基于Node.js配置网站联系页Outlook SMTP遇认证失败问题排查
Outlook SMTP认证失败(535 5.7.3)解决建议
问题场景
在Node.js项目中使用Nodemailer配置Outlook/Office 365 SMTP服务时,遇到以下认证错误:
[0] Error: Invalid login: 535 5.7.3 Authentication unsuccessful [MA0PR01CA0059.INDPRD01.PROD.OUTLOOK.COM 2024-04-06T09:43:31.279Z 08DC55931D44CA62] [0] at SMTPConnection._formatError (/home/abhishek/Academy_Website/node_modules/nodemailer/lib/smtp-connection/index.js:790:19) [0] at SMTPConnection._actionAUTHComplete (/home/abhishek/Academy_Website/node_modules/nodemailer/lib/smtp-connection/index.js:1564:34) [0] at SMTPConnection.<anonymous> (/home/abhishek/Academy_Website/node_modules/nodemailer/lib/smtp-connection/index.js:1518:18) [0] at SMTPConnection._processResponse (/home/abhishek/Academy_Website/node_modules/nodemailer/lib/smtp-connection/index.js:969:20) [0] at SMTPConnection._onData (/home/abhishek/Academy_Website/node_modules/nodemailer/lib/smtp-connection/index.js:755:14) [0] at SMTPConnection._onSocketData (/home/abhishek/Academy_Website/node_modules/nodemailer/lib/smtp-connection/index.js:193:44) [0] at TLSSocket.emit (node:events:513:28) [0] at addChunk (node:internal/streams/readable:324:12) [0] at readableAddChunk (node:internal/streams/readable:297:9) [0] at Readable.push (node:internal/streams/readable:234:10) { [0] code: 'EAUTH', [0] response: '535 5.7.3 Authentication unsuccessful [MA0PR01CA0059.INDPRD01.PROD.OUTLOOK.COM 2024-04-06T09:43:31.279Z 08DC55931D44CA62]', [0] responseCode: 535, [0] command: 'AUTH LOGIN'
使用的Nodemailer配置代码:
const transporter = nodemailer.createTransport({ host: "smtp.office365.com", // Outlook/Office 365 SMTP server port: 587, // Port for TLS/STARTTLS secure: false, // true for 465, false for other ports auth: { user: process.env.EMAIL_ADDRESS, // Your Outlook/Office 365 email address pass: process.env.EMAIL_PASSWORD, // Your Outlook/Office 365 password }, tls: { ciphers: "SSLv3", }, });
怀疑问题与Microsoft Entra的安全默认设置有关,但无法找到单独针对该用户修改设置的方法。
解决建议
校验基础认证信息
确认环境变量EMAIL_ADDRESS和EMAIL_PASSWORD没有拼写错误、多余空格或特殊字符未转义。直接用该邮箱账号和密码登录Outlook网页版,验证账号未被锁定、状态正常。使用应用密码替代普通密码
如果该邮箱开启了多重身份验证(MFA),普通密码无法用于SMTP认证。需要登录Microsoft账户安全页面,生成专门的应用密码,替换代码中的EMAIL_PASSWORD。调整TLS配置
代码中指定的SSLv3加密协议已被Outlook弃用,建议修改TLS配置:tls: { rejectUnauthorized: false, // 测试环境临时使用,生产环境建议配置合法SSL证书 minVersion: 'TLSv1.2' }配置Entra ID用户级认证策略
若为Office 365组织账户,全局管理员可在Entra管理中心操作:- 进入「用户」→ 目标用户 →「身份验证方法」
- 确保该用户的「传统认证」未被禁用(SMTP属于传统认证范畴)
- 若组织开启了安全默认值,无法单独禁用单个用户的传统认证限制,可选择:
- 为该用户创建条件访问策略,允许其使用SMTP传统认证
- 改用Microsoft Graph API发送邮件(符合现代认证标准,替代SMTP)
确认SMTP连接参数
当前使用的host: smtp.office365.com、port:587、secure:false参数符合Outlook要求,无需修改。
内容的提问来源于stack exchange,提问作者Tabish Imam
相关产品推荐
相关产品推荐

