• Resolved Hola12345

    (@mridul12345)


    Hi

    Even though my authentication to Outlook worked fine, I am getting this error

    Connection needs attention: admi*****ls.com (outlook)
    Could not renew the Microsoft access token: Authorization Server rejected the request: AADSTS900144: The request body must contain the following parameter: ‘refresh_token’. Trace ID: db4d7e40-7a78-48c9-9c2a-8……….. Correlation ID: 3dd05363-1f7c-4e4a……….. Timestamp: 2026-09-15 23:47:30Z. Please reconnect this Outlook connection in FluentSMTP settings.

    Please help.

Viewing 5 replies - 1 through 5 (of 5 total)
  • Thread Starter Hola12345

    (@mridul12345)

    I’ll appreciate your response ASAP since my website email stopped functioning. Thank you!

    Plugin Support Ariful Islam

    (@arifulislam1)

    Hi @mridul12345 ,

    Apologies for the delayed reply here. Thanks for sharing the error details.

    This means the Outlook connection no longer has a usable Microsoft refresh token saved on your site, so FluentSMTP cannot renew the access token. Microsoft requires a refresh_token when renewing Outlook/Microsoft 365 OAuth access, and if that token is missing, expired, or revoked, the connection must be authenticated again.

    Please try this:

    1. Update FluentSMTP to the latest version.
    2. Go to WP Admin → Settings → FluentSMTP → Settings/Connections.
    3. Edit the Outlook / Office 365 connection.
    4. Click Authenticate with Office365 again.
    5. Complete the Microsoft login/consent flow.
    6. Copy the returned code back into FluentSMTP, save the connection, then send a test email.

    If the same error returns after reconnecting, please confirm:

    • Your FluentSMTP version
    • Whether you are using Outlook.com, Microsoft 365, or a single-tenant Entra app
    • Whether the Directory (tenant) ID field is empty or filled
    • A screenshot of the Outlook connection settings, with client secret/tokens hidden

    Please do not share any client secret, access token, or refresh token publicly.

    Thank you.

    Thread Starter Hola12345

    (@mridul12345)

    Thank you. Unfortunately, it solved one problem but created another.

    I had 2 senders; admin@domain.com and no-reply@domain.com The no-reply@domain.com sender was working perfectly before. Tested on real environment and tested with “Send Test Email” feature. But admin@domain.com was NOT working and that is the reason I contacted you for support.

    Your solution fixed the admin@domain issue. Tested with the email test feature. But now no-reply@domain.com is not sending test email. It is showing this error

    “The user account which was used to submit this request does not have the right to send mail on behalf of the specified sending account., Cannot submit message.”

    Could you please help.

    Thread Starter Hola12345

    (@mridul12345)

    I’ll appreciate your help. Could you please get back to me.

    Plugin Support Ariful Islam

    (@arifulislam1)

    I’m sorry for the delayed reply.

    The refresh-token issue for admin@domain.com appears to be resolved, but the new error with no-reply@domain.com is a separate Microsoft 365 permission issue.

    Microsoft is rejecting the message because the Microsoft account used to authenticate FluentSMTP does not currently have permission to send as, or send on behalf of, no-reply@domain.com.

    Microsoft is rejecting the request because the account authenticated in the FluentSMTP connection is not currently allowed to send using no-reply@domain.com.

    Please verify the following:

    1. Confirm which Microsoft account was used to authenticate the no-reply@domain.com connection.
    2. If no-reply@domain.com is a separate or shared mailbox, grant the authenticated account either Send As or Send on Behalf permission for that mailbox.
    3. Confirm that the Microsoft Graph delegated permission Mail.Send.Shared is enabled and consented.
    4. Reconnect the no-reply@domain.com connection in FluentSMTP after confirming the permissions.
    5. If no-reply@domain.com is only an alias, verify that it is mapped to the correct Outlook connection.

    Please do not share any client secret, access token, or refresh token publicly. If the issue continues, please let us know whether no-reply@domain.com is a separate mailbox, shared mailbox, or alias, and which account was used during authentication.

    Thank you.

Viewing 5 replies - 1 through 5 (of 5 total)

You must be logged in to reply to this topic.