使用C# MailKit发送邮件时SMTP认证失败的问题排查
问题:MailKit连接Office365 SMTP验证失败(535错误)
错误信息
535: 5.7.139 Authentication unsuccessful, the user credentials were incorrect. [BN8PR12CA0010.namprd12.prod.outlook.com 2023-04-27T20:31:00.281Z 08DB46E9CDA92BA3]
C# 代码(使用MailKit 4.0)
using(var client = new SmtpClient()) { client.Connect(config.Email.Smtp, 587, SecureSocketOptions.StartTls); client.Authenticate(config.Email.Username, config.Email.Password); var message = new MimeMessage(); message.From.Add(new MailboxAddress("No-Reply", config.Email.From)); message.To.Add(new MailboxAddress("Display To User", config.Email.To)); message.Subject = "Subject Goes Here"; message.Body = new TextPart("html") { Text = errors.Any() ? string.Join("<br/>", errors) : "Ran to completion with no errors." }; client.Send(message); client.Disconnect(true); }
调试确认异常在client.Authenticate(...)处抛出。
可正常运行的PowerShell脚本
$SMTPserver= "smtp.office365.com" $username=no-reply@emaildomain.com $password = "Password" | ConvertTo-SecureString -AsPlainText -Force $credential = New-Object System.Management.Automation.PSCredential($username, $password) Send-MailMessage -ErrorAction Stop -from $EmailFrom -to $EmailTo -cc $ccRecipients -subject $EmailSubject -body $EmailReport -SmtpServer $SMTPserver -Priority Normal -Credential $credential -Port 587 -UseSsl
补充说明
- 确认未配置OTP或2FA
- 用户名和密码仅含ASCII字符,团队成员均遇此问题,排除拼写错误
- MailKit版本为4.0
- SMTP协议日志:
Connected to smtp://smtp.office365.com:587/?starttls=when-available S: 220 BN8PR04CA0063.outlook.office365.com Microsoft ESMTP MAIL Service ready at Mon, 1 May 2023 12:41:38 +0000 C: EHLO BLD S: 250-BN8PR04CA0063.outlook.office365.com Hello [161.199.135.241] S: 250-SIZE 157286400 S: 250-PIPELINING S: 250-DSN S: 250-ENHANCEDSTATUSCODES S: 250-STARTTLS S: 250-8BITMIME S: 250-BINARYMIME S: 250-CHUNKING S: 250 SMTPUTF8 C: STARTTLS S: 220 2.0.0 SMTP server ready C: EHLO BLD S: 250-BN8PR04CA0063.outlook.office365.com Hello [161.199.135.241] S: 250-SIZE 157286400 S: 250-PIPELINING S: 250-DSN S: 250-ENHANCEDSTATUSCODES S: 250-AUTH LOGIN XOAUTH2 S: 250-8BITMIME S: 250-BINARYMIME S: 250-CHUNKING S: 250 SMTPUTF8 C: AUTH LOGIN S: 334 VXNlcm5hbWU6 C: ******** S: 334 UGFzc3dvcmQ6 C: ******** S: 535 5.7.139 Authentication unsuccessful, the user credentials were incorrect. [BN8PR04CA0063.namprd04.prod.outlook.com 2023-05-01T12:41:52.739Z 08DB49979AAF0242]
解决方案
1. 强制使用NTLM认证
从协议日志可见,MailKit默认用AUTH LOGIN,但PowerShell的Send-MailMessage可能优先用NTLM认证。修改C#代码的认证逻辑:
// 替换原client.Authenticate调用 var credentials = new NetworkCredential(config.Email.Username, config.Email.Password); client.Authenticate(new SaslMechanismNtlm(credentials));
2. 核对SMTP服务器地址
确保config.Email.Smtp的值为smtp.office365.com,和PowerShell脚本中的地址完全一致,避免配置项错误。
3. 开启邮箱的传统SMTP权限
Office365可能默认阻止用户名密码式SMTP认证,需在Azure AD后台为该邮箱账户开启"允许使用用户名/密码进行SMTP认证"权限。
4. 排查密码转义问题
即使是ASCII字符,配置文件中的特殊字符(如\、引号)可能被转义,导致实际传递的密码与PowerShell中使用的不一致。可在代码中输出密码哈希值,和PowerShell中密码的哈希对比验证。
5. 切换到OAuth2认证(推荐)
Office365逐步淘汰传统SMTP认证,建议改用XOAUTH2方式。需先在Azure AD注册应用,获取客户端ID,再通过以下方式认证:
// 需要引入Microsoft.Identity.Client库 var scopes = new[] { "https://outlook.office365.com/SMTP.Send" }; var app = PublicClientApplicationBuilder.Create("你的客户端ID").Build(); var result = await app.AcquireTokenInteractive(scopes).ExecuteAsync(); client.Authenticate(new SaslMechanismOAuth2(config.Email.Username, result.AccessToken));
内容的提问来源于stack exchange,提问作者Luv2Learn
相关产品推荐
相关产品推荐

