Authelia email and the Microsoft 365 Basic auth shutdown
Authelia is an authentication and two-factor portal sitting in front of everything else somebody self-hosts. It sends:
- identity-verification mail when a user registers a second factor
- password-reset mail
None of that is noisy, and none of it is noticed when it stops. Mail that is never sent leaves no error on any screen anybody looks at.
What changes at the end of December 2026
If these messages go out through Microsoft 365 with a username and a password, Exchange Online stops accepting that by default. Not throttles — refuses. An administrator can switch it back on, which buys time rather than solving it: Microsoft announces the final removal date in the second half of 2027, and tenants created after December 2026 do not get the option at all.
Which of the four you are looking at is decided by the exact string the server sends back.
Why this application fits a free relay
Authelia mails a person once, at the moment they set up or recover access. The volume is tiny and the stakes are not: if this mail cannot leave, nobody can enrol a second factor or recover an account.
That is the honest test, and it is worth applying before the settings: mail leaves from a generated @msgwing.com address rather than your own domain, and the cap is 200 messages a day. For an invoice or a shop receipt that is disqualifying. For Authelia it usually is not.
Settings
The notifier.smtp section of configuration.yml.
| Setting | Value |
|---|---|
address | submission://mx.msgwing.com:587 |
username | your @msgwing.com login |
password | your @msgwing.com password |
sender | your @msgwing.com login |
Register at msgwing.com first — the login and password are generated and shown once.
The part worth reading twice
Authelia’s address is a URI with a scheme, not a bare hostname. submission:// means STARTTLS on 587 and submissions:// means implicit TLS on 465 - one letter apart, and getting it wrong produces a connection error rather than an authentication one, which sends people looking in the wrong place.
Where these names come from
Every field above was read off SMTP notifier, Authelia’s own documentation, rather than recalled. If that page and this one disagree, that page is right and this one is out of date — say so.
Related
- Other self-hosted applications
- Connection values and every other application
- All SMTP AUTH error messages
- Tools that are a better fit than this one
Last reviewed 2026-08-29.
Updated 29 Aug 2026