How to Fix PHPMailer SMTP Error 535 5.7.139 for Outlook and Hotmail
Question details
The user needs to successfully send emails using PHPMailer with a Hotmail or Outlook account after Microsoft disabled basic authentication.
- Product
- PHPMailer / Microsoft 365
- Device & OS
- not provided
- Scenario
- Sending emails via a web application or script using PHPMailer connected to an Outlook or Hotmail SMTP server.
- Observed behavior
- PHPMailer fails to connect and returns SMTP error 535 5.7.139 because basic authentication has been disabled by Microsoft.
Verify that you have admin access to your Microsoft 365 tenant and ensure your PHPMailer library is updated to version 6.0 or higher to properly support OAuth 2.0 authentication.
Configure PHPMailer to Use OAuth 2.0 Authentication
The most secure and recommended method for connecting PHPMailer to Microsoft 365 after basic authentication is disabled.
Since Microsoft deprecated basic authentication for Exchange Online, legacy username and password combinations will no longer work. You must transition your application to use modern authentication (OAuth 2.0).
Log in to the Microsoft Entra admin center (formerly Azure AD), navigate to App registrations, and create a new application for your PHP script.
Grant your newly registered application the necessary delegated permissions for Microsoft Graph or Office 365 Exchange Online, specifically enabling SMTP.Send.
Create a new client secret under the 'Certificates & secrets' tab. Copy and save the secret value securely, as it will be hidden once you leave the page.
Modify your PHPMailer script to utilize the OAuthToken provider class. Input your registered Client ID, Client Secret, and Tenant ID to authenticate the SMTP connection.
Utilize a Third-Party SMTP Relay Service
Ideal for applications where implementing OAuth 2.0 is too complex or not feasible for your server environment.
Enable Authenticated SMTP via Microsoft 365 Admin Center
A temporary or legacy workaround if your tenant still supports enabling basic SMTP Auth for specific mailboxes.
Looking for a Lightweight Alternative to Microsoft Office?
While you manage your server-side email configurations and adapt to Microsoft's evolving authentication policies, consider streamlining your everyday documentation workflow. WPS Office provides a free, highly compatible, and lightweight alternative to Microsoft Office, ensuring seamless document management without expensive subscription fees.
- 1. Download the Installer: Visit the official WPS Office website and download the free installation package for your operating system.
- 2. Install WPS Office: Run the installer and follow the on-screen prompts to set up the suite on your device in just a few minutes.
- 3. Open Your Documents: Launch WPS Office and instantly open your existing Microsoft Office files without losing any formatting or data.

Frequently Asked Questions
What does SMTP error 535 5.7.139 mean?
This error indicates that the Microsoft email server rejected the connection because SMTP basic authentication (using only a username and password) is disabled for the account or tenant. Microsoft has deprecated this legacy method to enforce tighter security through modern authentication like OAuth 2.0.
Can I still use basic authentication with Outlook in PHPMailer?
Generally, no. Microsoft has permanently disabled basic authentication across most Exchange Online tenants. You must either configure OAuth 2.0, switch to a dedicated SMTP relay service, or re-enable Authenticated SMTP for specific mailboxes if your admin policies temporarily permit it.
How do I get the Client ID and Secret for PHPMailer OAuth 2.0?
You must register your web application in the Microsoft Entra admin center (Azure AD). After registering the app and granting it the necessary Exchange API permissions, you can generate a Client Secret under the 'Certificates & secrets' menu.
Which PHPMailer version is required for OAuth 2.0 support?
You should use PHPMailer version 6.0 or higher. Recent versions include built-in support for OAuth 2.0 via the OAuthToken provider class, enabling secure API connections to Microsoft 365, Google Workspace, and other modern email providers.




