5.7.12 Sender was not authenticated by organization
5.7.12 Sender was not authenticated by organization
The receiving organisation, not yours, refused the message because the sender was not authenticated to it. You cannot fix this from your own tenant settings, and trying to is where the time goes: the change has to happen at the destination, or the mail has to arrive by a route that organisation accepts.
Check it from the machine that is failing
npx zerosmtp-check --explain "5.7.12 Sender was not authenticated by organization"
No install and nothing sent. It reads the refusal your own client printed - which is rarely what the server said, because libraries and device panels rewrite it - and says which of these cases you are in.
If the send is hanging rather than being refused, the cause is usually the network and not the credentials. npx zerosmtp-check with no arguments checks ports 25, 587 and 465 from where you are standing.
Check this before assuming it is the Basic auth shutdown
This one is worth ruling out cheaply, because the fix is usually local:
- Does the device’s SMTP configuration have an authentication checkbox, and is it off?
- Was this device previously relaying anonymously through an internal server that has since been retired or repointed?
- Is it sending
AUTHafterMAIL FROM? Some older firmware does, and Microsoft 365 will not accept it.
If authentication is genuinely configured and still refused, you are looking at 535 5.7.139 instead.
Two things this is often confused with
| Symptom | Actual cause |
|---|---|
| Connection times out; no authentication error ever appears | The network is blocking outbound SMTP. Cloud providers block port 25 and often 587 by default — see troubleshooting. |
Certificate verify failed / unable to get local issuer certificate | The device’s trust store cannot validate the server certificate. Common on firmware predating current root CAs — see the Canon Maxify MB2755 case. |
Source: Microsoft’s own list of Exchange Online error codes. This entry was written from that documentation rather than from watching a machine fail, which is worth knowing when you compare it against what your hardware actually printed.
Related
- All SMTP AUTH error messages
- Which devices have OAuth firmware
- What breaks at the end of December 2026
Seeing a string that is not here? Report it with what produced it. Errors from real hardware are worth more than anything transcribed from documentation.
Last reviewed 2026-08-16.
Updated 22 Aug 2026