Vaultwarden email and the Microsoft 365 Basic auth shutdown
Vaultwarden is a self-hosted server for the Bitwarden clients, run by one person for a family, a team or themselves. It sends:
- invitations to new users, valid for five days
- verification, password-hint and two-factor mail, when those features are on
None of that is noisy, and none of it is noticed when it stops. Mail that is never sent leaves no error on any screen anybody looks at.
What changes at the end of December 2026
If these messages go out through Microsoft 365 with a username and a password, Exchange Online stops accepting that by default. Not throttles — refuses. An administrator can switch it back on, which buys time rather than solving it: Microsoft announces the final removal date in the second half of 2027, and tenants created after December 2026 do not get the option at all.
Which of the four you are looking at is decided by the exact string the server sends back.
Why this application fits a free relay
An invitation is sent once per person, ever. A password vault that stops sending invitations has no other way to add anybody, and the volume never approaches a daily cap.
That is the honest test, and it is worth applying before the settings: mail leaves from a generated @msgwing.com address rather than your own domain, and the cap is 200 messages a day. For an invoice or a shop receipt that is disqualifying. For Vaultwarden it usually is not.
Settings
Environment variables, usually in the docker-compose.yml or .env beside it.
| Setting | Value |
|---|---|
SMTP_HOST | mx.msgwing.com |
SMTP_PORT | 587 |
SMTP_SECURITY | starttls |
SMTP_FROM | your @msgwing.com login |
SMTP_USERNAME | your @msgwing.com login |
SMTP_PASSWORD | your @msgwing.com password |
Register at msgwing.com first — the login and password are generated and shown once.
The part worth reading twice
SMTP_FROM has to be the generated address, not your own domain. Vaultwarden will start with a mismatched one and the mail will be refused or filed as spam, which looks like Vaultwarden failing.
Where these names come from
Every field above was read off SMTP configuration, Vaultwarden’s own documentation, rather than recalled. If that page and this one disagree, that page is right and this one is out of date — say so.
Related
- Other self-hosted applications
- Connection values and every other application
- All SMTP AUTH error messages
- Tools that are a better fit than this one
Last reviewed 2026-08-29.
Updated 29 Aug 2026