyone holding the key can make valid codes. Keep it in a password manager, not in a chat, a note app or a shared sheet.

One year or more

Why a year floor comes with it

Every account here also passed an age test. The batch has to name registration years that all end at least a full year before today. Age and the key cover different things. Age is for services that look at how long an address has existed; the key is for Google's own sign-in prompt. Neither replaces the other.

  • A batch qualifies only when every year it names ends a full year or more before delivery
  • Accounts in one order can come from different years inside that range
  • You cannot choose the year on this listing; the homepage catalogue sells single batches by year

Age is a date, not a record

A 2021 account may have sat idle for most of that time. Read the age as a fact about when it was made. It says nothing about activity, contacts or how its mail has been received.

Backup codes as a spare

Where a batch includes them, each 8-digit code gets past the prompt once. Keep two or three unused for the day the phone with your authenticator is out of reach.

Authenticator key or SMS code on a bought Gmail

Google offers more than one kind of second step. On an account that has changed hands, they behave very differently.

SituationSecond step by SMSSecond step by authenticator key
First sign-in from your deviceThe code goes to the seller's numberYou make the code from the key yourself
A year on, the number has lapsedNothing arrives, so you depend on recovery optionsNo change: the key does not expire
Retiring the seller's copySwap the phone number, which Google may hold for reviewChange authenticator app: a new key replaces the old one

Describes how Google 2-Step Verification works for any account at the time of writing. A new key alone does not close every way back in: review recovery details and signed-in devices too.

Reading the line

Which field is which

Everything for one account sits on a single line, split by colons. Each supplier orders them its own way, so go by what a field looks like, not where it sits.

FieldShapeUse
Address, password, recovery emailTwo items with an @: the @gmail.com one is the account, the other is its recovery mailbox. The password is the plain string beside the account.Web sign-in, and answering a recovery prompt
2FA keyAbout 32 capital letters and the digits 2 to 7, often in groups of fourMaking the six-digit sign-in code in an authenticator app or the linked generator
App password or backup codes16 lowercase letters, often in four groups; or a run of 8-digit numbersIMAP and SMTP software; one web sign-in per backup code

A listing promises only what its page says. Fields beyond that are a bonus of the batch.

When it does not work

Three problems buyers hit first

A prompt on the first sign-in is Google meeting a new device, and it usually clears. Accounts that fail as delivered are replaced when reported within 24 hours.

ProblemFix
The six-digit code is refusedCodes follow the clock. Set the device time to update automatically, wait for the next code and enter it within its 30 seconds.
A mail client rejects the app passwordUse the full Gmail address as the username, with imap.gmail.com on port 993 and SSL. If the account password was changed, the app password is gone and a new one has to be made.
Google asks to confirm the recovery email, or to "verify it's you"Answer with the recovery address from your line. After two failed tries, stop and return an hour later from the same browser. Report the account if the prompt will not clear.

The 24-hour window starts at delivery. It covers what arrives broken; a password or key you change yourself falls outside it.

Before 24 hours pass

Prove the key works, then store it

The 24-hour replacement window covers an account or second step that fails as delivered. Four steps, a few minutes each.

  1. Add the key to your authenticator app, or paste it into the generator linked under the buy box, and note the six-digit code.
  2. Go to accounts.google.com, sign in with the delivered login, then type that code at the prompt.
  3. Open Security, then 2-Step Verification, and check that an authenticator app is listed as a second step.
  4. A code refused on a correctly set clock, or 2-Step Verification showing as off, is a fault on our side: flag the account on its order page while the window is open.
FAQ

Questions about this listing

Can I turn 2FA off once I am in?
Google lets you, but on a bought account it is the wrong direction. Without a second step, the password alone opens the account, and the seller knew that password. Change the password and set up a fresh key instead.
My batch sent backup codes and no key. What now?
Sign in with one of the codes, open 2-Step Verification and add an authenticator app. Google shows the new key as a QR code, with a text version you can copy. Save that text, and the account works like the rest of this listing.
Will Google stop asking for checks once 2FA is on?
No. It decides what Google asks for, not whether it asks. A new device, a new country or several failed tries can still bring up extra checks, such as confirming the recovery email.
Does the seller still have the key?
Assume so, since the key was made before the sale. After you have signed in, use Change authenticator app in the 2-Step Verification settings. Google issues a new key, and codes from the old one stop working.

Recommended products

Recent reviews

  • 9/22/2026

    Fast delivery and worked as described.

  • 9/21/2026

    Smooth checkout, account credentials arrived quickly.

  • 9/20/2026

    Good quality account, no issues so far.

  • 9/18/2026

    Exactly what I needed for my project.