Skip to content
Skip to main content

Outlook SMTP settings: server, port, TLS

Last updated:

Microsoft removed Basic Authentication from most Exchange Online protocols on October 1, 2022, and SMTP client submission is the last protocol still accepting it. Microsoft plans to disable Basic auth for SMTP AUTH by default at the end of December 2026. The server is still smtp.office365.com on port 587 with STARTTLS, but new integrations should authenticate with an OAuth 2.0 token in XOAUTH2 format. Here’s the full reference.

What are the Outlook SMTP server settings?

Section titled “What are the Outlook SMTP server settings?”

The Outlook SMTP server is smtp.office365.com on port 587 with STARTTLS; Microsoft deprecated port 25 for client submission and recommends 587 over 465 for Exchange Online. Authentication uses OAuth 2.0 (Modern Auth), and the username is the full email address.

SettingValue
SMTP server (Microsoft 365 / Exchange Online)smtp.office365.com
SMTP server (Outlook.com personal accounts)smtp-mail.outlook.com
Port587
EncryptionSTARTTLS (required)
AuthenticationOAuth 2.0 (Modern Auth)
UsernameFull email address
IMAP serveroutlook.office365.com (port 993, TLS)
POP3 serveroutlook.office365.com (port 995, TLS)

Three details catch developers. First, personal Outlook.com accounts use a different SMTP hostname (smtp-mail.outlook.com) than Microsoft 365 work accounts, on the same port 587. Second, the IMAP and POP3 hostname (outlook.office365.com) differs from the SMTP hostname, so copying one into the other field fails. Third, SMTP AUTH can be switched off for the whole organization or for individual mailboxes, and it’s already off in tenants that use Entra ID security defaults. Microsoft’s SMTP AUTH documentation shows how an admin checks and changes the setting with Set-CASMailbox -SmtpClientAuthenticationDisabled.

How did the Basic Auth shutdown change SMTP access?

Section titled “How did the Basic Auth shutdown change SMTP access?”

Microsoft disabled Basic Authentication for most Exchange Online protocols, including POP, IMAP, EWS, Exchange ActiveSync, and Remote PowerShell, starting October 1, 2022. SMTP AUTH got an exception that Microsoft has extended several times. The current plan, published in the updated SMTP AUTH deprecation timeline, disables Basic auth for SMTP AUTH by default for existing tenants at the end of December 2026, lets tenant admins re-enable it, and says Microsoft will announce the final removal date in the second half of 2027. For tenants created after December 2026, Basic auth for SMTP AUTH is unavailable by default and OAuth is the supported method, so new integrations should present an OAuth 2.0 access token using the XOAUTH2 SASL mechanism from the start.

Modern Auth SMTP needs an Entra ID (Azure AD) app registration with the SMTP.Send delegated permission. The token request goes to https://login.microsoftonline.com/{tenant}/oauth2/v2.0/token with scope=https://outlook.office.com/SMTP.Send (add offline_access for refresh tokens); app-only flows authorized by a tenant admin use scope=https://outlook.office365.com/.default instead. Microsoft access tokens last a random 60 to 90 minutes by default, so production code needs a refresh loop. If you send through a Microsoft grant on Nylas instead, you skip all of this: Nylas stores the refresh token and renews access tokens for you. The handshake then looks like this:

EHLO client.example.com
STARTTLS
EHLO client.example.com
AUTH XOAUTH2 <base64-encoded-token-string>
# Token string format before base64 encoding:
# [email protected]^Aauth=Bearer <access_token>^A^A
# where ^A is the ASCII SOH character (0x01)

The XOAUTH2 string isn’t a standard Bearer header: the user= and auth=Bearer fields are separated by SOH (0x01) characters before the whole string is base64-encoded. A malformed string fails authentication. Microsoft’s XOAUTH2 documentation includes a sample that builds the string correctly.

What are common Outlook SMTP errors and fixes?

Section titled “What are common Outlook SMTP errors and fixes?”

Outlook SMTP returns RFC 5321 reply codes with Microsoft-specific enhanced status codes. The throttling and quota errors below come from Microsoft’s documentation for SMTP AUTH submissions:

ErrorMeaningFix
432 4.3.2 Concurrent connections limit exceededMore than 3 connections are submitting messages for the mailbox at onceSend over fewer parallel connections, then retry
554 5.2.0 Submission quota exceeded (SubmissionQuotaExceededException)The mailbox passed its daily limit of 10,000 recipientsWait for the 24-hour window to roll forward, or spread sending across mailboxes
554 5.2.2 Mailbox fullThe sending mailbox is full, so it can’t save to Sent ItemsFree space, or set a retention policy on Sent Items
550 5.2.251 to 550 5.2.255The mailbox is throttled after repeated errors: mailbox full, Send As denied, invalid license, too many recipients, or invalid recipientsFix the underlying error, then wait for the throttling period to end

Microsoft documents the first three in message storage and concurrent connection throttling for SMTP AUTH, and the 5.2.25x family in continuous error throttling for SMTP AUTH. Microsoft sets the throttling period for the 5.2.25x errors, and Microsoft support can’t lift it.

Authentication failures, such as 535 5.7.3 Authentication unsuccessful, usually mean one of three things: SMTP AUTH is turned off for the mailbox or organization, the client sent a username and password where Basic auth is disabled, or the XOAUTH2 string is malformed. Check the SMTP AUTH setting first, then the token request and the SOH-separated encoding shown above. For other delivery errors, see Microsoft’s list of Exchange Online NDR and SMTP error codes.

What are the sending limits for Microsoft 365?

Section titled “What are the sending limits for Microsoft 365?”

Microsoft 365 applies these limits to each mailbox: 30 messages per minute and 10,000 recipients per 24 hours. Microsoft’s Exchange Online limits page applies them “per user to all outbound and internal messages”. For SMTP AUTH, Microsoft says messages over the per-minute rate are throttled and carried over into the following minutes, which shows up as delayed delivery. Going over the daily recipient limit returns the 554 5.2.0 error above.

LimitMicrosoft 365Outlook.com (Microsoft 365 subscribers)
Recipients per day10,0005,000
Recipients per message500 by default; admins can set 1 to 1,000500
New or external recipients per dayA tenant-wide external recipient limit, sized by license count1,000 recipients never emailed before
Messages per minute30Not published
Max message size35 MB by default; admins can set 1 MB to 150 MBNot published

Microsoft sets the 500-recipient default in its customizable recipient limits announcement. The Outlook.com figures come from Sending limits in Outlook.com, which counts a new recipient as someone the account has never emailed before. Microsoft says limits “will be lower for non-subscribers” and starts new accounts on a low temporary quota, without publishing those numbers.

The 30-messages-per-minute cap surprises teams building notification systems, because it’s per mailbox rather than per tenant. For bulk or high-volume email to external recipients, Microsoft’s Exchange Online limits recommend Azure Communication Services Email rather than a user mailbox.

How do you send Outlook email without SMTP?

Section titled “How do you send Outlook email without SMTP?”

The Nylas Email API sends through a connected Outlook or Microsoft 365 account with one HTTPS request: POST /v3/grants/{grant_id}/messages/send. The grant authenticates through Microsoft Graph with the Mail.ReadWrite and Mail.Send scopes, so SMTP AUTH never enters the picture. There’s no XOAUTH2 encoding, no per-mailbox SMTP AUTH setting, and no token refresh code, because Nylas keeps the grant’s tokens current for you.

The send Outlook email recipe has the full walkthrough, including attachments and the comparison with Microsoft Graph’s sendMail endpoint. For the provider-neutral version that also covers Gmail, Yahoo, and IMAP accounts, see send email without SMTP; Microsoft’s own sending limits above still apply because mail leaves through the user’s mailbox.