Office 365 SMTP authentication failing, even with correct account information

Anonymous
2020-02-10T16:38:43+00:00

On my Wordpress site I've run into a problem in the last day or so, where emails simply fail to send. Before today it was running flawlessly for two months. The account information/password/username etc have not changed in that two months.

I'm using a Wordpress plugin called WP Mail SMTP to facilitate the sending of all outgoing emails. The error log I'm getting from the email test on that is as follows:

Versions:

WordPress: 5.3.2

WordPress MS: No

PHP: 7.3.14-5+0~20200202.52+debian9~1.gbpa71879

WP Mail SMTP: 1.8.1

Params:

Mailer: smtp

Constants: No

ErrorInfo: SMTP Error: Could not authenticate.

Host: smtp.office365.com

Port: 587

SMTPSecure: tls

SMTPAutoTLS: bool(true)

SMTPAuth: bool(true)

Server:

OpenSSL: OpenSSL 1.1.1d 10 Sep 2019

SMTP Debug:

2020-02-10 16:36:56 Connection: opening to smtp.office365.com:587, timeout=300, options=array ()

2020-02-10 16:36:56 Connection: opened

2020-02-10 16:36:56 SERVER -> CLIENT: 220 LNXP123CA0008.outlook.office365.com Microsoft ESMTP MAIL Service ready at Mon, 10 Feb 2020 16:36:55 +0000

2020-02-10 16:36:56 CLIENT -> SERVER: EHLO www.*****.com

2020-02-10 16:36:56 SERVER -> CLIENT: 250-LNXP123CA0008.outlook.office365.com Hello [***]250-SIZE 157286400250-PIPELINING250-DSN250-ENHANCEDSTATUSCODES250-STARTTLS250-8BITMIME250-BINARYMIME250-CHUNKING250 SMTPUTF8

2020-02-10 16:36:56 CLIENT -> SERVER: STARTTLS

2020-02-10 16:36:56 SERVER -> CLIENT: 220 2.0.0 SMTP server ready

2020-02-10 16:36:56 CLIENT -> SERVER: EHLO www.zestpromotional.com

2020-02-10 16:36:56 SERVER -> CLIENT: 250-LNXP123CA0008.outlook.office365.com Hello [***]250-SIZE 157286400250-PIPELINING250-DSN250-ENHANCEDSTATUSCODES250-AUTH LOGIN XOAUTH2250-8BITMIME250-BINARYMIME250-CHUNKING250 SMTPUTF8

2020-02-10 16:36:56 CLIENT -> SERVER: AUTH LOGIN

2020-02-10 16:36:56 SERVER -> CLIENT: 334 VXNlcm5hbWU6

2020-02-10 16:36:56 CLIENT -> SERVER: c2FsZXNAemVzdHByb21vdGlvbmFsLmNvbQ==

2020-02-10 16:36:56 SERVER -> CLIENT: 334 UGFzc3dvcmQ6

2020-02-10 16:36:56 CLIENT -> SERVER: QmFkMzM4MzA=

2020-02-10 16:37:02 SERVER -> CLIENT: 535 5.7.3 Authentication unsuccessful [LNXP123CA0008.GBRP123.PROD.OUTLOOK.COM]

2020-02-10 16:37:02 SMTP ERROR: Password command failed: 535 5.7.3 Authentication unsuccessful [LNXP123CA0008.GBRP123.PROD.OUTLOOK.COM]

SMTP Error: Could not authenticate.

2020-02-10 16:37:02 CLIENT -> SERVER: QUIT

2020-02-10 16:37:02 SERVER -> CLIENT: 221 2.0.0 Service closing transmission channel

2020-02-10 16:37:02 Connection: closed

SMTP Error: Could not authenticate.

Does anyone have any ideas at all? I'm completely at a loss here.

Microsoft 365 and Office | Subscription, account, billing | For home | Windows

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

48 answers

Sort by: Newest
  1. Anonymous
    2021-04-02T09:48:38+00:00

    Hello @ll,

    I had the same problem with a none premium version (no access to MFA configuration).

    A very good structured answer without any needs of Powershell etc. is found here:

    https://metablogue.com/send-wordpress-emails-with-microsoft-365/

    It tells you exactly how your issue with WP Mail SMTP Plugin can be solved step by step.

    Best wishes

    inkognitus

    PS:

    When you changed your configuration, please wait about 15 - 30 minutes before you test it. Obviously it needs some time to synchronize...

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2021-02-28T18:45:12+00:00

    Followed instructions provided and disabled modern authentication. via MS 365 Admin center Confirmed this changed Azure as well. Contact Us email from my business website were received. Back in business, for now. Thanks all for the help.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2021-02-28T13:30:55+00:00

    Yes - I guess it is Microsoft's way of inducing developers to use OAuth2 instead of basic authentication! And since the latter has been deprecated for IMAP and POP for a couple of years (but was only recently 'undeprecated' again - at least temporarily) it seems fair enough I guess, although it has given lots of people, me included, a headache trying to get things working. SMTP AUTH with basic authentication was never officially deprecated but branded as 'insecure'. It's worth noting, however that Conditional Access policies are not available 'from the AAD menu' in Business Basic or Business Standard accounts, although low-level policies such as 'switch on modern authentication' or 'block basic authentication' can be defined and then be allocated to an account (rather than broad-brush tenant-wide) using 365 Powershell.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2021-02-28T12:05:09+00:00

    I've been working on this the past 3 days. Recently we add multi factor security for our users and after that an inhouse application which sent emails via SMTP authentication failed to authenticate the user. I removed the MFA from the user but it didn't help. Here's how I finally solved it with the help of this thread and this one. [SOLVED] Everything using Office 365 SMTP authentication is broken, wont authenticate? - Spiceworks

    First find the reason its not authenticating. You can go into the Azure AD Admin Center-> Users->Sign Ins

    FInd the user and incident where it failed. In my case the application was "Office365 Exchange Online" The reason for failure was "

    Access has been blocked by Conditional Access policies. The access policy does not allow token issuance."

    This is a default policy that apparently is created when Modern Authentication is turned on which is a prerequisite for MFA. To get my authentication back and keep the MFA, i had to uncheck the modern authentication, create a policy for MFA sign ins.

    Uncheck modertn authentication: 365 admin center -> Settings -> org settings -> Modern authentication.

    To create conditional policies: Azure AD Admin Center->Azure AD -> Security ->Conditional Access

    • New Policy Select the users or groups , Grant -> Require MFA

    Enable policy and Save.

    This solved my specific problem.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  5. Anonymous
    2021-02-27T21:13:54+00:00

     I was struggling with that too. Finally I found a solution which requires to change properties in Azure Active Directory (Properties > Manage Security Defaults). You have to turn off "Enable Security defaults" like at the linked screenshot from the documentation.

     

    The starting point to find that solution was **Microsoft 365 Admin Center > Settings > Org settings > Services > Modern authentication.**The link to the above mentioned documentation is provided in description of Modern authentication.

     

    Now I'm able to send emails by SMTP protocol with using an app password from MFA enabled account. 

    Yes - Microsoft have made OAuth2 (the basis for Modern Authentication) a prerequisite for MFA. And it would be a bit pointless enabling MFA but leaving Basic Authentication enabled - a bit like double-locking the front door but leaving an adjacent window wide open!

    And to Mark0756's comment "MS Office tells me to pay my web host to fix", could he elaborate exactly what it says pls?

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments