535 5.7.8 Authentication credentials invalid
Sample bounce line
535 5.7.8 Authentication credentials invalid
What it means
RFC 4954 section 6 defines this AUTH reply: 'This response to the AUTH command indicates that the authentication failed due to invalid or insufficient authentication credentials.' It is a permanent failure of the AUTH command, so the client should not just repeat the same credentials.
Why it happens
- Wrong username or password, or an account that is disabled or unknown to the authentication backend
- Insufficient credentials, for example the wrong login name format (full address versus short name) or an unsupported mechanism setup
- Server-side authenticator misconfiguration, such as the Exim PLAIN authenticator missing 'server_prompts = :' for clients that send PLAIN without initial data (Exim FAQ Q0723)
How to fix it
- Re-enter the username and password and check the login name format
- Admin: check the server logs; Dovecot's auth_debug=yes logs a debug line for almost everything related to authentication
- Postfix with Dovecot SASL: confirm smtpd_sasl_type = dovecot, smtpd_sasl_path = private/auth and smtpd_sasl_auth_enable = yes
- Exim: for clients that fail PLAIN with '535 Incorrect authentication data', add server_prompts = : to the PLAIN authenticator (Exim FAQ)
Check your domain now
Many of these errors come from missing or broken SPF, DKIM, DMARC or reverse DNS records. Enter your domain to run the free check.
Related errors
No related errors listed yet.