Blazalek.com

5.7.8SMTP 5.7.8: Authentication credentials invalid

Authentication failed because the credentials were invalid or insufficient. Do not retry the same unchanged attempt.

Category
Security, authentication and policy
Class
Permanent failure
Retry
Do not retry unchanged
Suppression
Check the full context

TL;DR

Permanent AUTH failure: credentials were invalid or insufficient. Supply new credentials or fix identity configuration before retrying. Not a recipient-address bounce; repeated auth failures can reflect on sender reputation. Do not retry with the same credentials.

What this code means

SMTP AUTH failed because the supplied credentials were invalid or insufficient for the attempted session; that is code 5.7.8 under pattern X.7.8. The enhanced status register treats this credential outcome as permanent for the current attempt. The standard places the detail in the security and authentication family, yet the numeric reply concerns client authentication, not recipient addressing, and by itself it does not identify which credential element failed or prove that the recipient address is invalid.

Provider examples

Yahoo / AOL example
535 5.7.8 Error: authentication failed: authentication failure

Technical meaning

As a response to the AUTH command, X.7.8 means authentication failed because the credentials were invalid or insufficient. Code 5.7.8 applies this detail in permanent class 5; the client should ask the user to supply new credentials afterward.

Delivery status

The leading digit 5 denotes a permanent failure of the current attempt. The code concerns client authentication, but by itself it does not identify which credentials were invalid or insufficient, and it does not establish that the recipient address is invalid.

Class
Permanent failure
Retry
Do not retry unchanged
Suppression
Check the full context

Retry decision

Operational guidance: stop automatic and manual retries with the same credentials. Consider a new AUTH attempt only after obtaining new credentials or confirming a correction to identity, authorization, or configuration; check suppression again before the attempt.

Suppression decision

Operational guidance: do not automatically suppress the recipient address or domain based on 5.7.8 alone. Inspect the complete response, authentication context, event history, and applicable policy, then make the suppression decision in that context.

Common causes

  • The credentials supplied in the AUTH attempt were invalid or insufficient.

Diagnostic steps

  1. Inspect the raw SMTP response and confirm that the enhanced code is exactly 5.7.8 and that the basic reply is in the 5xx class; retain the complete response without recording secrets.
  2. Correlate the response with the specific AUTH attempt, time, identity used, authentication mechanism, and system that returned the code; use safe logs to determine whether the credentials were invalid or insufficient.
  3. Stop unchanged retries; before a controlled new attempt, confirm new credentials or a material configuration correction and check suppression again.

Actions by owner

Sender

  • Do not retry with the same credentials; supply new credentials through an approved secure mechanism or give the administrator the complete context without exposing secrets.

Sender administrator

  • Stop unchanged retries, inspect the identity, AUTH mechanism, and credential source, then permit a new attempt only after a verified correction and another suppression check.

Recipient administrator

  • If you manage the authenticating system, inspect safe logs and the applicable authorization for the specified attempt, then correct only a confirmed server-side problem.

Provider

  • If you operate a service involved in the attempt, inspect its authentication logs and give the administrator safe context needed to distinguish invalid credentials from insufficient authorization.

Sources

These sources define what this enhanced status code means, mainly through the IANA registry and related RFCs. When provider examples appear on the page, they come from that provider's published documentation. Follow the links to read the original wording in context.

Last verified:

Found an error or inaccuracy? Report a correction.

Point out the part of this page that should be checked. Every report is reviewed manually.

Type of problem

Describe the issue and, if useful, suggest corrected wording.

For a factual report, include a public source when possible.

You can submit anonymously. A reply is not guaranteed.

Do not paste full bounce messages, headers, email addresses, Message-IDs, tokens, or other personal data. Redact evidence before sending.

Sending a correction shares the information you enter with Formspree so I can review and improve this page. Read the privacy notice.

Guide

  • Deliverability

    SPF/DKIM/DMARC and related auth policy are required for inbox delivery.

Incidents

Wojtek Blazalek

Email deliverability expert

Stuck on this error code? I help teams identify rejection causes and fix authentication and reputation, so email reaches the inbox.

Hands-on deliverability work for teams that send at scale.