Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsA scanner that suddenly stops sending email usually has one of four problems: the SMTP settings are wrong, the mailbox cannot authenticate, the network or TLS connection fails, or the selected sending method does not match the recipient. Work through these checks in order rather than changing the port at random.
1. Correct the SMTP server, port, and encryption settings
Open the scanner’s web administration page or control-panel settings. Common menu names include Network, Email, Scan to Email, SMTP, or Administrator Settings. Check the values against the provider you use.
| Service and method | SMTP server | Port | Security | Authentication |
|---|---|---|---|---|
| Microsoft 365 SMTP AUTH client submission | smtp.office365.com | 587 recommended; 25 also supported | TLS/STARTTLS enabled | Required; use the full mailbox address and password |
| Microsoft 365 Direct Send | Your organization’s MX hostname ending in mail.protection.outlook.com | 25 | Configured according to the device and tenant setup | None |
| Microsoft 365 SMTP relay | Your organization’s MX hostname ending in mail.protection.outlook.com | 25 | Configured with a Microsoft 365 connector | Connector/IP-based setup |
| Gmail or Google Workspace | smtp.gmail.com | Use the port specified by the device for SSL/TLS | SSL/TLS enabled | Account authentication is required |
For Microsoft 365 SMTP AUTH, enter the complete address as the username, such as scanner@contoso.com. Do not leave the username and password blank. The error Client was not authenticated to send anonymous mail during MAIL FROM means the scanner is attempting to use smtp.office365.com without credentials.
Do not substitute an IP address for a Microsoft 365 MX hostname. Microsoft can change the endpoint’s IP address, which can make an IP-based configuration fail later.
#1 Best Overall
- PORTABLE SCANNER FOR USE ON-THE-GO — The fastest and lightest mobile single-sheet-fed compact document scanner in its class¹
- QUICK DOCUMENT SCANNING ― This Epson ultra-fast scanner scans a single page as quickly as 5.5 seconds²; Windows and Mac compatible
- VERSATILE PAPER HANDLING ― Portable scanner scans documents up to 8.5 x 72 in; Also easily digitizes receipts and ID cards to make accounting, bookkeeping, and organizing simpler
- INTUITIVE, HIGH-SPEED SOFTWARE — Epson ScanSmart Software³ is a smart tool allowing you to easily scan, review, and save; Stay organized easily with the help of this Epson scanner
- EASY SETUP — USB-powered connect to your computer for quick and simple scanning; No batteries or external power supply required to operate portable document scanner; Standard Connectivity: USB 2.0
Also check the device’s terminology. STARTTLS is not always labelled simply “TLS,” and “SSL” may refer to implicit TLS rather than STARTTLS. Select the mode supported by the scanner and the SMTP service, then save the settings and reboot the device if its firmware requires it.
2. Verify the mailbox and From address
First, sign in to Outlook on the web with the mailbox credentials and send a normal test message. If the account is blocked, restricted, locked, or the password has expired, the scanner will not work with those credentials either.
For Microsoft 365, SMTP AUTH must be allowed by the tenant configuration and, where applicable, for the individual mailbox. An administrator can check whether SMTP AUTH is restricted for the mailbox and enable it only if organizational policy permits. Security policy may intentionally disable SMTP AUTH, so do not change this setting without checking with the Microsoft 365 administrator.
Next, compare the scanner’s From address with the account used to log in. For example, if the scanner authenticates as sales@contoso.com but sends as salesperson1@contoso.com, Microsoft 365 may return an error similar to 5.7.60 SMTP; Client does not have permissions to send as this sender.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Rank #2
- FAST SPEEDS - Scans color and black and white documents a blazing speed up to 16ppm (1). Color scanning won’t slow you down as the color scan speed is the same as the black and white scan speed.
- ULTRA COMPACT – At less than 1 foot in length and only about 1. 5lbs in weight you can fit this device virtually anywhere (a bag, a purse, even a pocket).
- READY WHENEVER YOU ARE – The DS-640 mobile scanner is powered via an included micro USB 3. 0 cable allowing you to use it even where there is no outlet available. Plug it into you PC or laptop and you are ready to scan.
- WORKS YOUR WAY – Use the Brother free iPrint&Scan desktop app for scanning to multiple “Scan-to” destinations like PC, Network, cloud services, Email and OCR. (2) Supports Windows, Mac and Linux and TWAIN/WIA for PC/ICA for Mac/SANE drivers. (3)
- OPTIMIZE IMAGES AND TEXT – Automatic color detection/adjustment, image rotation (PC only), bleed through prevention/background removal, text enhancement, color drop to enhance scans. Software suite includes document management and OCR software. (4)
The simplest fix is to make both addresses the same. If an alternate From address is required, the authenticated mailbox needs Send As permission for it. An administrator can instead use Microsoft 365 SMTP relay, provided the connector and static public IP requirements are met.
For Google Workspace, direct authentication from a printer can fail when 2-Step Verification is enabled. Check the organization’s current Google SMTP guidance and the scanner’s supported authentication options; do not rely on old “allow less secure apps” instructions.
3. Test the network connection and TLS support
Test from a computer on the same network as the scanner. This separates a network problem from a scanner configuration problem. On Windows, open Command Prompt, type telnet, and then run:
open smtp.office365.com 587
Use 25 instead if that is the port configured on the scanner. A working connection returns an SMTP response beginning with 220 and identifying the Microsoft ESMTP service.
Rank #3
- FAST DOCUMENT SCANNING — Document scanner with feeder allows you to speed through stacks with a 50-sheet Auto Document Feeder (ADF); Efficient office scanner to help you scan more productively
- INTUITIVE, HIGH-SPEED SOFTWARE — Quickly scan with this desktop document scanner; Epson ScanSmart Software lets you easily preview scans, email files, upload to the cloud, and more; Plus, automatic file naming saves even more time
- SEAMLESS INTEGRATION — Easily incorporate your data into most document management software with the included TWAIN driver; Office document scanner integrates seamlessly with business workflows
- EASY SHARING — Duplex scanner allows you to scan straight to email or popular cloud storage2 services like Dropbox, Evernote, Google Drive, and OneDrive for simple storage and sharing
- SIMPLE FILE MANAGEMENT — Scanner allows the creation of searchable PDFs with Optical Character Recognition (OCR) and convert scans to editable Word or Excel files effortlessly; Designed for home and office document scanning
If the connection times out or is refused, check the following:
- The scanner’s gateway and DNS server are correct.
- The local firewall allows outbound TCP 587 or TCP 25.
- The router, corporate firewall, or ISP is not blocking SMTP traffic.
- The scanner can resolve smtp.office365.com.
A failed connection at this stage is not caused by the scanned document, address book, or PDF settings.
Microsoft 365 SMTP AUTH requires TLS 1.2 or later. An older scanner may have worked previously but stopped after its service began rejecting TLS 1.0 or TLS 1.1 connections. Check the manufacturer’s firmware notes and update the device if possible.
For a device that cannot support TLS 1.2, Microsoft documents a legacy compatibility route: an administrator must opt in to legacy TLS clients using the AllowLegacyTLSClients setting or, in the Exchange admin center, Settings > Mail Flow, under Security, select Turn on use of legacy TLS clients, and then configure the device to use smtp-legacy.office365.com. This is an exception for obsolete hardware, not the preferred configuration.
Rank #4
- Scanner type: Document
- Connectivity technology: USB
- With Auto Scan Mode, the scanner automatically detects what you're scanning
- Digitize documents and images
Finally, check the scanner’s date, time, and time zone. A badly incorrect clock can make the server certificate appear invalid and cause TLS negotiation to fail. Enable NTP if the device supports it.
4. Choose the right Microsoft 365 sending method
Some scanners have no username or password fields. That limitation determines which Microsoft 365 method you can use.
- Use SMTP AUTH client submission when the scanner can securely store mailbox credentials. Configure smtp.office365.com, port 587, STARTTLS, and an authenticated mailbox. This supports both internal and external recipients.
- Use Direct Send when the scanner only needs to send to Microsoft 365 recipients inside your organization. Configure the organization’s MX endpoint ending in mail.protection.outlook.com, port 25, with no authentication. Direct Send is not intended for sending to external internet addresses.
- Use SMTP relay when the device cannot authenticate or must send to internal and external recipients. This requires a Microsoft 365 connector and a publicly visible static IP address for the device or the host relaying its mail. The sending IP may also be blocked by an outbound-spam list.
To find the organization’s MX endpoint, query the domain’s MX records or ask the Microsoft 365 administrator. Do not use smtp.office365.com for Direct Send or relay.
If Direct Send messages reach internal users but external recipients fail, that is expected behavior rather than proof that the scanner is broken. If messages arrive in junk mail, check SPF authorization for the scanner’s static public IP. A changed ISP or public IP requires the SPF record to be updated.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Best Value
- OUR MOST ADVANCED SCANSNAP. Large touchscreen, fast 45ppm double-sided scanning, 100-sheet document feeder, Wi-Fi and USB connectivity, automatic optimizations, and support for cloud services. Upgraded replacement for the discontinued iX1600
- CUSTOMIZABLE. SHARABLE. Select personalized profiles from the touchscreen. Send to PC, Mac, mobile devices, and clouds. QUICK MENU lets you quickly scan-drag-drop to your favorite computer apps
- STABLE WIRELESS OR USB CONNECTION. Built-in Wi-Fi 6 for the fastest and most secure scanning. Connect to smart devices or cloud services without a computer. USB-C connection also available
- PHOTO AND DOCUMENT ORGANIZATION MADE EFFORTLESS. Easily manage, edit, and use scanned data from documents, receipts, photos, and business cards. Automatically optimize, name, and sort files
- AVOIDS PAPER JAMS AND DAMAGE. Features a brake roller system to feed paper smoothly, a multi-feed sensor that detects pages stuck together, and skew detection to prevent paper damage and data loss
Quick diagnosis by symptom
| Symptom or error | Most likely cause | Action |
|---|---|---|
| No connection or timeout | Firewall, ISP, DNS, gateway, or wrong port | Test TCP 587 or 25 from the same network |
| Anonymous-send error during MAIL FROM | Credentials missing while using smtp.office365.com | Add mailbox credentials or switch to Direct Send/relay |
| 5.7.60 sender-permission error | From address differs from authenticated mailbox | Match the addresses or grant Send As permission |
| TLS or certificate error | Old TLS version or incorrect device clock | Update firmware, enable TLS 1.2+, and correct date/time |
| Internal mail works; external mail fails | Direct Send was selected | Use SMTP AUTH or correctly configured SMTP relay |
When to contact the administrator or manufacturer
Escalate the issue when the scanner can connect but Microsoft 365 rejects authentication, SMTP AUTH is disabled by organizational policy, a connector is required, or the device cannot support TLS 1.2. Give the administrator the exact SMTP error, timestamp, sending address, recipient domain, firmware version, and the SMTP method selected. Those details are more useful than simply reporting that “scan to email does not work.”
For reference, Microsoft’s troubleshooting documentation covers printer and scanner SMTP AUTH, Direct Send, and relay configuration, while Google documents SMTP access for Gmail and Google Workspace.
- Microsoft: fix issues with printers, scanners, and line-of-business applications using Microsoft 365
- Microsoft: configure a multifunction device or application for SMTP relay
- Google Workspace SMTP relay and SMTP service documentation
FAQ
What SMTP server should I use for Microsoft 365 scan to email?
For authenticated SMTP AUTH client submission, use smtp.office365.com on port 587 with STARTTLS, a full Microsoft 365 mailbox address, and its password. Direct Send and SMTP relay use the organization’s MX endpoint ending in mail.protection.outlook.com on port 25.
Can I use Microsoft 365 SMTP without a username and password?
Not with smtp.office365.com. A no-credential configuration requires Microsoft 365 Direct Send or SMTP relay, each with different recipient, connector, and network requirements.
Free tools Windows power users keep installed
One-click scans. No signup required.
Why does the scanner send to coworkers but not external addresses?
It is probably using Microsoft 365 Direct Send, which is limited to recipients in the same organization. Use authenticated SMTP AUTH or configure SMTP relay for external delivery.
Why does changing the SMTP port not fix the scanner?
Port selection is only one part of delivery. Authentication, SMTP AUTH policy, the From address, Send As permission, firewall access, TLS version, device time, and recipient restrictions can all independently cause failure.
The Bottom Line
For most current Microsoft 365 scanners, start with smtp.office365.com, port 587, STARTTLS, and a dedicated mailbox whose From address matches its login. If the device cannot authenticate, use Direct Send only for internal recipients or configure SMTP relay with the required connector and static IP. Then verify port access, TLS 1.2 support, and the scanner’s clock before troubleshooting documents or address books.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

