Steps to reproduce
- Configure an email account in Nextcloud Mail using Microsoft 365 / Exchange Online with XOAUTH2 authentication.
- Configure an outbound SMTP username that differs from the account email address.
- Try to send an email.
Mail uses the account email address for XOAUTH2 SMTP authentication instead of the configured outbound SMTP username.
Expected behavior
XOAUTH2 SMTP authentication should work when the configured outbound SMTP username differs from the account email address.
The configured outbound SMTP username should be taken into account when creating the XOAUTH2 authentication credentials.
Actual behavior
SMTP XOAUTH2 authentication fails when the configured outbound SMTP username differs from the account email address.
Mail 5.11.5 uses the account email address for XOAUTH2 authentication instead of the configured outbound SMTP username.
Using the configured outbound username as a local workaround makes SMTP sending work correctly.
Mail app version
5.11.5
Nextcloud version
34.0.4
Mailserver or service
Microsoft 365 / Exchange Online
Operating system
Ubuntu 26.04.1 LTS
PHP engine version
Other
Nextcloud memory caching
Redis 8
Web server
Apache (supported)
Database
PostgreSQL
Additional info
PHP version: 8.5.10
The issue is reproducible with the unmodified Mail 5.11.5 code.
Official Mail 5.11.5 contains:
$params['xoauth2_token'] = new Horde_Smtp_Password_Xoauth2(
$account->getEmail(),
$decryptedAccessToken,
);
As a local workaround, changing $account->getEmail() to $mailAccount->getOutboundUser() makes XOAUTH2 SMTP sending work correctly in this environment.
I am reporting this as an observed workaround rather than assuming that this is necessarily the correct upstream implementation.
Steps to reproduce
Mail uses the account email address for XOAUTH2 SMTP authentication instead of the configured outbound SMTP username.
Expected behavior
XOAUTH2 SMTP authentication should work when the configured outbound SMTP username differs from the account email address.
The configured outbound SMTP username should be taken into account when creating the XOAUTH2 authentication credentials.
Actual behavior
SMTP XOAUTH2 authentication fails when the configured outbound SMTP username differs from the account email address.
Mail 5.11.5 uses the account email address for XOAUTH2 authentication instead of the configured outbound SMTP username.
Using the configured outbound username as a local workaround makes SMTP sending work correctly.
Mail app version
5.11.5
Nextcloud version
34.0.4
Mailserver or service
Microsoft 365 / Exchange Online
Operating system
Ubuntu 26.04.1 LTS
PHP engine version
Other
Nextcloud memory caching
Redis 8
Web server
Apache (supported)
Database
PostgreSQL
Additional info
PHP version: 8.5.10
The issue is reproducible with the unmodified Mail 5.11.5 code.
Official Mail 5.11.5 contains:
As a local workaround, changing
$account->getEmail()to$mailAccount->getOutboundUser()makes XOAUTH2 SMTP sending work correctly in this environment.I am reporting this as an observed workaround rather than assuming that this is necessarily the correct upstream implementation.