Office 365 SMTP authentication failing, even with correct account information

Anonymous
2020-02-10T16:38:43+00:00

On my Wordpress site I've run into a problem in the last day or so, where emails simply fail to send. Before today it was running flawlessly for two months. The account information/password/username etc have not changed in that two months.

I'm using a Wordpress plugin called WP Mail SMTP to facilitate the sending of all outgoing emails. The error log I'm getting from the email test on that is as follows:

Versions:

WordPress: 5.3.2

WordPress MS: No

PHP: 7.3.14-5+0~20200202.52+debian9~1.gbpa71879

WP Mail SMTP: 1.8.1

Params:

Mailer: smtp

Constants: No

ErrorInfo: SMTP Error: Could not authenticate.

Host: smtp.office365.com

Port: 587

SMTPSecure: tls

SMTPAutoTLS: bool(true)

SMTPAuth: bool(true)

Server:

OpenSSL: OpenSSL 1.1.1d 10 Sep 2019

SMTP Debug:

2020-02-10 16:36:56 Connection: opening to smtp.office365.com:587, timeout=300, options=array ()

2020-02-10 16:36:56 Connection: opened

2020-02-10 16:36:56 SERVER -> CLIENT: 220 LNXP123CA0008.outlook.office365.com Microsoft ESMTP MAIL Service ready at Mon, 10 Feb 2020 16:36:55 +0000

2020-02-10 16:36:56 CLIENT -> SERVER: EHLO www.*****.com

2020-02-10 16:36:56 SERVER -> CLIENT: 250-LNXP123CA0008.outlook.office365.com Hello [***]250-SIZE 157286400250-PIPELINING250-DSN250-ENHANCEDSTATUSCODES250-STARTTLS250-8BITMIME250-BINARYMIME250-CHUNKING250 SMTPUTF8

2020-02-10 16:36:56 CLIENT -> SERVER: STARTTLS

2020-02-10 16:36:56 SERVER -> CLIENT: 220 2.0.0 SMTP server ready

2020-02-10 16:36:56 CLIENT -> SERVER: EHLO www.zestpromotional.com

2020-02-10 16:36:56 SERVER -> CLIENT: 250-LNXP123CA0008.outlook.office365.com Hello [***]250-SIZE 157286400250-PIPELINING250-DSN250-ENHANCEDSTATUSCODES250-AUTH LOGIN XOAUTH2250-8BITMIME250-BINARYMIME250-CHUNKING250 SMTPUTF8

2020-02-10 16:36:56 CLIENT -> SERVER: AUTH LOGIN

2020-02-10 16:36:56 SERVER -> CLIENT: 334 VXNlcm5hbWU6

2020-02-10 16:36:56 CLIENT -> SERVER: c2FsZXNAemVzdHByb21vdGlvbmFsLmNvbQ==

2020-02-10 16:36:56 SERVER -> CLIENT: 334 UGFzc3dvcmQ6

2020-02-10 16:36:56 CLIENT -> SERVER: QmFkMzM4MzA=

2020-02-10 16:37:02 SERVER -> CLIENT: 535 5.7.3 Authentication unsuccessful [LNXP123CA0008.GBRP123.PROD.OUTLOOK.COM]

2020-02-10 16:37:02 SMTP ERROR: Password command failed: 535 5.7.3 Authentication unsuccessful [LNXP123CA0008.GBRP123.PROD.OUTLOOK.COM]

SMTP Error: Could not authenticate.

2020-02-10 16:37:02 CLIENT -> SERVER: QUIT

2020-02-10 16:37:02 SERVER -> CLIENT: 221 2.0.0 Service closing transmission channel

2020-02-10 16:37:02 Connection: closed

SMTP Error: Could not authenticate.

Does anyone have any ideas at all? I'm completely at a loss here.

Microsoft 365 and Office | Subscription, account, billing | For home | Windows

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

48 answers

Sort by: Newest
  1. Anonymous
    2020-08-07T16:05:46+00:00

    Thanks timme,

    It worked! Great job!

    Almost scratch my head when i configured xerox printer to relay scanned pdf through office 365.

    Never had a problem with other tenant before, now i'm having this kind of problem.

    Thanks microsoft managed service, great job.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2020-07-25T12:14:22+00:00

    If you are using desktop Outlook and are on versions 2010 or 2013, openid authentication (on top of Oauth2) is not supported by 2010 and is only supported via a registry change in 2013.

    Was this answer helpful?

    0 comments No comments
  3. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  4. Anonymous
    2020-07-25T11:05:09+00:00

    The 17th July 2020 doc Option 1 (recommended): “Authenticate your device or application directly with a Microsoft 365 or Office 365 mailbox, and send mail using SMTP AUTH client submission” confused me, and I think the confusion comes from my being unable to distinguish when the doc is referring to SMTP AUTH with Basic Authentication or SMTP AUTH with Oauth2 (or both!).

    Your comment “Regarding basic authentication … this is a protocol-based setting and it disables SMTP AUTH, regardless of whether basic auth or OAuth is being used” is a minor bombshell and confuses me further. MSFT’s original announcement was that Basic Authentication was deprecated and would be discontinued early this year, with the discontinue date then being moved to later in 2021. We were guided to replace Basic Authentication by Modern Authentication (aka Oauth2). Your comment above implies that EITHER form of authentication* is deprecated – that SMTP itself will be blocked! If so, what is the recommended replacement?

    * to be pedantic: for ‘Oauth2’ read openid authentication with Oauth2 authorisation

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  5. Anonymous
    2020-07-24T21:56:29+00:00

    Hi all,

    As mentioned above, the SMTP AUTH protocol is now disabled by default for new organisations onboarding to Microsoft 365/Office 365/Exchange Online. This was announced here: 

    https://techcommunity.microsoft.com/t5/exchange-team-blog/securing-authenticated-smtp-in-exchange-online/ba-p/1293154

    The change uses two settings, an organisation setting (SmtpClientAuthenticationDisabled) , and per-mailbox settings (Under Manage Email Apps or the ) to allow admins to finetune what mailboxes have this protocol enabled. with the per-mailbox settings overriding the organsation setting such that you only need to enable mailboxes that need to use the protocol and allow the others to remain secured and disabled. 

    You can learn who to change these in the document shared above: 

    https://docs.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/authenticated-client-smtp-submission 

    For reference, the main support document that offers advice on how to configure devices and clients like Wordpress sites to send emails can be found here: 

    https://docs.microsoft.com/en-us/exchange/mail-flow-best-practices/how-to-set-up-a-multifunction-device-or-application-to-send-email-using-microsoft-365-or-office-365

    We added a note warning about SMTP AUTH being disabled to it as part of this change in behaviour. 

    Regarding basic authentication, just to be clear, this is a protocol-based setting and it disables SMTP AUTH, regardless of whether basic auth or OAuth is being used.

    Was this answer helpful?

    5 people found this answer helpful.
    0 comments No comments