Canon Maxify MB2755: OAuth 2.0 and Microsoft 365 SMTP AUTH

Status: No OAuth for this purpose

There is no OAuth option for this purpose at all, on any firmware version. The settings screen accepts a username and a password and nothing else, so the only thing that can change is what those credentials point at.

What the vendor says

Separate failure mode from OAuth: the firmware ships a fixed root CA store predating current Let’s Encrypt roots, so certificate validation fails regardless of authentication. Hardware-confirmed, unchanged after a firmware update. Verification has to be disabled on the device.

Read the vendor’s statement in full
Everything on this page comes from that document. If it and this page disagree, the vendor is right and this page is out of date — say so.

Models named in the advisory

  • Maxify MB2755

A model missing from this list is not automatically safe. Vendors publish headline lists; regional variants and OEM rebadges drift away from them.

What to do instead

Once firmware is ruled out, three options remain, and they differ more than they look:

  • Direct Send — free, but only delivers to recipients inside your own tenant, and needs a connector plus a static IP.
  • A relay that still accepts a username and password — works for any recipient, and is three fields on the device rather than a project.
  • Replace the device — sometimes the honest answer. A 2016 MFP with no OAuth path and no security updates is a hardware decision, not a mail one.

The migration guide walks through all of them, including Graph API and paid relays, and the quiz on that page gives a recommendation you can link to.

ZeroSMTP is the second option. It is free with no paid tier, accepts plain SMTP AUTH, and is capped at 200 messages a day — and it sends from a shared @msgwing.com address, not your own domain. If the from-address has to be yours, it is the wrong answer and the migration guide covers the others.

Create a free account · what to put in the device’s SMTP fields · the code examples

Last reviewed 2026-08-16. Source: data/devices.json.

Updated 16 Aug 2026

mx.msgwing.com587 STARTTLS · 465 SSL/TLS Register free