Microsoft removed Basic Authentication from most Exchange Online protocols on October 1, 2022, and SMTP client submission is the last protocol still accepting it. Microsoft plans to disable Basic auth for SMTP AUTH by default at the end of December 2026. The server is still smtp.office365.com on port 587 with STARTTLS, but new integrations should authenticate with an OAuth 2.0 token in XOAUTH2 format. Here’s the full reference.
What are the Outlook SMTP server settings?
Section titled “What are the Outlook SMTP server settings?”The Outlook SMTP server is smtp.office365.com on port 587 with STARTTLS; Microsoft deprecated port 25 for client submission and recommends 587 over 465 for Exchange Online. Authentication uses OAuth 2.0 (Modern Auth), and the username is the full email address.
| Setting | Value |
|---|---|
| SMTP server (Microsoft 365 / Exchange Online) | smtp.office365.com |
| SMTP server (Outlook.com personal accounts) | smtp-mail.outlook.com |
| Port | 587 |
| Encryption | STARTTLS (required) |
| Authentication | OAuth 2.0 (Modern Auth) |
| Username | Full email address |
| IMAP server | outlook.office365.com (port 993, TLS) |
| POP3 server | outlook.office365.com (port 995, TLS) |
Three details catch developers. First, personal Outlook.com accounts use a different SMTP hostname (smtp-mail.outlook.com) than Microsoft 365 work accounts, on the same port 587. Second, the IMAP and POP3 hostname (outlook.office365.com) differs from the SMTP hostname, so copying one into the other field fails. Third, SMTP AUTH can be switched off for the whole organization or for individual mailboxes, and it’s already off in tenants that use Entra ID security defaults. Microsoft’s SMTP AUTH documentation shows how an admin checks and changes the setting with Set-CASMailbox -SmtpClientAuthenticationDisabled.
How did the Basic Auth shutdown change SMTP access?
Section titled “How did the Basic Auth shutdown change SMTP access?”Microsoft disabled Basic Authentication for most Exchange Online protocols, including POP, IMAP, EWS, Exchange ActiveSync, and Remote PowerShell, starting October 1, 2022. SMTP AUTH got an exception that Microsoft has extended several times. The current plan, published in the updated SMTP AUTH deprecation timeline, disables Basic auth for SMTP AUTH by default for existing tenants at the end of December 2026, lets tenant admins re-enable it, and says Microsoft will announce the final removal date in the second half of 2027. For tenants created after December 2026, Basic auth for SMTP AUTH is unavailable by default and OAuth is the supported method, so new integrations should present an OAuth 2.0 access token using the XOAUTH2 SASL mechanism from the start.
Modern Auth SMTP needs an Entra ID (Azure AD) app registration with the SMTP.Send delegated permission. The token request goes to https://login.microsoftonline.com/{tenant}/oauth2/v2.0/token with scope=https://outlook.office.com/SMTP.Send (add offline_access for refresh tokens); app-only flows authorized by a tenant admin use scope=https://outlook.office365.com/.default instead. Microsoft access tokens last a random 60 to 90 minutes by default, so production code needs a refresh loop. If you send through a Microsoft grant on Nylas instead, you skip all of this: Nylas stores the refresh token and renews access tokens for you. The handshake then looks like this:
EHLO client.example.comSTARTTLSEHLO client.example.comAUTH XOAUTH2 <base64-encoded-token-string>
# Token string format before base64 encoding:# [email protected]^Aauth=Bearer <access_token>^A^A# where ^A is the ASCII SOH character (0x01)The XOAUTH2 string isn’t a standard Bearer header: the user= and auth=Bearer fields are separated by SOH (0x01) characters before the whole string is base64-encoded. A malformed string fails authentication. Microsoft’s XOAUTH2 documentation includes a sample that builds the string correctly.
What are common Outlook SMTP errors and fixes?
Section titled “What are common Outlook SMTP errors and fixes?”Outlook SMTP returns RFC 5321 reply codes with Microsoft-specific enhanced status codes. The throttling and quota errors below come from Microsoft’s documentation for SMTP AUTH submissions:
| Error | Meaning | Fix |
|---|---|---|
432 4.3.2 Concurrent connections limit exceeded | More than 3 connections are submitting messages for the mailbox at once | Send over fewer parallel connections, then retry |
554 5.2.0 Submission quota exceeded (SubmissionQuotaExceededException) | The mailbox passed its daily limit of 10,000 recipients | Wait for the 24-hour window to roll forward, or spread sending across mailboxes |
554 5.2.2 Mailbox full | The sending mailbox is full, so it can’t save to Sent Items | Free space, or set a retention policy on Sent Items |
550 5.2.251 to 550 5.2.255 | The mailbox is throttled after repeated errors: mailbox full, Send As denied, invalid license, too many recipients, or invalid recipients | Fix the underlying error, then wait for the throttling period to end |
Microsoft documents the first three in message storage and concurrent connection throttling for SMTP AUTH, and the 5.2.25x family in continuous error throttling for SMTP AUTH. Microsoft sets the throttling period for the 5.2.25x errors, and Microsoft support can’t lift it.
Authentication failures, such as 535 5.7.3 Authentication unsuccessful, usually mean one of three things: SMTP AUTH is turned off for the mailbox or organization, the client sent a username and password where Basic auth is disabled, or the XOAUTH2 string is malformed. Check the SMTP AUTH setting first, then the token request and the SOH-separated encoding shown above. For other delivery errors, see Microsoft’s list of Exchange Online NDR and SMTP error codes.
What are the sending limits for Microsoft 365?
Section titled “What are the sending limits for Microsoft 365?”Microsoft 365 applies these limits to each mailbox: 30 messages per minute and 10,000 recipients per 24 hours. Microsoft’s Exchange Online limits page applies them “per user to all outbound and internal messages”. For SMTP AUTH, Microsoft says messages over the per-minute rate are throttled and carried over into the following minutes, which shows up as delayed delivery. Going over the daily recipient limit returns the 554 5.2.0 error above.
| Limit | Microsoft 365 | Outlook.com (Microsoft 365 subscribers) |
|---|---|---|
| Recipients per day | 10,000 | 5,000 |
| Recipients per message | 500 by default; admins can set 1 to 1,000 | 500 |
| New or external recipients per day | A tenant-wide external recipient limit, sized by license count | 1,000 recipients never emailed before |
| Messages per minute | 30 | Not published |
| Max message size | 35 MB by default; admins can set 1 MB to 150 MB | Not published |
Microsoft sets the 500-recipient default in its customizable recipient limits announcement. The Outlook.com figures come from Sending limits in Outlook.com, which counts a new recipient as someone the account has never emailed before. Microsoft says limits “will be lower for non-subscribers” and starts new accounts on a low temporary quota, without publishing those numbers.
The 30-messages-per-minute cap surprises teams building notification systems, because it’s per mailbox rather than per tenant. For bulk or high-volume email to external recipients, Microsoft’s Exchange Online limits recommend Azure Communication Services Email rather than a user mailbox.
How do you send Outlook email without SMTP?
Section titled “How do you send Outlook email without SMTP?”The Nylas Email API sends through a connected Outlook or Microsoft 365 account with one HTTPS request: POST /v3/grants/{grant_id}/messages/send. The grant authenticates through Microsoft Graph with the Mail.ReadWrite and Mail.Send scopes, so SMTP AUTH never enters the picture. There’s no XOAUTH2 encoding, no per-mailbox SMTP AUTH setting, and no token refresh code, because Nylas keeps the grant’s tokens current for you.
The send Outlook email recipe has the full walkthrough, including attachments and the comparison with Microsoft Graph’s sendMail endpoint. For the provider-neutral version that also covers Gmail, Yahoo, and IMAP accounts, see send email without SMTP; Microsoft’s own sending limits above still apply because mail leaves through the user’s mailbox.
What’s next
Section titled “What’s next”- How to send Outlook email sends through Microsoft 365 with one API call.
- Gmail SMTP settings is the Google equivalent of this reference.
- Send email without SMTP covers the cross-provider API path.
- How to list Microsoft email messages reads the mailbox the same connection sends from.