Troubleshooting
Why does SMTP return 535 Authentication failed?
Fix "535 Authentication failed" from smtp.emailit.com. The SMTP password must be an active Emailit API key, not your account password.
This article helps when the Emailit SMTP relay rejects your login. Authentication is the first step of every SMTP session, so nothing is sent until it succeeds.
Symptoms
- Your client logs
535 Authentication failedright after theAUTHcommand. - Frameworks show messages such as
Invalid login,Username and Password not acceptedorFailed to authenticate on SMTP server. - Less often you see
454 Temporary authentication failure. That one is a temporary server-side problem: retry after a short wait.
Cause
Emailit SMTP accepts AUTH PLAIN and AUTH LOGIN and checks only the password. The password must be an API key that is still active in the workspace. Typical reasons it fails:
- You used your dashboard password instead of an API key.
- The key was deleted in the dashboard or through the API.
- The key was regenerated. Regenerating replaces the secret and the old value stops working immediately.
- The value was copied with extra characters, such as a trailing space, a line break or surrounding quotes in a
.envfile. - Your client only offers CRAM-MD5 or another mechanism. Emailit supports PLAIN and LOGIN only.
The username is not checked, but use emailit so your configuration matches the docs.
Fix
-
Check the server’s verdict in Logs. Open Email APILogs and filter Source to SMTP. A failed
AUTHwith status535appears there when the key belonged to your workspace but has been deleted. If nothing appears, the password doesn’t match any key at all. -
Create a fresh API key. Go to Email APIAPI Keys and select Add API key. Choose Full Access, or Sending Only if the key is only for sending. Copy the key now: it’s shown once. Only workspace admins can create keys. See API keys.
-
Update your SMTP settings. Use these values and nothing else:
SMTP_HOST=smtp.emailit.com SMTP_PORT=587 SMTP_USERNAME=emailit SMTP_PASSWORD=secret_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxDon’t wrap the key in quotes unless your loader strips them, and remove trailing whitespace.
-
Pick PLAIN or LOGIN. If your client lets you choose the mechanism, set it to
PLAINorLOGIN, or leave it on automatic. -
Restart and send a test. Many frameworks cache configuration, so restart the app or clear its config cache. A successful login returns
235, and the accepted message returns250 2.0.0 OK: queued as em_….
If authentication now works but the message is refused, see Why does SMTP return 530 From domain not verified?. For every setting in one place, see SMTP settings.
Still stuck?
Contact support or ask in Discord. Share the API key’s name (never the key itself), the time of the failed attempt and the library you use.