{"id":13460,"date":"2026-09-07T09:00:42","date_gmt":"2026-09-07T07:00:42","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=13460"},"modified":"2026-09-07T09:00:47","modified_gmt":"2026-09-07T07:00:47","slug":"metode-de-autentificare-prin-e-mail-explicatii-privind-parolele-parolele-din-aplicatii-oauth-2-0-si-autentificarea-smtp","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/ro\/knowledgebase\/email-authentication-methods-explained-passwords-app-passwords-oauth-2-0-and-smtp-auth\/","title":{"rendered":"Explica\u021bii privind metodele de autentificare prin e-mail: parole, parole de aplica\u021bie, OAuth 2.0 \u0219i SMTP AUTH"},"content":{"rendered":"<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">Email authentication is the process an email service uses to confirm that a mail client is allowed to access an account or send a message. A normal password, an app password, OAuth 2.0, and SMTP AUTH are related, but they do not describe the same part of the connection. This difference explains why a password can work in webmail while an email app rejects it.<\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/email-authentication-methods-explained-passwords-app-passwords-oauth-2-0-and-smtp-auth\/#Why_webmail_and_an_email_app_can_behave_differently\" >Why webmail and an email app can behave differently<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/email-authentication-methods-explained-passwords-app-passwords-oauth-2-0-and-smtp-auth\/#Normal_passwords\" >Normal passwords<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/email-authentication-methods-explained-passwords-app-passwords-oauth-2-0-and-smtp-auth\/#App_passwords\" >App passwords<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/email-authentication-methods-explained-passwords-app-passwords-oauth-2-0-and-smtp-auth\/#OAuth_20_sign-in\" >OAuth 2.0 sign-in<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/email-authentication-methods-explained-passwords-app-passwords-oauth-2-0-and-smtp-auth\/#SMTP_AUTH\" >SMTP AUTH<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/email-authentication-methods-explained-passwords-app-passwords-oauth-2-0-and-smtp-auth\/#How_to_choose_the_authentication_method\" >How to choose the authentication method<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/email-authentication-methods-explained-passwords-app-passwords-oauth-2-0-and-smtp-auth\/#Practical_checks_when_credentials_are_rejected\" >Practical checks when credentials are rejected<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_webmail_and_an_email_app_can_behave_differently\"><\/span>Why webmail and an email app can behave differently<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Webmail and a mail app do not use the same connection path. Webmail handles sign-in inside the provider&#8217;s website. A mail app must connect to the relevant mail server and authenticate through the protocol used for receiving or sending mail.<\/p>\n\n\n\n<\/div>\n\n<div id=\"mybox-3491355266\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Acces timpuriu<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Mai ave\u021bi nevoie de ajutor?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contacta\u021bi echipa noastr\u0103 de servicii pentru clien\u021bi.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Trimite mesaj<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">For outgoing mail, the app must authenticate with the SMTP server. If it tries to send without being properly logged in to that server, the sender address can be rejected even when the account password works in webmail. mybox describes this error as a sign that the application is not correctly logged in to the outgoing SMTP server. <a href=\"https:\/\/mybox.com\/help\/ro\/baza-de-cunostinte\/adresa-expeditorului-respinsa-nu-este-logat\/\">Read the mybox explanation of the \u201csender address rejected: not logged in\u201d error<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Normal_passwords\"><\/span>Normal passwords<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A normal password is the account credential used to prove identity during sign-in. In a mail app, the password is submitted as part of the authentication exchange with the mail server. The app must also use the account&#8217;s correct email address and connect to the correct server service.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A successful webmail login does not by itself prove that the mail app has authenticated to SMTP. The app may be using a separate outgoing-mail setting, an old saved password, or a connection that is not logged in. In that situation, entering the correct password again may not resolve the problem until the SMTP authentication setting is corrected.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Passwords should be protected carefully. A strong password and Two-Step Verification reduce the risk created by brute-force attacks and phishing. <a href=\"https:\/\/mybox.com\/help\/ro\/baza-de-cunostinte\/parole-puternice-si-verificare-in-doi-pasi\/\">mybox recommends strong passwords and Two-Step Verification<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"App_passwords\"><\/span>App passwords<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">An app password is a separate password created for use by a specific application or connection. It is not the same as the account&#8217;s main password. Its purpose is to let a mail app authenticate when the app cannot complete the account provider&#8217;s normal sign-in process.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Use an app password only when the provider supports it and the mail client requires it. It is not a general replacement for a normal password, and creating one does not correct an SMTP connection that is pointed to the wrong service or is not configured to authenticate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Because an app password is still a credential, it must be treated as sensitive account information. Do not reuse it for another service or share it with another person. Credential security matters because weak or exposed credentials can put website files, customer data, and professional email at risk. <a href=\"https:\/\/mybox.com\/help\/ro\/baza-de-cunostinte\/dincolo-de-lacat-rolul-critic-al-securitatii-acreditarilor\/\">Read mybox&#8217;s guidance on credential security<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"OAuth_20_sign-in\"><\/span>OAuth 2.0 sign-in<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">OAuth 2.0 is a sign-in method in which the mail app sends the user through the provider&#8217;s authorization screen instead of asking the app to store or submit the account&#8217;s normal password directly. After authorization, the provider gives the app an access token. The app uses that token to access the permitted mail service.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">OAuth 2.0 requires support from both the email provider and the mail client. If either side does not support the required OAuth sign-in flow, the app cannot use it for that account. In that case, the available method depends on the provider&#8217;s supported authentication options and the client&#8217;s capabilities.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"SMTP_AUTH\"><\/span>SMTP AUTH<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">SMTP AUTH is authentication for the outgoing SMTP connection. It tells the outgoing mail server which account is sending the message and proves that the mail client is allowed to submit mail through that server.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SMTP AUTH is not a separate type of password. It is the authentication step used by the SMTP connection. That step may use a normal password, an app password, or another supported method. A mail app can therefore have a valid account password and still fail to send if SMTP authentication is disabled, incomplete, or connected to the wrong outgoing-mail service.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_choose_the_authentication_method\"><\/span>How to choose the authentication method<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Use a normal password<\/strong> when the provider and mail client support direct password authentication and the account does not require another sign-in method.<\/li>\n\n\n\n<li><strong>Use an app password<\/strong> when the provider supports app passwords and the mail client cannot use the provider&#8217;s normal protected sign-in flow.<\/li>\n\n\n\n<li><strong>Use OAuth 2.0<\/strong> when both the provider and the mail client offer OAuth sign-in for the account. This keeps the main password out of the mail app&#8217;s password field.<\/li>\n\n\n\n<li><strong>Check SMTP AUTH<\/strong> whenever outgoing mail fails. Confirm that the app is set to authenticate to the SMTP server. A sender rejection can mean that the app is not logged in to the outgoing server, rather than that the account password is invalid. <a href=\"https:\/\/mybox.com\/help\/ro\/baza-de-cunostinte\/adresa-expeditorului-respinsa-nu-este-logat\/\">See the mybox SMTP authentication error guidance<\/a>.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Practical_checks_when_credentials_are_rejected\"><\/span>Practical checks when credentials are rejected<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Confirm that webmail sign-in works with the account credentials.<\/li>\n\n\n\n<li>Check whether the mail app is asking for a normal password, an app password, or an OAuth sign-in.<\/li>\n\n\n\n<li>Review the outgoing SMTP account and confirm that authentication is enabled.<\/li>\n\n\n\n<li>Replace an old saved credential in the mail app if the account password or app password has changed.<\/li>\n\n\n\n<li>If the app still cannot send, treat the problem as an SMTP authentication issue rather than repeatedly weakening account security or sharing credentials.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The appropriate method is the strongest method supported by both the provider and the mail client. A normal password can be valid but used in the wrong connection. An app password can help an older client, while OAuth 2.0 uses a separate authorization flow. SMTP AUTH remains the key check for outgoing-mail failures because it controls whether the app is authenticated to the sending server.<\/p>\n<\/div>","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[41],"manual_kb_tag":[],"class_list":["post-13460","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-email"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/13460","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/13460\/revisions"}],"predecessor-version":[{"id":13473,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/13460\/revisions\/13473"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/media?parent=13460"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manualknowledgebasecat?post=13460"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb_tag?post=13460"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}