- Match SMTP ports, TLS settings, usernames, and app passwords correctly.
- Use calibre job details to separate authentication failures from delivery problems.
- Test a dedicated GMX or compatible Outlook account before reinstalling calibre.
- Confirm the Symptom With a Small Safe Test
- Check the calibre Email Account Settings
- Consider a Dedicated Account for calibre
- Check Firewall, Antivirus, VPN, and Network Restrictions
- Read calibre Job Details and Debug Output Safely
- Run a Clean Temporary Test Before Reinstalling
- Quick Fix Checklist
- Frequently Asked Questions
When calibre reports an SMTP authentication failure, the program has usually reached an email server but cannot sign in with the supplied account details. Typical causes include an incorrect SMTP server, a mismatched port and encryption method, a normal password where an app password is required, disabled access for external email programs, or a provider that no longer accepts basic username-and-password authentication. Firewall and antivirus software can also interrupt the connection before authentication finishes.
This problem is separate from Kindle approval rules, attachment formats, and retailer delivery policies. Begin by proving that calibre can authenticate with the outgoing email server. Only investigate recipient-specific delivery rules after calibre reports that the test email was sent successfully.

Start with free Canva bundles
Browse the freebies page to claim ready-to-use Canva bundles, then get 25% off your first premium bundle after you sign up.
Free to claim. Canva-ready. Instant access.
1. Confirm the Symptom With a Small Safe Test
Open calibre and go to Preferences > Sharing > Sharing books by email. Locate the outgoing email settings and use calibre's email test function. If possible, send the test to an ordinary address you can check, rather than starting with a device-specific address.
A small test separates SMTP authentication from book conversion, attachment size, recipient approval, and format compatibility. You do not need to delete books, rebuild the library, reconnect a reader, or reinstall calibre to perform it.
1.1 Identify Where the Test Fails
Read the final lines of the test result or job error. SMTP errors often contain a three-digit status code and a short provider message. Look for phrases such as:
- Authentication failed, invalid credentials, or username and password not accepted: Check the username, password, app-password requirement, and account security settings.
- Connection timed out or connection refused: Check the server name, port, firewall, antivirus, VPN, and network.
- TLS required, wrong version number, or an SSL handshake error: Correct the encryption and port pairing.
- Relay denied or sender not authorized: Verify that the From address belongs to the authenticated account or is an approved alias.
- Temporary failure, a 4xx response, or a rate-limit message: Stop changing credentials and retry later.
Do not post or share the complete log until you have removed email addresses, usernames, account identifiers, message IDs, and any text that might contain a password. calibre normally masks sensitive information in many contexts, but you should still inspect copied output carefully.
1.2 Know What Success Looks Like
The test should complete without an authentication, TLS, or connection error, and the message should appear in the receiving inbox or spam folder. Once that happens, stop changing SMTP settings. If a book later fails to reach a device-specific address, SMTP login is no longer the problem.
2. Check the calibre Email Account Settings
Most cases of calibre SMTP authentication failed are resolved inside the email configuration screen. Re-enter each value manually instead of assuming a saved value is correct. Copied passwords can contain hidden spaces, while autofill tools sometimes insert the wrong account password.
2.1 Match the SMTP Server to the Account
The SMTP server must belong to the provider for the account calibre uses to send mail. Do not enter an incoming IMAP or POP server, the recipient's provider, or a webmail address.
Common examples include smtp.gmail.com for Gmail and smtp-mail.outlook.com for Outlook.com. Custom-domain, work, school, and internet-provider accounts may use different servers. Confirm the current value in the provider's official documentation or ask the account administrator.
The username is normally the complete sending email address, including the domain. A short username may work with some older services, but the full address is the safer choice unless the provider explicitly says otherwise.
2.2 Pair the Port With the Correct Encryption
SMTP ports and encryption choices are not interchangeable. The two common secure configurations are:
- Port 587 with TLS: The connection begins normally and upgrades using STARTTLS. In calibre, this is generally the appropriate choice when a provider says to use TLS or STARTTLS.
- Port 465 with SSL: Encryption begins as soon as calibre connects. Select SSL when the provider explicitly specifies port 465 with SSL/TLS.
Do not select SSL for a server expecting STARTTLS on port 587. Likewise, do not select TLS on port 465 when the provider expects an immediate SSL connection. A mismatch can produce certificate, handshake, disconnect, timeout, or apparently unrelated authentication errors.
Avoid unencrypted SMTP unless you administer the server and understand the network security implications. calibre's SMTP documentation warns that choosing no encryption is insecure. Port 25 is also frequently filtered by internet providers, workplace networks, and security products.
After correcting the combination, run the built-in test again. If the test succeeds, keep that exact server, port, and encryption configuration.
2.3 Use an App Password When Required
An app password is a provider-generated password for applications that cannot use the provider's interactive sign-in page. It is different from your ordinary webmail password. Providers may require one when two-step verification is enabled or when traditional SMTP clients cannot complete modern browser-based authentication.
For a Google account, app passwords require two-step verification. Google also notes that app passwords can be unavailable for some organization-managed accounts, Advanced Protection accounts, or accounts configured to use only security keys. Changing the main Google Account password revokes existing app passwords, so calibre will need a newly generated one afterward.
If your provider supplies an app password:
- Create a new app password in the account's official security settings.
- Copy it without adding spaces before or after it.
- Paste it into calibre's password field instead of the normal account password.
- Save the settings and run the email test.
- Store or revoke the app password according to the provider's guidance.
Success means the authentication error disappears. If the provider's security page does not offer app passwords, do not repeatedly guess credentials. The account may require OAuth or an administrator-controlled SMTP relay that calibre's basic account configuration cannot use.
2.4 Check Whether External SMTP Access Is Enabled
Some providers disable access from external email programs until it is enabled in webmail. calibre's documentation specifically advises GMX users to enable sending and receiving through an external program in the account's POP3 and IMAP settings.
Work and school accounts may have SMTP authentication disabled by policy. In that situation, the correct server and password can still fail. Contact the administrator and ask whether authenticated SMTP is permitted for the account. Do not weaken organization security controls or try to evade them.
2.5 Make the Sender Address Match
Set calibre's From address to the same address used as the SMTP username unless the provider has confirmed that another address is an authorized alias. A mismatch can pass the password stage but fail later with a sender, relay, or authorization error.
After changing the From address, repeat the small test. Stop adjusting the sender if the provider accepts it and the test arrives.
3. Consider a Dedicated Account for calibre
If your main provider blocks traditional SMTP authentication, a separate account can be simpler and safer than repeatedly changing your primary account's security settings. The calibre manual recommends using a free GMX account and also suggests creating a GMX or Outlook account used only by calibre.
3.1 Set Up GMX Through calibre
In Preferences > Sharing > Sharing books by email, select calibre's GMX setup option and supply the dedicated account information. Then sign in to GMX through a browser and enable access for external email programs in the provider's mail settings.
Use the settings supplied by the preset or GMX's current official documentation. Do not guess the server name, port, or encryption option from an old forum post. Providers can update connection requirements.
Run calibre's test before adding several recipient addresses. A successful test confirms that the new account works as an SMTP relay. It does not yet prove that every destination will accept every attachment.
3.2 Use Outlook Only When the Account Allows the Required Authentication
Outlook.com documents port 587 with STARTTLS for outgoing SMTP. However, Microsoft increasingly uses modern authentication, and account type or security policy can affect whether password-based SMTP works. An app password may help with some accounts, but it cannot override an administrator policy that disables authenticated SMTP.
If Outlook rejects a correct password and no compatible app-password option is available, stop cycling through ports. Use a provider or relay that explicitly supports the authentication method available in calibre.
3.3 Respect Provider Sending Limits
Do not reduce calibre's delay between messages simply because a test succeeded. Public email services use anti-spam controls and may temporarily restrict or disable accounts that send too many attachments too quickly. calibre deliberately spaces messages when using recognized public relays such as GMX, Outlook, and Gmail.
For ordinary personal library use, the delay is protective rather than a fault. Wait for the current job to finish before launching repeated tests.
4. Check Firewall, Antivirus, VPN, and Network Restrictions
Security software usually causes a timeout, reset, or blocked connection rather than a clean incorrect-password response. Nevertheless, some products interrupt TLS negotiation in a way that makes the result look like an authentication problem.
4.1 Allow calibre to Make Outbound Connections
Check the firewall or security suite for blocked events involving calibre. Depending on the platform and installation, the relevant process may be calibre itself or a calibre helper process used for email jobs.
- Windows: Check Windows Security and any third-party firewall or antivirus history. Allow calibre on the active network profile when prompted.
- macOS: Review firewall, network-filtering, endpoint-security, and content-filter applications. Corporate profiles may prevent you from changing these controls.
- Linux: Check the host firewall, security policy, container or sandbox restrictions, and any outbound filtering configured by the distribution or network administrator.
Create a narrow application exception rather than disabling all protection. If a temporary test with an approved exception succeeds, restore normal protection and retain only the minimum rule required for calibre's outbound SMTP connection.
4.2 Test Another Trusted Network
Guest Wi-Fi, hotels, workplaces, schools, and some internet providers block outbound SMTP ports. A VPN may also route the connection through an address that the email provider treats as suspicious.
Pause the VPN briefly if organizational policy permits, or test on a trusted home network or mobile hotspot. If the same settings work there, the calibre account configuration is probably correct. Stop changing the password and investigate the original network's outbound rules.
4.3 Check the System Clock and Certificates
TLS certificate validation depends on the computer's date, time, time zone, and trusted certificate store. Correct a substantially inaccurate clock and install normal operating-system certificate updates. Avoid options that disable certificate verification, because doing so can expose account credentials to an untrusted server.

5. Read calibre Job Details and Debug Output Safely
When sending a book, calibre runs the operation as a job. Open the Jobs area and view the failed job's details. The last SMTP response is usually more useful than the first general error line.
5.1 Translate Common SMTP Responses
- 535 or 5.7.x authentication error: The server was reached but rejected the credentials or authentication method. Check the full username, app password, and provider policy.
- 530 authentication required: Authentication may be missing, or the server requires TLS before it will accept login credentials.
- 550 or 5.7.1 relay or sender rejection: The authenticated account may not be allowed to use the configured From address or destination.
- 421, 450, or another 4xx response: This is commonly temporary. Wait before retesting and avoid launching many jobs.
- Name resolution error: The SMTP hostname may be misspelled, or DNS and network access may be unavailable.
- Timeout before an SMTP response: Focus on the port, firewall, VPN, antivirus, and network rather than repeatedly changing the password.
The provider's wording is more important than the numeric code alone. Record the code and a sanitized version of the message before changing anything.
5.2 Use calibre-debug Only When Normal Job Details Are Insufficient
Advanced users can start calibre from a terminal with calibre-debug -g to collect additional GUI diagnostic output while reproducing the failure. Close calibre first, launch it through the command, run one email test, and then inspect the resulting output.
Debug output can contain local paths, account names, addresses, server names, book titles, and other private information. Remove sensitive material before sharing it. Never include a real password or app password in a forum post, screenshot, support ticket, or command copied for someone else.
6. Run a Clean Temporary Test Before Reinstalling
Reinstalling calibre rarely fixes a server rejecting valid or invalid credentials. A cleaner diagnostic is to isolate the account, recipient, and attachment.
- Write down the current SMTP settings without recording the password in an insecure file.
- Use one known-good sending account.
- Set the From address to that same account.
- Use the provider's documented SMTP server and matching secure port.
- Send calibre's built-in test to a normal inbox you control.
- If that succeeds, send one small, ordinary e-book attachment.
- Only then test the intended device or automated destination.
If the built-in test fails, the problem is still the account, authentication method, connection, or provider policy. The library database, book metadata, conversion profile, viewer, editor, Content server, USB mode, and device plugin are not responsible for an SMTP login rejection.
If the test succeeds but one book fails, inspect the failed job for attachment size, source-file, conversion, or recipient-policy errors. If ordinary inbox delivery succeeds but a device address does not, investigate that destination's approval and format rules separately.
Do not delete the calibre library, remove metadata, reset device detection, or bulk-convert books while diagnosing authentication. Those actions do not repair an SMTP password failure and create unnecessary risk.
7. Quick Fix Checklist
- Run calibre's built-in email test before sending a book.
- Use the provider's outgoing SMTP server, not its IMAP or POP server.
- Enter the complete email address as the username.
- Pair port 587 with TLS or STARTTLS when the provider specifies it.
- Pair port 465 with SSL when the provider specifies it.
- Use an app password instead of the normal password when required.
- Create a new app password after changing the main account password.
- Enable access for external email programs when the provider requires it.
- Make the From address match the authenticated account or an approved alias.
- Check firewall, antivirus, VPN, and network blocks if the connection times out.
- Read the final SMTP response in the failed job details.
- Use a dedicated GMX or compatible Outlook account if the primary provider blocks calibre's authentication method.
- Stop changing settings as soon as the built-in test succeeds.
8. Frequently Asked Questions
8.1 Why Does calibre Say Authentication Failed When My Password Works in Webmail?
Webmail and SMTP may use different sign-in methods. Your browser can complete two-step verification or OAuth, while calibre's SMTP connection may require an app password. The provider may also have disabled external SMTP access. Confirm the account's app-password and SMTP policies rather than assuming that a successful browser login proves the SMTP password will work.
8.2 Should I Choose TLS or SSL in calibre?
Follow the provider's documented pairing. Port 587 normally uses TLS or STARTTLS, while port 465 normally uses SSL. Do not choose based only on which term sounds more secure. The server, port, and encryption method must agree.
8.3 Can I Use Gmail to Send Books From calibre?
It may work when the account permits app passwords and you configure the documented Gmail SMTP settings. However, Google-managed organization accounts can restrict third-party authentication, and app passwords are not available for every account. If compatible authentication is unavailable, use a dedicated provider that supports calibre's SMTP method instead of weakening account security.
8.4 Is a Dedicated GMX or Outlook Account Safer?
It can reduce the impact of storing an email credential in calibre because the account is not your primary personal mailbox. Use a unique password, enable the provider's recommended security controls, send only your own legitimate content, and respect rate limits. A separate account does not eliminate the need for secure TLS settings.
8.5 Why Does the Test Work but My Book Still Does Not Arrive?
A successful test means SMTP authentication and basic sending work. The later failure may involve attachment size, file format, conversion output, recipient approval, spam filtering, or a device-specific delivery policy. Open the book-sending job details and follow the new error instead of changing the working SMTP password.
8.6 Should I Reinstall calibre or Delete My Library?
No, not for a straightforward SMTP authentication error. Reinstallation does not change the email provider's password rules, app-password requirement, server configuration, or network filtering. Deleting a library is unrelated and risks losing organization work. Run an isolated email test and diagnose its exact response first.