# Why does SMTP return 535 Authentication failed?

> Fix "535 Authentication failed" from smtp.emailit.com. The SMTP password must be an active Emailit API key, not your account password.

This article helps when the Emailit SMTP relay rejects your login. Authentication is the first step of every SMTP session, so nothing is sent until it succeeds.

## Symptoms

- Your client logs `535 Authentication failed` right after the `AUTH` command.
- Frameworks show messages such as `Invalid login`, `Username and Password not accepted` or `Failed to authenticate on SMTP server`.
- Less often you see `454 Temporary authentication failure`. That one is a temporary server-side problem: retry after a short wait.

## Cause

Emailit SMTP accepts `AUTH PLAIN` and `AUTH LOGIN` and checks only the password. The password must be an **API key** that is still active in the workspace. Typical reasons it fails:

- **You used your dashboard password** instead of an API key.
- **The key was deleted** in the dashboard or through the API.
- **The key was regenerated.** Regenerating replaces the secret and the old value stops working immediately.
- **The value was copied with extra characters**, such as a trailing space, a line break or surrounding quotes in a `.env` file.
- **Your client only offers CRAM-MD5** or another mechanism. Emailit supports PLAIN and LOGIN only.

The username is not checked, but use `emailit` so your configuration matches the docs.

## Fix

1. **Check the server's verdict in Logs.** Open **Email API → Logs** and filter **Source** to **SMTP**. A failed `AUTH` with status `535` appears there when the key belonged to your workspace but has been deleted. If nothing appears, the password doesn't match any key at all.

2. **Create a fresh API key.** Go to **Email API → API Keys** and select **Add API key**. Choose **Full Access**, or **Sending Only** if the key is only for sending. Copy the key now: it's shown once. Only workspace admins can create keys. See [API keys](/docs/developers/api-keys/).

3. **Update your SMTP settings.** Use these values and nothing else:

```ini title=".env"
SMTP_HOST=smtp.emailit.com
SMTP_PORT=587
SMTP_USERNAME=emailit
SMTP_PASSWORD=secret_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
```

   Don't wrap the key in quotes unless your loader strips them, and remove trailing whitespace.

4. **Pick PLAIN or LOGIN.** If your client lets you choose the mechanism, set it to `PLAIN` or `LOGIN`, or leave it on automatic.

5. **Restart and send a test.** Many frameworks cache configuration, so restart the app or clear its config cache. A successful login returns `235`, and the accepted message returns `250 2.0.0 OK: queued as em_…`.

If authentication now works but the message is refused, see [Why does SMTP return 530 From domain not verified?](/docs/kb/smtp-530-from-domain-not-verified/). For every setting in one place, see [SMTP settings](/docs/smtp/settings/).

## Still stuck?

[Contact support](/contact/) or ask in [Discord](https://discord.emailit.com). Share the API key's name (never the key itself), the time of the failed attempt and the library you use.

---
Source: https://emailit.com/docs/kb/smtp-535-authentication-failed/
