530 5.7.0 Authentication required / Must issue a STARTTLS command first

The server will not go any further until the client does something it has not done yet. Two different demands share this code. "Authentication required" means the server only accepts mail from logged-in users and your client sent MAIL FROM without AUTH. "Must issue a STARTTLS command first" means the server requires encryption before it will accept AUTH or MAIL FROM, and the client tried in plaintext.

What the server replies

530 5.7.0 Must issue a STARTTLS command first. a1b2c3d4e5f6-sm.google.com

Sent by
Any mail server
Type
PermanentRetry fails
About
Authentication
Enhanced code
5.7.0

Who sends it

Submission servers on port 587: Gmail (smtp.gmail.com), Microsoft 365 (smtp.office365.com), Postfix with smtpd_tls_auth_only or permit_sasl_authenticated. The STARTTLS form is Gmail's exact wording.

Why it happens

  • The client's "use TLS" or "STARTTLS" option is off.
  • The client has no username and password configured, or has them under a profile that is not in use.
  • The client connected to port 587 expecting implicit TLS (which is port 465) and so never issued STARTTLS.
  • A library defaults to plaintext and needs an explicit secure flag.

How to fix it

  1. Match port and encryption

    Port 587 means STARTTLS: connect in plaintext, then upgrade. Port 465 means TLS from the first byte. Set the client accordingly; getting this backwards produces 530 on 587 and a hang or garbage on 465.

  2. Turn on authentication

    Enter the username (usually the full email address) and password or app password and make sure the client sends AUTH after STARTTLS.

  3. Verify with a connection test

    An SMTP test against the host and port shows whether STARTTLS is offered and which AUTH methods appear after the upgrade.

Check it yourself

These free tools show the records and connections behind this code for your own domain or server.

Related codes

Sources

Fewer bounces to look up.

Faivelo sends from authenticated, warmed infrastructure, turns permanent bounces into one clean event for your application and keeps the address out of future sends.

Send with Faivelo

Free tier included. No card needed.