Originally created by @Wolbaz on GitHub (May 11, 2023).
2FA email is rejected by Gmail
I have SMTP setup sufficiently that gmail allows the test emails to go through, yet when I try to set up 2FA through email, those messages get blocked.
Deployment environment
vaultwarden version: 1.28.1
Install method: Docker Container
Clients used: Web Vault, Android
Reverse proxy and version: traefik 2.6.7
MySQL/MariaDB or PostgreSQL version:
Other relevant details:
Steps to reproduce
Setup SMTP using gmail, send test email, attempt to send 2fa email.
Expected behaviour
Email sent
Actual behaviour
Email blocked by gmail. Have also tried a seperate email address not related to gmail and it was also blocked.
Troubleshooting data
Your environment (Generated via diagnostics page)
Vaultwarden version: v1.28.1
Web-vault version: v2023.3.0b
OS/Arch: linux/x86_64
Running within Docker: true (Base: Debian)
Environment settings overridden: true
Uses a reverse proxy: true
IP Header check: true (X-Real-IP)
Internet access: true
Internet access via a proxy: false
DNS Check: true
Browser/Server Time Check: true
Server/NTP Time Check: true
Domain Configuration Check: true
HTTPS Check: true
Database type: SQLite
Database version: 3.39.2
Clients used:
Reverse proxy and version:
Other relevant information:
Config (Generated via diagnostics page)
Show Running Config
Environment settings which are overridden: SIGNUPS_ALLOWED, INVITATIONS_ALLOWED, ADMIN_TOKEN
Originally created by @Wolbaz on GitHub (May 11, 2023).
<!--
# ###
NOTE: Please update to the latest version of vaultwarden before reporting an issue!
This saves you and us a lot of time and troubleshooting.
See:
* https://github.com/dani-garcia/vaultwarden/issues/1180
* https://github.com/dani-garcia/vaultwarden/wiki/Updating-the-vaultwarden-image
# ###
-->
<!--
Please fill out the following template to make solving your problem easier and faster for us.
This is only a guideline. If you think that parts are unnecessary for your issue, feel free to remove them.
Remember to hide/redact personal or confidential information,
such as passwords, IP addresses, and DNS names as appropriate.
-->
### 2FA email is rejected by Gmail
<!-- Describe your issue here. -->
I have SMTP setup sufficiently that gmail allows the test emails to go through, yet when I try to set up 2FA through email, those messages get blocked.

### Deployment environment
<!--
=========================================================================================
Preferably, use the `Generate Support String` button on the admin page's Diagnostics tab.
That will auto-generate most of the info requested in this section.
=========================================================================================
-->
<!-- The version number, obtained from the logs (at startup) or the admin diagnostics page -->
<!-- This is NOT the version number shown on the web vault, which is versioned separately from vaultwarden -->
<!-- Remember to check if your issue exists on the latest version first! -->
* vaultwarden version: 1.28.1
<!-- How the server was installed: Docker image, OS package, built from source, etc. -->
* Install method: Docker Container
* Clients used: <!-- web vault, desktop, Android, iOS, etc. (if applicable) --> Web Vault, Android
* Reverse proxy and version: <!-- if applicable --> traefik 2.6.7
* MySQL/MariaDB or PostgreSQL version: <!-- if applicable -->
* Other relevant details:
### Steps to reproduce
<!-- Tell us how to reproduce this issue. What parameters did you set (differently from the defaults)
and how did you start vaultwarden? -->
Setup SMTP using gmail, send test email, attempt to send 2fa email.
### Expected behaviour
<!-- Tell us what you expected to happen --> Email sent
### Actual behaviour
<!-- Tell us what actually happened --> Email blocked by gmail. Have also tried a seperate email address not related to gmail and it was also blocked.
### Troubleshooting data
<!-- Share any log files, screenshots, or other relevant troubleshooting data -->
### Your environment (Generated via diagnostics page)
* Vaultwarden version: v1.28.1
* Web-vault version: v2023.3.0b
* OS/Arch: linux/x86_64
* Running within Docker: true (Base: Debian)
* Environment settings overridden: true
* Uses a reverse proxy: true
* IP Header check: true (X-Real-IP)
* Internet access: true
* Internet access via a proxy: false
* DNS Check: true
* Browser/Server Time Check: true
* Server/NTP Time Check: true
* Domain Configuration Check: true
* HTTPS Check: true
* Database type: SQLite
* Database version: 3.39.2
* Clients used:
* Reverse proxy and version:
* Other relevant information:
### Config (Generated via diagnostics page)
<details><summary>Show Running Config</summary>
**Environment settings which are overridden:** SIGNUPS_ALLOWED, INVITATIONS_ALLOWED, ADMIN_TOKEN
```json
{
"_duo_akey": null,
"_enable_duo": false,
"_enable_email_2fa": true,
"_enable_smtp": true,
"_enable_yubico": true,
"_icon_service_csp": "",
"_icon_service_url": "",
"_ip_header_enabled": true,
"_smtp_img_src": "cid:",
"admin_ratelimit_max_burst": 3,
"admin_ratelimit_seconds": 300,
"admin_session_lifetime": 20,
"admin_token": "***",
"allowed_iframe_ancestors": "",
"attachments_folder": "data/attachments",
"authenticator_disable_time_drift": false,
"data_folder": "data",
"database_conn_init": "",
"database_max_conns": 10,
"database_timeout": 30,
"database_url": "***************",
"db_connection_retries": 15,
"disable_2fa_remember": false,
"disable_admin_token": false,
"disable_icon_download": false,
"domain": "*****://*************************",
"domain_origin": "*****://*************************",
"domain_path": "",
"domain_set": true,
"duo_host": null,
"duo_ikey": null,
"duo_skey": null,
"email_attempts_limit": 3,
"email_expiration_time": 600,
"email_token_size": 6,
"emergency_access_allowed": true,
"emergency_notification_reminder_schedule": "0 3 * * * *",
"emergency_request_timeout_schedule": "0 7 * * * *",
"enable_db_wal": true,
"event_cleanup_schedule": "0 10 0 * * *",
"events_days_retain": null,
"extended_logging": true,
"helo_name": null,
"hibp_api_key": null,
"icon_blacklist_non_global_ips": true,
"icon_blacklist_regex": null,
"icon_cache_folder": "data/icon_cache",
"icon_cache_negttl": 259200,
"icon_cache_ttl": 2592000,
"icon_download_timeout": 10,
"icon_redirect_code": 302,
"icon_service": "internal",
"incomplete_2fa_schedule": "30 * * * * *",
"incomplete_2fa_time_limit": 3,
"invitation_expiration_hours": 120,
"invitation_org_name": "Vaultwarden",
"invitations_allowed": true,
"ip_header": "X-Real-IP",
"job_poll_interval_ms": 30000,
"log_file": null,
"log_level": "Info",
"log_timestamp_format": "%Y-%m-%d %H:%M:%S.%3f",
"login_ratelimit_max_burst": 10,
"login_ratelimit_seconds": 60,
"org_attachment_limit": null,
"org_creation_users": "",
"org_events_enabled": false,
"org_groups_enabled": false,
"password_hints_allowed": true,
"password_iterations": 100000,
"reload_templates": false,
"require_device_email": false,
"rsa_key_filename": "data/rsa_key",
"send_purge_schedule": "0 5 * * * *",
"sendmail_command": null,
"sends_allowed": true,
"sends_folder": "data/sends",
"show_password_hint": true,
"signups_allowed": true,
"signups_domains_whitelist": "",
"signups_verify": true,
"signups_verify_resend_limit": 6,
"signups_verify_resend_time": 3600,
"smtp_accept_invalid_certs": false,
"smtp_accept_invalid_hostnames": false,
"smtp_auth_mechanism": null,
"smtp_debug": false,
"smtp_embed_images": true,
"smtp_explicit_tls": null,
"smtp_from": "*************************",
"smtp_from_name": "Vaultwarden",
"smtp_host": "**************",
"smtp_password": "***",
"smtp_port": 587,
"smtp_security": "starttls",
"smtp_ssl": null,
"smtp_timeout": 15,
"smtp_username": "*************************",
"templates_folder": "data/templates",
"tmp_folder": "data/tmp",
"trash_auto_delete_days": null,
"trash_purge_schedule": "0 5 0 * * *",
"use_sendmail": false,
"use_syslog": false,
"user_attachment_limit": null,
"web_vault_enabled": true,
"web_vault_folder": "web-vault/",
"websocket_address": "0.0.0.0",
"websocket_enabled": false,
"websocket_port": 3012,
"yubico_client_id": null,
"yubico_secret_key": null,
"yubico_server": null
}
```
</details>
If I'm correct, Google will also block if the from name deviates to much from the configured user. It may not do this the first few nails, but there AI or what ever you want to call it will c do that after a few emails from what i understand.
Besides that, there is nothing we can do. We can't magically pass through there detection filtering.
I suggest to s see if emails will work when you change the from name from Vaultwarden to the actual name of that mailbox and see what happens. Other than that, we can't do anything I'm afraid.
@BlackDex commented on GitHub (May 12, 2023):
If I'm correct, Google will also block if the from name deviates to much from the configured user. It may not do this the first few nails, but there AI or what ever you want to call it will c do that after a few emails from what i understand.
Besides that, there is nothing we can do. We can't magically pass through there detection filtering.
I suggest to s see if emails will work when you change the from name from `Vaultwarden` to the actual name of that mailbox and see what happens. Other than that, we can't do anything I'm afraid.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Originally created by @Wolbaz on GitHub (May 11, 2023).
2FA email is rejected by Gmail
I have SMTP setup sufficiently that gmail allows the test emails to go through, yet when I try to set up 2FA through email, those messages get blocked.
Deployment environment
Install method: Docker Container
Clients used: Web Vault, Android
Reverse proxy and version: traefik 2.6.7
MySQL/MariaDB or PostgreSQL version:
Other relevant details:
Steps to reproduce
Setup SMTP using gmail, send test email, attempt to send 2fa email.
Expected behaviour
Email sentActual behaviour
Email blocked by gmail. Have also tried a seperate email address not related to gmail and it was also blocked.Troubleshooting data
Your environment (Generated via diagnostics page)
Config (Generated via diagnostics page)
Show Running Config
Environment settings which are overridden: SIGNUPS_ALLOWED, INVITATIONS_ALLOWED, ADMIN_TOKEN
@Wolbaz commented on GitHub (May 11, 2023):
I was able to work around this by running my emails through Mailjet instead of Gmail.
@BlackDex commented on GitHub (May 12, 2023):
If I'm correct, Google will also block if the from name deviates to much from the configured user. It may not do this the first few nails, but there AI or what ever you want to call it will c do that after a few emails from what i understand.
Besides that, there is nothing we can do. We can't magically pass through there detection filtering.
I suggest to s see if emails will work when you change the from name from
Vaultwardento the actual name of that mailbox and see what happens. Other than that, we can't do anything I'm afraid.