◇ Delivery failures

535 5.7.8 Authentication failed — the SMTP server rejected your login

PermanentYour side

Retrying will not help. The message will not be delivered.

The reply

535 5.7.8 Error: authentication failed: Invalid user or password!

The server you submit mail to did not accept the username and password, and nothing was sent. The cause is almost always the credentials themselves: a mistyped or changed password, the wrong login format, or a provider that wants an app password instead of the account password.

What it means

RFC 4954 defines 535 5.7.8 as "authentication credentials invalid": the AUTH exchange took place, the server checked the login and password and said no. It happens before MAIL FROM, so the failure stays between your application and the server it submits to — no recipient saw anything and your reputation is untouched. The big mailbox providers no longer accept the account password from programs. Gmail with 2-Step Verification wants an app password, Yandex wants an app password and mail-client access switched on, and Mail.ru answers "535 5.7.0 … Application password is REQUIRED".

Why it happens

  • A wrong password, or one that was changed or regenerated after the application was configured.
  • The provider requires an app password: Gmail with 2-Step Verification, Yandex, Mail.ru.
  • The wrong login format: the server expects the full address and got only the part before the @, or a space came along with a copy-paste.
  • At Yandex, access for mail programs is switched off in the mailbox settings.
  • Credentials from the wrong place: the dashboard password instead of the SMTP token's, or a token of another domain.

What to do

  1. Copy the login and password again from their source, without surrounding spaces, and paste rather than retype them.
  2. For Gmail, Yandex and Mail.ru, create an app password in the account's security settings and use it instead of the account password.
  3. Use the login format the provider documents. That is usually the full email address; for an SMTP relay it is the token's login.
  4. Match encryption to the port: STARTTLS on 587, SSL/TLS on 465. Many servers do not offer AUTH at all before TLS.
  5. Test the credentials outside the application with an SMTP test, so you know whether the password or the program's settings are at fault.

Questions

What is the difference between 535 and 530?

530 5.7.0 Authentication required means the client tried to send without logging in at all. 535 means it logged in and the server refused the login or password.

Why 535 when the password is definitely correct?

Because the provider does not accept the account password from mail programs. Gmail, Yandex and Mail.ru issue separate app passwords for SMTP: the account password works in the browser and fails here.

Which AUTH method should I use?

PLAIN over an encrypted connection works everywhere. Our relay accepts AUTH PLAIN only: a client restricted to LOGIN gets "504 5.5.4 Unrecognized authentication type". Most libraries pick PLAIN on their own when the server advertises it.

Does this affect deliverability?

No. The message was never accepted, so no receiving server saw it. Fix the credentials and send again.

More from Delivery failures

Other providers