office 365 "Cannot connect to SMTP server" "SSL negotiation failed"

Matthew Brady 210 Reputation points
2025-02-02T22:59:21.92+00:00

Hi team, I work for Ricoh and we have had several clients call in today with an error message when trying to scan. The error message is "Cannot connect to SMTP server" "SSL negotiation failed". Upon checking their setups they are all using office365 accounts for SMTP authentication, all of them stopped working this morning.

Have their been any updates or changes we need to be aware of?

Thanks

Outlook | Windows | Classic Outlook for Windows | For business
{count} votes

Accepted answer
  1. Dux, Monika 135 Reputation points
    2025-02-04T09:39:11.7533333+00:00

    Dear all, I just got a reply from Ricoh technician: "It looks to me as if Microsoft has disabled the cipher suites WITHOUT elliptic curves for TLS1.2. ECDHE is only possible with newer controllers from 18S onwards".

    Our affected MFPs models are: MP C307 , MP 6055, IM C3000, MP C3004ex, and they all have an older controller 16S or 17S.

    We also use IM C300, and, so far, this one seems to be affected.

    12 people found this answer helpful.

8 additional answers

Sort by: Most helpful
  1. Ben Barnes 30 Reputation points
    2025-02-07T06:30:33.14+00:00

    Can somebody Try enabling support for the legacy SMTP endpoint in their tenant:

    https://learn.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/opt-in-exchange-online-endpoint-for-legacy-tls-using-smtp-auth

    Then setting the SMTP Server on their Affected Printer to:

    • smtp-legacy.office365.com

    My guess is that this should work - your emails should still be encrypted with TLS 1.2 if your printer supports it, based on what OpenSSL Says (TLS 1.2 is supported on the endpoints I have been hitting with RSA)

    We are awaiting a change request to try this - can anybody get it implemented and tested faster than us to check?

    User's imageUser's image

    2 people found this answer helpful.

  2. Marvin Telch 35 Reputation points
    2025-02-05T06:53:58.2666667+00:00

    And once again: It seems that the servers that only offered Elliptic Curve via TLS1.2 yesterday now support TLS_RSA again! It looks like Microsoft is reversing the changes.

    1 person found this answer helpful.

  3. Marius L 5 Reputation points
    2025-02-05T07:17:34.5666667+00:00

    Hi!

    Seems like the scans started to normaly work agian. I think they haved fixed the problem with the SMTP servers.

    1 person found this answer helpful.
    0 comments No comments

  4. Carstens, Helge 5 Reputation points
    2025-02-05T11:00:05.9466667+00:00

    We have now solved it by setting up an internal server with an SMTP relay using hMailServer. We are routing all scans from the affected devices through it and then forwarding them to Microsoft. It's just a workaround for the problem, but it works for now.

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.