You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

密码到期通知PowerShell脚本无法发送邮件问题排查

解决AD密码到期提醒脚本SMTP认证失败问题

1. 补全SMTP服务器安全配置参数

  • 明确指定SMTP端口:AWS SES(对应smtpaws.com)的标准端口为587(STARTTLS)或465(SSL),默认25端口通常会被限制。在测试命令中添加-smtpPort参数,例如:
    PasswordChangeNotification.ps1 -smtpServer smtpaws.com -smtpPort 587 -expireInDays 7 -from "noreply@domain.com" -Logging -LogPath "C:\Scripts\Logs" -testing -testRecipient user@domain.com
    
  • 强制启用安全连接:确保脚本发送邮件的逻辑中包含-UseSsl参数(针对Send-MailMessage cmdlet),如果脚本未封装该参数,需要直接修改脚本内的邮件发送代码,添加-UseSsl和对应端口配置。

2. 添加SMTP认证凭据

AWS SES要求使用专门的SMTP凭据(非IAM访问密钥,需在IAM控制台生成)进行认证:

  • 先创建PSCredential对象存储凭据:
    $securePassword = ConvertTo-SecureString "你的SMTP密码" -AsPlainText -Force
    $smtpCredential = New-Object System.Management.Automation.PSCredential ("你的SMTP用户名", $securePassword)
    
  • 在测试命令中传入凭据参数(需确保脚本支持-smtpCredential参数):
    PasswordChangeNotification.ps1 -smtpServer smtpaws.com -smtpPort 587 -smtpCredential $smtpCredential -expireInDays 7 -from "noreply@domain.com" -Logging -LogPath "C:\Scripts\Logs" -testing -testRecipient user@domain.com
    
  • 若脚本未支持凭据参数,直接修改脚本内的邮件发送代码,添加-Credential $smtpCredential配置。

3. 验证发件人地址合法性

AWS SES要求发件人邮箱或域名必须经过验证,登录SES控制台确认noreply@domain.com已完成邮箱验证或域名验证,未验证的发件地址会被服务器拒绝。

4. 单独测试SMTP连通性

用独立的Send-MailMessage命令测试SMTP配置,排除脚本其他逻辑干扰:

$smtpParams = @{
    SmtpServer  = "smtpaws.com"
    Port        = 587
    UseSsl      = $true
    Credential  = $smtpCredential
    From        = "noreply@domain.com"
    To          = "user@domain.com"
    Subject     = "SMTP认证测试"
    Body        = "测试邮件内容"
}
Send-MailMessage @smtpParams

如果该命令发送成功,说明SMTP配置正确,问题出在脚本对参数的处理上;如果失败,根据返回的错误信息进一步排查凭据或端口问题。

内容的提问来源于stack exchange,提问作者Spertrun

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 04:16:14