5.7.57 "Client not authenticated to send mail" appears when a device or application tries to relay through smtp.office365.com without authenticating in the way that endpoint requires. It is a submission-path problem, not a DNS problem.
Most common causes
- The application attempted anonymous relay against an authenticated submission endpoint
- Stored credentials are invalid, expired or no longer accepted
- The device or application is using a legacy submission configuration
- The chosen Microsoft 365 relay method does not match the network and identity setup
What to verify next
- Identify the exact endpoint, port and authentication method in use
- Inventory the application or device as an email dependency
- Separate client submission from connector-based relay before changing settings
- Test the replacement path with a controlled message before production use
Three relay methods, three sets of rules
Microsoft 365 supports SMTP client submission (authenticated, port 587), direct send (unauthenticated, only to your own tenant’s mailboxes), and SMTP relay through a connector (unauthenticated, restricted by source IP or certificate). Each has its own endpoint and constraints. 5.7.57 means the client is using the client-submission endpoint without valid authentication.
The most common triggers are basic authentication being disabled for the tenant or the mailbox, a changed or expired password on a device that stores it, or SMTP AUTH being turned off for the account.
Find the device and its configuration
The NDR rarely names the device. Match the timestamp against application and device logs, and inventory anything that sends through the tenant: scanners, monitoring systems, ticketing tools, ERP notifications. Email Dependency Discovery helps map these from relay logs.
For each, confirm the endpoint, port, encryption and authentication method it uses. Devices configured years ago frequently still assume basic authentication that no longer works.
- Client submission needs SMTP AUTH enabled and modern authentication or valid credentials.
- Direct send delivers only to your own mailboxes.
- Connector relay requires a matching source IP or certificate.
Choose the right path and test
If the device supports OAuth or a current credential, enable SMTP AUTH for that mailbox and update the credential. If it does not, move it to connector-based relay with its public IP registered, or to direct send if it only mails internal recipients.
Test each changed device with a single message before returning it to production, and record the configuration so the next password rotation does not repeat the outage.
Best diagnostic path
Mail Failure Doctor
Classify the complete rejection and preserve provider-specific diagnostic context.
Open analysis → Live analysisEmail Dependency Discovery
Map applications and devices that depend on a relay or submission path before changing it.
Open analysis → Live analysisEmail Infrastructure Digital Twin
Map the domain’s public mail infrastructure and provider relationships before remediation.
Open analysis →Known limits
- Microsoft continues to retire legacy authentication; a working configuration today may need revisiting.
- The NDR does not identify the device; correlation with logs is required.
Common questions
The password is correct. Why does it fail?
SMTP AUTH may be disabled for the mailbox or tenant, or basic authentication may be blocked. Check the mailbox’s SMTP AUTH setting.
Should I use a connector instead?
For devices that cannot authenticate, yes. Register their public IP on an inbound connector and point them at your tenant’s MX endpoint.
Does this affect user mailboxes?
No. It concerns applications and devices submitting mail; Outlook clients use a different path.
Why the exact message matters
The same status family can be triggered by different conditions, and providers frequently add diagnostic text that narrows the issue. Use the complete rejection text rather than treating the numeric code as a complete diagnosis.
Provider reference
For the provider-defined meaning and current requirements, review Microsoft Exchange Online NDR reference.