I try to use Nodemailer to send an email with my GMail account but it doesn't work, it works in local but on my remote server I recieve an email from Google "Someone is using your account...."
How can I do ? = function(req, res){
var name =;
var from = req.body.from;
var message = req.body.message;
var to = '******';
var transport = nodemailer.createTransport("SMTP", {
service: 'Gmail',
auth: {
XOAuth2: {
user: "******",
clientId: "*****",
clientSecret: "******",
refreshToken: "******",
var options = {
from: from,
to: to,
subject: name,
text: message
transport.sendMail(options, function(error, response) {
if (error) {
} else {

Check out the solution from Unable to send email via google smtp on centos VPS:
In my case, my script is on a VPS so I don't have a way to load any url with a browser. What I did: Changed my gmail pw. Gmail > Settings > Accounts. Then in Google Accounts they listed suspicious logins that were blocked by google (these were my script's attempted logins). Then I clicked the option "Yes, that was me". After that, my script worked (using the new pw).


Nodemailer "connect ETIMEDOUT" with custom domain

I'm making a forgot password backend route in Node.js and I'm attempting to use nodemailer to send the email from a custom domain I purchased from, along with the email domain. I'm not sure if it's a problem with the host, the port/security, or the auth. However, when I change the host it gives a a ECONREFUSED error instead so I believe that part is working. My firewall is (as far as I can tell) disabled and I restarted, however it is harder to tell because Norton Antivirus controls it.
This is my code, taken from a router.get route in my back-end.
The full error is "connect ETIMEDOUT" then an ip address with :587 at the end.
const transporter = createTransport({
host: '',
port: 587,
secure: false,
auth: {
user: config.get('emailUser'),
pass: config.get('emailPass')
let resetLink = '';
let authToken = '';
await jwt.sign({ email: }, config.get('JWTSecret'), { expiresIn: 10800000 }, (err, token) => {
if (err) throw err;
authToken += token;
resetLink = await `${config.get('productionLink')}/recipients/resetpassword/${authToken}`
console.log(`resetlink : ${resetLink}`)
const mailOptions = {
from: '"Axotl Support" <>',
subject: "Forgot Password",
text: `Hello ${},\n\nHere is the password reset link you requested (expires in 3 hours): ${resetLink}\nIf you did not request this, please notify us at\n\nThanks!\n-Axotl Support`
try {
console.log('trycatch entered')
// const verified = await transporter.verify()
// console.log(`verified : ${verified}`)
const res = await transporter.sendMail(mailOptions)
console.log('email completed')
res.json({ msg: "email sent" })
} catch (err) {
res.status(500).send("Server Error")
Turns out I was using the wrong host domain-- the service doesn't directly host the email domain on the website. I don't know enough about this specific section. I changed it to the email host and it worked.

Send email without password using nodemailer over a zimbra smtp

im using nodemailer to send emails in a web app using keystonejs as cms. The web app is stored in a server and the email server in other, but SMTP communications between servers does not require password. Now, i need to send emails to other peoples when required using a generic account without the password field because is not neccesary.
This is my nodemailer config:
var selfSignedConfig = {
host: '',
port: 25,
secure: false, // use TLS
auth: {
pass: email.password //NOT REQUIRED
tls: {
// do not fail on invalid certs
rejectUnauthorized: false
var transporter = nodemailer.createTransport(selfSignedConfig);
// verify connection configuration
"email": {
"email": "",
"password": ""
I'm stuck on this, I have tried with "password": "" and "password": " " and nothing works. The email server is Zimbra.
This gave me the following error:
The server IS NOT READY to take the messages: Error: Invalid login: 535 5.7.8 Error: authentication failed: authentication failure
In our case we removed tls, auth and secure fields and it worked on our SMTP server.
The from, to options were set from mail options separately.
You might give the following a try:
var nodemailer = require ('nodemailer'),
_ = require ('lodash')
var selfSignedConfig = {
host: '',
port: 25
var transporter = nodemailer.createTransport(selfSignedConfig);
var attachFiles = attachments?attachments:[];
var attachObjArray = [];
var mailOptions = {
from: fromEmail, // sender address (who sends)
to: toEmail, // list of receivers (who receives)
subject: subject, // Subject line
html: body, // html body
attachments:attachObjArray //attachment path with file name
// send mail with defined transport object
transporter.sendMail(mailOptions, function(error, info) {
return console.log(error);
} else {
console.log('Message sent: ' + info.response);

Gmail refresh tokens, xoauth2 and general informations

I started using nodejs and nodemailer a week ago and I've got some questions about Gmail oauth.
I've set my client ID my secret ID pretty easily but now I'm stuck on a "problem", I'm using gmail refresh tokens for authorizing my botmailer to send newsletter emails, being said it seems that when the token expires my bot is no more authorized and I cannot send emails anymore.
Is there a way I can automatically update the refresh token in my code ?
This is what I got so far, thanks in advance!
var transporter = nodemailer.createTransport({
service: 'gmail',
auth: {
xoauth2: xoauth2.createXOAuth2Generator({
user: 'mybotemail',
clientId: 'myclientid',
clientSecret: 'mysecretid',
refreshToken: 'myrefreshtoken',
accessToken: 'myaccesstoken'
var mailOptions = {
from: "myemailverifiedabove",
to: user,
subject: "Hello world",
generateTextFromHTML: true,
html: "<b>Hello world</b>"
transporter.sendMail(mailOptions, function(error, response) {
if (error) {
} else {
EDIT: Gmail also suspended my account once without even saying why, if some of you does know why, I would appreciate it.

Sending emails using Mailgun with NodeMailer package

A couple of days ago I realized that Google has changed the security of gmail accounts, particularly for the possibility of sending emails from applications. After Googling around for a while I couldn't find a fix for it.
So, I resorted to using Mailgun. I created an account and had it enabled with Business verification. However, I still can't send emails. I keep getting an error about the requested URL not being found.
I am suspecting that since I haven't set up a domain yet, it is not picking the mailgun domain it provided by default. Could someone show me how to test sending emails using Mailgun from NodeMailer indicating the sandbox name provided by mailgun.
thanks in advance
var nodemailer = require('nodemailer');
// send mail with password confirmation
var transporter = nodemailer.createTransport( {
service: 'Mailgun',
auth: {
user: '',
var mailOpts = {
from: '',
to: '',
subject: 'test subject',
text : 'test message form mailgun',
html : '<b>test message form mailgun</b>'
transporter.sendMail(mailOpts, function (err, response) {
if (err) {
//ret.message = "Mail error.";
} else {
//ret.message = "Mail send.";
I created the Nodemailer transport for mailgun.
Here it how it works.
You install the package with npm install as you would do with any package, then in an empty file:
var nodemailer = require('nodemailer');
var mg = require('nodemailer-mailgun-transport');
// This is your API key that you retrieve from (free up to 10K monthly emails)
var auth = {
auth: {
api_key: 'key-1234123412341234',
domain: ''
var nodemailerMailgun = nodemailer.createTransport(mg(auth));
from: '',
to: '', // An array if you have multiple recipients.
subject: 'Hey you, awesome!',
text: 'Mailgun rocks, pow pow!',
}, function (err, info) {
if (err) {
console.log('Error: ' + err);
else {
console.log('Response: ' + info);
Replace your API key with yours and change the details and you're ready to go!
It worked me, when I added the domain also to the auth object (not only the api_key). Like this:
var auth = {
auth: {
api_key: 'key-12319312391',
domain: ''

Sending email via Node.js using nodemailer is not working

I've set up a basic NodeJS server (using the nodemailer module) locally (http://localhost:8080) just so that I can test whether the server can actually send out emails.
If I understand the SMTP option correctly (please correct me if I'm wrong), I can either try to send out an email from my server to someone's email account directly, or I can send the email, still using Node.js, but via an actual email account (in this case my personal Gmail account), i.e using SMTP. This option requires me to login into that acount remotely via NodeJS.
So in the server below I'm actually trying to use NodeJs to send an email from my personal email account to my personal email account.
Here's my simple server :
var nodemailer = require('nodemailer');
var transporter = nodemailer.createTransport("SMTP", {
service: 'Gmail',
auth: {
user: '*my personal Gmail address*',
pass: '*my personal Gmail password*'
var http = require('http');
var httpServer = http.createServer(function (request, response)
from: '*my personal Gmail address*',
to: '*my personal Gmail address*',
subject: 'hello world!',
text: 'hello world!'
However, it's not working. I got an email by Google saying :
Google Account: sign-in attempt blocked
If this was you
You can switch to an app made by Google such as Gmail to access your account (recommended) or change
your settings at so that your account is no
longer protected by modern security standards.
I couldn't find a solution for the above problem on the nodemailer GitHub page. Does anyone have a solution/suggestion ?
Thanks! :-)
The answer is in the message from google.
Go to :
set the Access for less secure apps setting to Enable
For the second part of the problem, and in response to
I'm actually simply following the steps from the nodemailer github page so there are no errors in my code
I will refer you to the nodemailer github page, and this piece of code :
var transporter = nodemailer.createTransport({
service: 'Gmail',
auth: {
user: '',
pass: 'userpass'
It differs slightly from your code, in the fact that you have : nodemailer.createTransport("SMTP".
Remove the SMTP parameter and it works (just tested). Also, why encapsulating it in a http server? the following works :
var nodemailer = require('nodemailer');
var transporter = nodemailer.createTransport({
service: 'Gmail',
auth: {
user: 'xxx',
pass: 'xxx'
from: '',
to: '',
subject: 'hello world!',
text: 'hello world!'
Outdated: refreshToken and accessToken no longer exist in JSON file output
For those who actually want to use OAuth2 / don't want to make the app "less secure", you can achieve this by
Search "Gmail API" from the google API console and click "Enable"
Follow the steps at In the quickstart.js file, changing the SCOPES var from [''] to [''] in the quickstart js file provided as suggested in troubleshooting at
After following the steps in (2), the generated JSON file will contain the acessToken, refreshToken, and expires attributes needed in the OAuth2 Examples for Nodemailer
This way you can use OAuth2 authentication like the following
let transporter = nodemailer.createTransport({
service: 'Gmail',
auth: {
type: 'OAuth2',
user: '',
clientId: '',
clientSecret: 'XxxxxXXxX0xxxxxxxx0XXxX0',
refreshToken: '1/XXxXxsss-xxxXXXXXxXxx0XXXxxXXx0x00xxx',
accessToken: 'ya29.Xx_XX0xxxxx-xX0X0XxXXxXxXXXxX0x',
expires: 1484314697598
instead of storing your gmail password in plaintext and downgrading the security on your account.
i just set my domain to: and it works. I am using a VPS Vultr.
the code:
const nodemailer = require('nodemailer');
const ejs = require('ejs');
const fs = require('fs');
let transporter = nodemailer.createTransport({
host: '',
port: 465,
secure: true,
auth: {
user: '',
pass: 'xxx'
let mailOptions = {
from: '"xxx" <>',
to: '',
subject: 'Teste Templete ✔',
html: ejs.render( fs.readFileSync('e-mail.ejs', 'utf-8') , {mensagem: 'olá, funciona'})
transporter.sendMail(mailOptions, (error, info) => {
if (error) {
return console.log(error);
console.log('Message %s sent: %s', info.messageId, info.response);
my ejs template (e-mail.ejs):
<span>Esse é um templete teste</span>
<p> gerando com o EJS - <%=mensagem%> </p>
Make sure:
install ejs: npm install ejs --save
install nodemailer: npm install nodemailer --save
ping to works: ping
change to your gmail email
change to the email that you want to send a email
Enable less secure apps
Disable Captcha temporarily
have a nice day ;)
While the above answers do work, I'd like to point out that you can decrease security from Gmail by the following TWO steps.
Google Account: sign-in attempt blocked If this was you You can switch to an app made by Google such as Gmail to access your account (recommended) or change your settings at so that your account is no longer protected by modern security standards.
In addition to enabling Allow less secure apps, you might also need to navigate to and click continue.
You only need App password for google auth, then replace your google password in your code.
go here
sample code:
const nodemailer = require('nodemailer');
var transporter = nodemailer.createTransport({
service: "Gmail",
auth: {
user: '',
pass: 'app password here'
transporter.sendMail(option, function(error, info){
if (error) {
} else {
console.log('Email sent: ' + info.response);
For debugging purpose it is handy to implement a callback function (they never do on the nodemailer github page) which shows the error message (if there is one).
from: from,
to: to,
subject: subject,
html: text
}, function(err){
It helped me solve my problem... Turns out newer versions are not working properly:
"Looks like nodemailer 1.0 has breaking changes so 0.7 must be used instead:
Message posted on nodemailer as of 12/17/15:
Do not upgrade Nodemailer from 0.7 or lower to 1.0 as there are breaking changes. You can continue to use the 0.7 branch as long as you like. See the documentation for 0.7 here."
I found this answer here
And install smtp module as dependency:
npm install smtp
var nodemailer = require('nodemailer');
var transporter = nodemailer.createTransport({
service: 'gmail',
type: "SMTP",
host: "",
secure: true,
auth: {
user: '',
pass: 'YourGmailPassword'
var mailOptions = {
from: '',
to: '',
subject: 'Sending Email to test Node.js nodemailer',
text: 'That was easy to test!'
transporter.sendMail(mailOptions, function(error, info){
if (error) {
} else {
console.log('Email sent');
Go to
and change it ON because
Some apps and devices use less secure sign-in technology, which makes your account more vulnerable. You can turn off access for these apps, which we recommend, or turn on access if you want to use them despite the risks.
You should not use gmail password for it anymore!
Recently google has provided a new method to use in 3rd party apps or APIs. You need to use App Password instead of the gmail password. But for creating it, you need to enable 2-step Authentication mode in your google account:
You can find steps here:
try this code its work for me.
var http = require('http');
var nodemailer = require('nodemailer');
http.createServer(function (req, res) {
res.writeHead(200, {'Content-Type': 'text/plain'});
var fromEmail = '';
var toEmail = '';
var transporter = nodemailer.createTransport({
host: 'domain',
port: 587,
secure: false, // use SSL
debug: true,
auth: {
user: '',
pass: 'userpassword'
from: fromEmail,
to: toEmail,
subject: 'Regarding forget password request',
text: 'This is forget password response from your app',
html: '<p>Your password is <b>sample</b></p>'
}, function(error, response){
console.log('Failed in sending mail');
console.dir({success: false, existing: false, sendError: true});
res.end('Failed in sending mail');
console.log('Successful in sending email');
console.dir({success: true, existing: false, sendError: false});
res.end('Successful in sending email');
console.log('Server listening on port 8000');
Successful in sending email
{ success: true, existing: false, sendError: false }
{ accepted: [ '' ],
rejected: [],
response: '250 2.0.0 uAMACW39058154 Message accepted for delivery',
{ from: '',
to: [ '' ] },
messageId: '' }
Adding to xShirase answer just providing screenshots where to enable. Also confirm in security that previous attempt was from you.
Xshirase deserves all upvotes.Iam just showing screenshot.
Here is best way send email using gmail
const transporter = nodemailer.createTransport({
service: 'gmail',
auth: {
user: '******',
pass: '**********',
use two authentication from google => security => app password and do fill some stuff get app password
