530 5.7.0 Authentication required / Must issue a STARTTLS command first
The server will not go any further until the client does something it has not done yet. Two different demands share this code. "Authentication required" means the server only accepts mail from logged-in users and your client sent MAIL FROM without AUTH. "Must issue a STARTTLS command first" means the server requires encryption before it will accept AUTH or MAIL FROM, and the client tried in plaintext.
What the server replies
530 5.7.0 Must issue a STARTTLS command first. a1b2c3d4e5f6-sm.google.com
- Sent by
- Any mail server
- Type
- PermanentRetry fails
- About
- Authentication
- Enhanced code
- 5.7.0
Who sends it
Submission servers on port 587: Gmail (smtp.gmail.com), Microsoft 365 (smtp.office365.com), Postfix with smtpd_tls_auth_only or permit_sasl_authenticated. The STARTTLS form is Gmail's exact wording.
Why it happens
- The client's "use TLS" or "STARTTLS" option is off.
- The client has no username and password configured, or has them under a profile that is not in use.
- The client connected to port 587 expecting implicit TLS (which is port 465) and so never issued STARTTLS.
- A library defaults to plaintext and needs an explicit secure flag.
How to fix it
Match port and encryption
Port 587 means STARTTLS: connect in plaintext, then upgrade. Port 465 means TLS from the first byte. Set the client accordingly; getting this backwards produces 530 on 587 and a hang or garbage on 465.
Turn on authentication
Enter the username (usually the full email address) and password or app password and make sure the client sends AUTH after STARTTLS.
Verify with a connection test
An SMTP test against the host and port shows whether STARTTLS is offered and which AUTH methods appear after the upgrade.
Check it yourself
These free tools show the records and connections behind this code for your own domain or server.
Related codes
- 535 5.7.8 Authentication credentials invalid / Username and Password not acceptedThe server rejected the login.
- 550 5.7.1 Relay access denied / relaying deniedYou asked a mail server to deliver to a domain it does not host, and it refused because you are not an authorised client.
- 501 5.5.4 Invalid HELO/EHLO argument / syntax error in parametersThe server did not like the arguments your client sent with a command, most often the hostname in HELO or EHLO.
Sources
Fewer bounces to look up.
Faivelo sends from authenticated, warmed infrastructure, turns permanent bounces into one clean event for your application and keeps the address out of future sends.
Free tier included. No card needed.
Other free tools
All tools- Email DNS checkerCheck MX, SPF, DKIM, DMARC and reverse DNS for any domain and get the exact records to add or fix.
- DMARC checkerLook up a domain's DMARC record, read every tag in plain words and see what to tighten next.
- DMARC record generatorBuild a valid DMARC record from a few choices and copy the host and value into your DNS.
- DMARC report analyzerDrop in a DMARC aggregate report and see who is sending as your domain and whether they pass.
- SMTP connection testerConnect to any SMTP server, check TLS and the login step, and see each stage with its timing.
- Email header analyzerPaste raw headers to see every hop, where the delay was, and whether SPF, DKIM and DMARC passed.
- Email address validatorCheck whether an address is well formed, whether its domain accepts mail, and whether it is disposable or a role account.