How to Set Up Scan to Email on a Copier
A current, plain-English guide to configuring scan-to-email with Microsoft 365, Google Workspace, Gmail, and other email providers—including modern authentication, relay options, app passwords, copier settings, and the fixes for systems that suddenly stopped working.
Your Copier Is an Email-Sending Device
When a copier emails a scan, it connects to an outgoing mail service, proves that it is allowed to send, and attaches the scanned document to a message. Most scan-to-email failures originate in one of four places:
- 01The email delivery method — OAuth, SMTP relay, Direct Send, an app password, or another provider-supported method.
- 02The mail server settings — server name, port, encryption type, sender address, and authentication setting.
- 03The copier's network settings — a valid IP address, default gateway, DNS server, date, time, and access through the firewall.
- 04The copier's security capabilities — current firmware, TLS 1.2 or newer where required, certificate validation, and support for the authentication method your email provider now expects.
Organizations that want ongoing help with driver changes, address books, scan settings, and other everyday printer issues can review ABT Concierge. For broader fleet monitoring, automatic toner fulfillment, and centralized support, see Managed Print Services.
Gather These Five Things First
A few minutes of preparation prevents the stop-search-restart cycle that makes this job feel harder than it is.
- 01A dedicated scanner identity or sender address — for example scanner@yourcompany.com. Avoid using an employee's personal mailbox. Account-authenticated methods may require a licensed mailbox; relay-based methods may not.
- 02Administrative access to the email environment — Microsoft 365, Google Workspace, or the control panel for your other email provider. Some methods require an email administrator to create a connector, relay rule, or application consent.
- 03The copier's IP address — print a network configuration report or locate it under a menu such as Settings › Network › TCP/IP. You will use it to configure the device from a browser.
- 04The exact manufacturer, model, and firmware version — OAuth and modern TLS support vary by device and firmware. Check for a firmware update before assuming the copier is too old.
- 05The delivery requirement — decide whether the copier must send only to employees inside your domain or also to customers, vendors, and other outside addresses. That answer determines the correct Microsoft and Google path.
Choose the Right Microsoft 365 Setup
There is no longer one Microsoft 365 configuration that is best for every copier. The correct method depends on whether the device supports OAuth, whether scans must go outside your organization, and whether the office has a static public IP address or certificate that can secure a relay connector.
OAuth / Modern Authentication
Use this when the copier explicitly supports Microsoft 365 OAuth, Modern Authentication, or an Exchange Online sign-in flow.
- Sends to internal and external recipients
- Uses a token instead of storing a normal password
- Usually requires current firmware and vendor-specific setup
Direct Send
Use this when scans only need to reach Microsoft 365 recipients inside your organization and the device cannot use OAuth.
- No mailbox password required
- No licensed mailbox required
- Can be blocked tenant-wide by the Microsoft 365 administrator
- Cannot deliver to Gmail, Yahoo, customers, or vendors
Microsoft 365 SMTP Relay
Use this for older devices that must send internally and externally when the office has a static public IP address or a suitable TLS certificate.
- No licensed sender mailbox required
- Requires a Microsoft 365 inbound connector
- Port 25 must be open and permitted by the ISP
Password-Based SMTP AUTH
This may still work for existing tenants and older copiers, but Microsoft is moving away from Basic Authentication. Treat it as a transition plan, not a permanent design.
- Requires a licensed Microsoft 365 mailbox
- Blocked by Security Defaults and many Conditional Access policies
- Scheduled to be disabled by default in existing tenants at the end of December 2026
Option 1: OAuth / Modern Authentication
Start here when the copier's email setup includes a button or option such as Sign in with Microsoft, OAuth 2.0, Modern Authentication, or Exchange Online. Update the copier's firmware first, because manufacturers often add or repair OAuth support through firmware updates.
| SMTP server | smtp.office365.com |
| Port | 587 |
| Encryption | STARTTLS — TLS 1.2 or newer |
| Authentication | OAuth 2.0 / Modern Authentication |
| Mailbox | Dedicated, licensed Microsoft 365 mailbox |
| From address | Use the authenticated mailbox unless Send As permission is configured |
The exact registration and sign-in steps are manufacturer-specific. Some devices open a Microsoft sign-in page and request administrator consent; others require an application registration or vendor cloud service. Follow the copier manufacturer's instructions for that exact model.
Option 2: Direct Send for Internal Recipients
-
Find Your Microsoft 365 MX Endpoint
Look up the MX record for your Microsoft 365 domain. It normally resembles yourdomain-com.mail.protection.outlook.com. Use the actual MX endpoint for your domain—not smtp.office365.com.
-
Enter the Direct Send Settings
SMTP server Your domain's Microsoft 365 MX endpoint Port 25 Encryption STARTTLS when supported Authentication None From address An address in your accepted Microsoft 365 domain Delivery Recipients inside your Microsoft 365 organization only -
Verify Domain Authentication and Port Access
Have the email administrator verify the domain's SPF, DKIM, and DMARC configuration. Confirm the office firewall and internet provider allow outbound port 25, and ask whether the tenant-wide RejectDirectSend setting is enabled. If the copier sends internally but not externally, that is expected behavior for Direct Send.
Option 3: Microsoft 365 SMTP Relay
SMTP relay is often the best answer for an older copier that cannot use OAuth but must send scans to people outside the organization. An administrator creates an inbound connector that recognizes the office by a TLS certificate or a static public IP address. Dynamic public IP addresses are not supported for IP-based Microsoft 365 relay authentication.
| SMTP server | Your domain's Microsoft 365 MX endpoint |
| Port | 25 |
| Encryption | STARTTLS — TLS 1.2 or newer |
| Authentication | Inbound connector using certificate or static public IP |
| Username / password | Not entered on the copier for IP- or certificate-based relay |
| From address | Any address in an accepted Microsoft 365 domain |
| Delivery | Internal and external recipients |
Option 4: Temporary Password-Based SMTP AUTH
If the copier cannot support a durable authentication method even after a firmware update, compare the cost of continued workarounds with replacement using our Upgrade vs. Keep guide. Organizations considering new equipment can also review the Business Printer Leasing Guide.
-
Enable Authenticated SMTP for the Dedicated Mailbox
In the Microsoft 365 admin center, go to Users › Active users, open the dedicated scanner account, select Mail › Manage email apps, and enable Authenticated SMTP. This only enables the mailbox-level setting; tenant security policies can still block Basic Authentication.
-
Enter the Transitional Settings
SMTP server smtp.office365.com Port 587 Encryption STARTTLS — TLS 1.2 or newer Authentication On — username and password Username The full licensed mailbox address Password The dedicated mailbox password From address Match the authenticated mailbox unless Send As is granted -
Do Not Disable Organization-Wide Security
Microsoft Security Defaults and Conditional Access policies commonly block Basic Authentication. Do not turn off MFA, Security Defaults, or a company-wide legacy-authentication block just to make one copier work. Move the device to OAuth, Direct Send, SMTP relay, or a properly secured third-party relay.
Not Sure Which Microsoft Path Fits Your Copier?
Send ABT the manufacturer, model, firmware version, email domain, and whether scans must go to outside addresses. Those details usually identify the correct method before anyone begins changing settings. Existing and prospective customers who need recurring remote help can also review ABT Concierge.
Submit the Copier Details ›Use SMTP Relay for Workspace—or an App Password for a Simple Gmail Setup
Google recommends its SMTP relay service for printers, scanners, and business applications in a Google Workspace environment. A personal Gmail account or a simple one-device setup can use smtp.gmail.com with a 16-character app password.
Google Workspace: SMTP Relay Is the Recommended Method
-
Create a Restricted Relay Rule
In the Google Admin console, open the Gmail routing settings and configure the SMTP relay service. Restrict the rule to approved senders and the office's public IP address or another Google-supported authentication method. Require TLS when the copier supports it.
-
Enter the Relay Settings on the Copier
SMTP server smtp-relay.gmail.com Port 587 with STARTTLS preferred; Google also supports 25 or 465 Encryption STARTTLS / TLS when supported Authentication As configured in the Google Workspace relay rule From address An address permitted by the relay rule Delivery Internal and external recipients -
Test from the Office Network
If the relay authenticates by public IP address, test while the copier is on the approved office internet connection. A dynamic public IP can change and break an IP-restricted relay, so verify the internet service arrangement before choosing that design.
Personal Gmail or Simple Account Authentication: Use an App Password
-
Turn On 2-Step Verification
Sign in to the dedicated Google account, open Google Account › Security, and enable 2-Step Verification. App passwords are available only after 2-Step Verification is active.
-
Create a 16-Character App Password
Open the account's App Passwords page and create a password named “Copier.” Copy it immediately because Google displays it only once. Enter the 16 characters on the copier without spaces.
-
Enter the Gmail SMTP Settings
SMTP server smtp.gmail.com Port 587 with STARTTLS, or 465 with SSL Authentication On — username and app password Username The full Gmail or Google Workspace email address Password The 16-character app password From address The same Google account address
Restricted Gmail SMTP: A Limited Special Case
Google Workspace also offers aspmx.l.google.com on port 25 without authentication, but it can send only to Gmail or Google Workspace users and requires IP allowlisting and correct SPF configuration. Because the delivery limits are easy to misunderstand, most organizations are better served by the normal Workspace SMTP relay.
Enter the Settings Through the Copier's Web Page
Most network-connected business copiers have a web administration page. Configuring email from a computer is faster and less error-prone than typing server names and credentials on a small touchscreen.
-
Open the Copier's Web Administration Page
From a computer on the same trusted network, enter the copier's IP address in a browser. Try https://<copier IP> first when the device supports HTTPS. Some older devices use http://<copier IP>. Never expose this page directly to the public internet.
-
Sign In as the Device Administrator
HP often calls this the Embedded Web Server, Canon the Remote UI, Brother Web Based Management, and other manufacturers use similar names. Change any default administrator password before storing email credentials on the device.
-
Find Email, SMTP, or Digital Send Settings
Look for a path such as Network › Email, Scan/Digital Send › Email Setup, Send › E-Mail Settings, or SMTP. Enter the settings for the Microsoft, Google, or other-provider method selected above.
-
Confirm the Device Clock and Firmware
Verify the date, time, time zone, DNS server, default gateway, and firmware version. A wrong clock can make a valid security certificate appear expired or not yet valid, while outdated firmware can prevent TLS or OAuth from working.
-
Run a Connection Test and a Real Scan
Use the device's Test connection or Send test email feature first. Then scan a real page to an internal address and, when external delivery is required, to an outside address. Record the exact error code if either test fails.
-
Build the Address Book and Sensible Defaults
Add staff addresses and one-touch destinations through the browser. For everyday documents, start with PDF at 200 or 300 DPI. Use grayscale or black and white when color is unnecessary. Higher resolutions increase attachment size quickly.
Make It Work Without Creating a New Security Problem
A functioning scan-to-email setup should also be restricted, documented, and easy to revoke.
- 01Use a dedicated scanner identity rather than an employee's everyday account.
- 02Prefer OAuth or a restricted relay over storing a reusable mailbox password on the copier.
- 03Restrict relay permissions to approved sender domains, office IP addresses, certificates, and recipient types.
- 04Change default copier administrator credentials and keep the web page reachable only from trusted internal networks or approved management channels.
- 05Store the configuration securely — document the method, sender identity, relay owner, firmware version, and recovery steps without recording reusable passwords in an unsecured file.
- 06Revoke access when the device is retired — remove app passwords, OAuth grants, relay permissions, address books, and stored credentials before a copier is returned, sold, or recycled. Organizations that need ongoing device maintenance and support can also review ABT's printer and copier service plans.
Scan-to-Email Troubleshooting
Match the exact symptom or error to the most likely cause. Do not change several settings at once—you will lose the clue that identifies the real problem.
The Authentication Method or Credential Is Wrong
Confirm the full email address is used as the username. For Gmail, use the app password rather than the normal account password. For Microsoft 365, verify whether the device is using OAuth or legacy SMTP AUTH and whether the mailbox and tenant permit that method. Security Defaults and Conditional Access can block password-based SMTP even when the mailbox setting is enabled.
The From Address Does Not Match the Authenticated Mailbox
Set the copier's From or Device Email address to the same mailbox used to authenticate. If a different sender address is required, a Microsoft 365 administrator must grant the authenticating account Send As permission for that address.
The Copier Cannot Complete the Required Encryption
Confirm the device supports TLS 1.2 or newer where the provider requires it, update the copier firmware, and verify the device's date, time, and time zone. A wrong clock can cause certificate validation to fail. Also confirm the selected port matches the encryption type: commonly 587 with STARTTLS or 465 with SSL for Gmail.
Direct Send May Be Blocked Tenant-Wide
Microsoft 365 administrators can enable RejectDirectSend to reject unauthenticated messages sent through the tenant's MX endpoint. Confirm the MX record, sender domain, DNS, gateway, and outbound port 25 first. If those are correct, ask the Microsoft 365 administrator whether Direct Send has been disabled for the organization. Use OAuth or a properly restricted SMTP relay instead of weakening the tenant's security policy.
The Configuration Is Internal-Only
Microsoft Direct Send cannot deliver to external recipients. Google's restricted SMTP server is also limited. Move to OAuth, Microsoft 365 SMTP relay, Google Workspace SMTP relay, Gmail SMTP with an app password, or another method that explicitly permits external delivery.
The Sender or Domain Authentication Needs Attention
Use a sender address permitted by the selected method. Have the email administrator verify SPF, DKIM, DMARC, relay restrictions, and the From address. An invented or unauthorized sender address is more likely to be filtered or rejected.
The Message Is Exceeding an Attachment Limit
Lower the default resolution to 200 or 300 DPI, use grayscale or black and white, enable compressed PDF, split the document, or use scan-to-folder or a secure cloud workflow. Scan-to-folder avoids normal email attachment limits, although the destination still has its own storage and file-size rules.
The Copier Cannot Reach the Mail Service
Verify the SMTP server name and port, then confirm the copier has a valid default gateway and approved DNS server. The gateway is normally the router or firewall address on the copier's subnet; DNS may be the router, an internal server, or another approved resolver. Check whether the firewall or internet provider blocks the required outbound port. Multi-device environments may benefit from managed print monitoring so network and device issues can be tracked centrally.
The Stored Authorization Was Revoked or No Longer Allowed
Google app passwords are revoked after the main account password changes. Microsoft 365 policies can disable legacy SMTP authentication. A provider migration changes the server settings entirely. Identify what changed on the email side and update only the affected credential, policy, or delivery method.
The Connection Worked, but Delivery Did Not
Check the recipient address, junk folder, message trace or email logs, attachment size, sender permissions, and whether the chosen method permits that recipient. A successful connection test proves the copier reached the server; it does not always prove the final message was accepted and delivered.
Scan-to-Email FAQ
These answers summarize the most common setup decisions. The detailed sections above explain when each method is appropriate.
What is the best way to set up scan to email with Microsoft 365?
Can I still use smtp.office365.com with a username and password?
How do I set up scan to email with Google Workspace?
How do I use Gmail for scan to email?
Why did scan to email suddenly stop working?
Why do long scans fail while short scans work?
Official Provider References
This guide was reviewed against the current provider documentation available on July 15, 2026:
Microsoft: Set up a multifunction device to send email
Microsoft: Updated SMTP AUTH Basic Authentication timeline
Google Workspace: Send email from a printer, scanner, or app
Prefer to Skip the Trial and Error?
ABT configures print drivers, network settings, address books, and scan-to-email—and tests the complete workflow before the job is finished. When an email provider changes its rules, we diagnose the account, network, and copier together instead of guessing at one system in isolation. For recurring remote support, review ABT Concierge; for multi-device fleet oversight, see Managed Print Services.