Exchange邮件服务器重启后同网段Ubuntu服务器PHPMailer认证失败求助
Alright, let's break down your problem: after restarting your on-prem Exchange server (same subnet as your Ubuntu Web Server), PHPMailer started trying to use NTLM authentication instead of the LOGIN method that works locally and on other subnets, throwing a 535 authentication error. Here are practical fixes and things to check:
1. Force LOGIN Authentication in PHPMailer
PHPMailer auto-detects supported auth methods, but your same-subnet setup might be making Exchange prioritize NTLM (even though LOGIN works). Override this by explicitly setting the auth type in your code:
Add this line right after enabling SMTPAuth:
$mail->AuthType = 'LOGIN';
This locks PHPMailer into using the same LOGIN method that works for your local tests, bypassing the auto-detected NTLM fallback that's failing.
2. Check Exchange Server Post-Restart Configs
Exchange restarts can sometimes flip settings related to authentication:
- Verify the SMTP Receive Connector for your subnet: ensure LOGIN authentication is still enabled, and that NTLM isn't set as the only allowed method.
- Check the Exchange event logs for the 535 error details—they might reveal why NTLM is failing for your account (like broken SPN registries or permission resets).
- Confirm that the IIS SMTP Virtual Server has both Basic (LOGIN) and NTLM auth enabled (if you want to keep both options open).
3. Audit Ubuntu Server's NTLM Environment
Your Ubuntu PHP stack might be pushing PHPMailer toward NTLM:
- If you have the
php-ntlmextension installed, try disabling it temporarily—this extension can make PHPMailer prefer NTLM over other auth methods. - Double-check DNS resolution on the Ubuntu server: make sure
mail.mailserver.comresolves directly to your Exchange server's IP (no weird proxy or DNS redirects that might alter auth negotiations).
4. Test SMTP Auth Manually
Use a tool like swaks on your Ubuntu server to confirm LOGIN works directly:
swaks --to test@example.com --from username@mailserver.com --server mail.mailserver.com:587 --starttls --auth LOGIN --auth-user $username --auth-password $password
If this sends successfully, you know LOGIN is supported from the Ubuntu server, and the fix is definitely just forcing PHPMailer to use it.
Since Gmail SMTP works (just slow), your network connectivity to Exchange is fine—this is purely an auth method negotiation issue. Start with forcing AuthType = 'LOGIN'; that's the quickest win here.
内容的提问来源于stack exchange,提问作者peng huang

