SonarQube安全邮件配置失败求助及SMTP用户名设置咨询
First off, let’s clarify the SMTP username question: 9 times out of 10, you need to enter your full email address (e.g., jane.smith@company.com). Some legacy mail servers might accept just the local part (like jane.smith), but modern providers (Gmail, Outlook, most enterprise systems) require the full address to authenticate properly. If you’re using an on-prem mail server, confirm with your admin if a shortened username is allowed—but start with the full email first.
Now, let’s walk through fixing your secure SMTP connection problems with both SSL (port 465) and STARTTLS (port 587):
General Pre-Checks (Do These First!)
- Verify network access: From the SonarQube server, run a telnet test to confirm the port is reachable:
If this fails, your firewall or network is blocking the connection—work with your ops team to open the port.# For SSL (465) telnet your-smtp-server.com 465 # For STARTTLS (587) telnet your-smtp-server.com 587 - Double-check credentials: Ensure your password is correct (copy-paste to avoid typos) and that your account isn’t locked. If 2FA is enabled on your email account, you’ll need to use an app-specific password instead of your regular login password.
- Check SonarQube logs: The logs (usually in
$SONARQUBE_HOME/logs/sonar.log) will have detailed error messages (e.g., SSL handshake failures, authentication errors). These are your best clue to the root cause.
Fixes for SSL (Port 465)
Make sure your sonar.properties file has these exact settings:
sonar.email.smtp.host=your-smtp-server.com sonar.email.smtp.port=465 sonar.email.smtp.ssl=true sonar.email.smtp.auth=true sonar.email.smtp.username=your-full-email@domain.com sonar.email.smtp.password=your-password-or-app-specific-password
- Trust the SMTP certificate: If your server uses a self-signed or internal CA certificate, SonarQube’s JVM won’t trust it by default. Import the certificate into the JVM’s truststore:
The default cacerts password iskeytool -import -alias smtp-cert -file /path/to/your/cert.crt -keystore $JAVA_HOME/lib/security/cacertschangeit. Restart SonarQube after this step.
Fixes for STARTTLS (Port 587)
Your sonar.properties should look like this (note the different TLS setting):
sonar.email.smtp.host=your-smtp-server.com sonar.email.smtp.port=587 sonar.email.smtp.starttls.enable=true sonar.email.smtp.auth=true sonar.email.smtp.username=your-full-email@domain.com sonar.email.smtp.password=your-password-or-app-specific-password
- Relax TLS version restrictions: Some older SMTP servers use outdated TLS versions that SonarQube’s JVM rejects. Add this JVM argument to SonarQube’s startup script (e.g.,
sonar.shorsonar.bat):
If that doesn’t work, you can try disabling strict STARTTLS checks (use cautiously):-Dmail.smtp.ssl.protocols=TLSv1.2
Restart SonarQube after modifying the script.-Dmail.smtp.starttls.required=false
Provider-Specific Tips
- Gmail/Google Workspace: Use
smtp.gmail.comwith port 465 (SSL) or 587 (STARTTLS). Enable an app-specific password if 2FA is on (avoid "less secure app access" for security). - Microsoft 365/Outlook: Use
smtp.office365.comon port 587 with STARTTLS. Your username is your full email, and password is your account or app-specific password. - On-prem enterprise servers: Confirm with your mail admin that SMTP auth is allowed from the SonarQube server’s IP, and that the server supports TLS 1.2+ (the modern standard).
内容的提问来源于stack exchange,提问作者Raq

