You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用C# MailKit发送邮件时SMTP认证失败的问题排查

问题:MailKit连接Office365 SMTP验证失败(535错误)

错误信息

535: 5.7.139 Authentication unsuccessful, the user credentials were incorrect. [BN8PR12CA0010.namprd12.prod.outlook.com 2023-04-27T20:31:00.281Z 08DB46E9CDA92BA3]

C# 代码(使用MailKit 4.0)

using(var client = new SmtpClient())
{
    client.Connect(config.Email.Smtp, 587, SecureSocketOptions.StartTls);
    client.Authenticate(config.Email.Username, config.Email.Password);
    var message = new MimeMessage();
    message.From.Add(new MailboxAddress("No-Reply", config.Email.From));
    message.To.Add(new MailboxAddress("Display To User", config.Email.To));
    message.Subject = "Subject Goes Here";
    message.Body = new TextPart("html")
    {
        Text = errors.Any() ? string.Join("<br/>", errors) : "Ran to completion with no errors."
    };
    client.Send(message);
    client.Disconnect(true);
}

调试确认异常在client.Authenticate(...)处抛出。

可正常运行的PowerShell脚本

$SMTPserver= "smtp.office365.com"
$username=no-reply@emaildomain.com
$password = "Password" | ConvertTo-SecureString -AsPlainText -Force
$credential = New-Object System.Management.Automation.PSCredential($username, $password)
Send-MailMessage -ErrorAction Stop -from $EmailFrom -to $EmailTo -cc $ccRecipients -subject $EmailSubject -body $EmailReport -SmtpServer $SMTPserver -Priority  Normal -Credential $credential -Port 587 -UseSsl

补充说明

  • 确认未配置OTP或2FA
  • 用户名和密码仅含ASCII字符,团队成员均遇此问题,排除拼写错误
  • MailKit版本为4.0
  • SMTP协议日志:
Connected to smtp://smtp.office365.com:587/?starttls=when-available
S: 220 BN8PR04CA0063.outlook.office365.com Microsoft ESMTP MAIL Service ready at Mon, 1 May 2023 12:41:38 +0000
C: EHLO BLD
S: 250-BN8PR04CA0063.outlook.office365.com Hello [161.199.135.241]
S: 250-SIZE 157286400
S: 250-PIPELINING
S: 250-DSN
S: 250-ENHANCEDSTATUSCODES
S: 250-STARTTLS
S: 250-8BITMIME
S: 250-BINARYMIME
S: 250-CHUNKING
S: 250 SMTPUTF8
C: STARTTLS
S: 220 2.0.0 SMTP server ready
C: EHLO BLD
S: 250-BN8PR04CA0063.outlook.office365.com Hello [161.199.135.241]
S: 250-SIZE 157286400
S: 250-PIPELINING
S: 250-DSN
S: 250-ENHANCEDSTATUSCODES
S: 250-AUTH LOGIN XOAUTH2
S: 250-8BITMIME
S: 250-BINARYMIME
S: 250-CHUNKING
S: 250 SMTPUTF8
C: AUTH LOGIN
S: 334 VXNlcm5hbWU6
C: ********
S: 334 UGFzc3dvcmQ6
C: ********
S: 535 5.7.139 Authentication unsuccessful, the user credentials were incorrect. [BN8PR04CA0063.namprd04.prod.outlook.com 2023-05-01T12:41:52.739Z 08DB49979AAF0242]

解决方案

1. 强制使用NTLM认证

从协议日志可见,MailKit默认用AUTH LOGIN,但PowerShell的Send-MailMessage可能优先用NTLM认证。修改C#代码的认证逻辑:

// 替换原client.Authenticate调用
var credentials = new NetworkCredential(config.Email.Username, config.Email.Password);
client.Authenticate(new SaslMechanismNtlm(credentials));

2. 核对SMTP服务器地址

确保config.Email.Smtp的值为smtp.office365.com,和PowerShell脚本中的地址完全一致,避免配置项错误。

3. 开启邮箱的传统SMTP权限

Office365可能默认阻止用户名密码式SMTP认证,需在Azure AD后台为该邮箱账户开启"允许使用用户名/密码进行SMTP认证"权限。

4. 排查密码转义问题

即使是ASCII字符,配置文件中的特殊字符(如\、引号)可能被转义,导致实际传递的密码与PowerShell中使用的不一致。可在代码中输出密码哈希值,和PowerShell中密码的哈希对比验证。

5. 切换到OAuth2认证(推荐)

Office365逐步淘汰传统SMTP认证,建议改用XOAUTH2方式。需先在Azure AD注册应用,获取客户端ID,再通过以下方式认证:

// 需要引入Microsoft.Identity.Client库
var scopes = new[] { "https://outlook.office365.com/SMTP.Send" };
var app = PublicClientApplicationBuilder.Create("你的客户端ID").Build();
var result = await app.AcquireTokenInteractive(scopes).ExecuteAsync();
client.Authenticate(new SaslMechanismOAuth2(config.Email.Username, result.AccessToken));

内容的提问来源于stack exchange,提问作者Luv2Learn

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 16:23:14