Fix PHPMailer SMTP Error 535 Authentication Unsuccessful in Microsoft 365
Question details
The user needs to resolve an SMTP authentication failure when sending emails via PHPMailer through Microsoft 365.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Attempting to send an email using PHPMailer configured with smtp.office365.com.
- Observed behavior
- PHPMailer connects and completes STARTTLS but fails authentication with error 535 5.7.139 because the organization's security policy blocks the sign-in method.
Ensure you have administrative access to the Microsoft 365 tenant or can contact your IT administrator, as resolving this issue requires modifying server-side security policies and mailbox settings.
Verify Mailbox Settings and Administrator Policies
Check if authenticated SMTP is enabled for the specific mailbox and ensure Conditional Access policies allow the connection.
Microsoft 365 disables Basic Authentication by default for most tenants to improve security. If your PHPMailer script relies on a standard username and password, it will be blocked unless explicitly permitted by the administrator.
Verify that the Microsoft 365 account being used is active, the password is correct, and it is not locked.
Have your Microsoft 365 administrator log into the Microsoft 365 Admin Center, navigate to Active Users, select the specific user account, go to the Mail tab, click 'Manage email apps', and ensure that 'Authenticated SMTP' is checked.
Ask the administrator to check the Azure portal for Security Defaults or Conditional Access policies that might be blocking legacy authentication (Basic Authentication) for the account.

Upgrade to OAuth 2.0 or Microsoft Graph API
Use modern authentication methods supported by Microsoft 365 to bypass legacy basic authentication restrictions securely.
Verify SMTP Connection Settings
Ensure the basic connection parameters for Microsoft 365 SMTP are correctly configured in your script.
Looking for a Reliable Office Suite? Try WPS Office
While you are troubleshooting Microsoft 365 email integrations and server policies, if you need a lightweight, free, and highly compatible office suite for your daily document tasks, WPS Office is an excellent alternative. It seamlessly handles Microsoft Office formats without the heavy subscription fees or complex administrative configurations.

Frequently Asked Questions
Why am I getting error 535 5.7.139 in Microsoft 365?
This error occurs when your organization's security policies, such as Security Defaults or Conditional Access, block the legacy sign-in method (Basic Authentication) used by your application to send emails.
Can I use an App Password to bypass this SMTP error?
App passwords might work if Multi-Factor Authentication (MFA) is enforced but basic authentication is still permitted by the tenant. However, relying on app passwords is not recommended as Microsoft continues to phase out legacy authentication in favor of OAuth 2.0.
How do I know if Authenticated SMTP is disabled for my account?
Your Microsoft 365 administrator can check this in the Microsoft 365 Admin Center by selecting your user profile, navigating to the Mail tab, and checking the 'Manage email apps' section to see if Authenticated SMTP is checked.




