exchange-online error

Exchange Online 550 5.7.57 — Client Not Authenticated During MAIL FROM

Microsoft 365 rejected relay through smtp.office365.com because the application or device was not authenticated in the way the submission path requires.

5.7.57 "Client not authenticated to send mail" appears when a device or application tries to relay through smtp.office365.com without authenticating in the way that endpoint requires. It is a submission-path problem, not a DNS problem.

Reviewed 2026-09-02. Provider wording and requirements change; the provider reference below is authoritative.

Most common causes

  • The application attempted anonymous relay against an authenticated submission endpoint
  • Stored credentials are invalid, expired or no longer accepted
  • The device or application is using a legacy submission configuration
  • The chosen Microsoft 365 relay method does not match the network and identity setup

What to verify next

  1. Identify the exact endpoint, port and authentication method in use
  2. Inventory the application or device as an email dependency
  3. Separate client submission from connector-based relay before changing settings
  4. Test the replacement path with a controlled message before production use

Three relay methods, three sets of rules

Microsoft 365 supports SMTP client submission (authenticated, port 587), direct send (unauthenticated, only to your own tenant’s mailboxes), and SMTP relay through a connector (unauthenticated, restricted by source IP or certificate). Each has its own endpoint and constraints. 5.7.57 means the client is using the client-submission endpoint without valid authentication.

The most common triggers are basic authentication being disabled for the tenant or the mailbox, a changed or expired password on a device that stores it, or SMTP AUTH being turned off for the account.

Find the device and its configuration

The NDR rarely names the device. Match the timestamp against application and device logs, and inventory anything that sends through the tenant: scanners, monitoring systems, ticketing tools, ERP notifications. Email Dependency Discovery helps map these from relay logs.

For each, confirm the endpoint, port, encryption and authentication method it uses. Devices configured years ago frequently still assume basic authentication that no longer works.

  • Client submission needs SMTP AUTH enabled and modern authentication or valid credentials.
  • Direct send delivers only to your own mailboxes.
  • Connector relay requires a matching source IP or certificate.

Choose the right path and test

If the device supports OAuth or a current credential, enable SMTP AUTH for that mailbox and update the credential. If it does not, move it to connector-based relay with its public IP registered, or to direct send if it only mails internal recipients.

Test each changed device with a single message before returning it to production, and record the configuration so the next password rotation does not repeat the outage.

Best diagnostic path

Known limits

  • Microsoft continues to retire legacy authentication; a working configuration today may need revisiting.
  • The NDR does not identify the device; correlation with logs is required.

Common questions

The password is correct. Why does it fail?

SMTP AUTH may be disabled for the mailbox or tenant, or basic authentication may be blocked. Check the mailbox’s SMTP AUTH setting.

Should I use a connector instead?

For devices that cannot authenticate, yes. Register their public IP on an inbound connector and point them at your tenant’s MX endpoint.

Does this affect user mailboxes?

No. It concerns applications and devices submitting mail; Outlook clients use a different path.

Why the exact message matters

The same status family can be triggered by different conditions, and providers frequently add diagnostic text that narrows the issue. Use the complete rejection text rather than treating the numeric code as a complete diagnosis.

Provider reference

For the provider-defined meaning and current requirements, review Microsoft Exchange Online NDR reference.