# Configure outgoing email

Connect Content Central to your mail system — classic SMTP or OAuth2 for Microsoft 365 and Google Workspace — so notifications, approvals, and the E-mail document action all work, with the test that proves it.

Product: content-central · Versions: 7.x · Audience: system-administrator · Time: 30 minutes · Last verified: 2026-09-05

Canonical: https://help.ademero.com/content-central/administration/configure-outgoing-email

**At the end of this guide Content Central can send mail — workflow notifications, approval requests, and the E-mail document action — through plain SMTP or through OAuth2 with Microsoft 365 or Google Workspace, and you'll have proven it with a real delivered message.**

One symptom is worth knowing before you start: when outgoing email isn't configured, Content Central doesn't complain — the **E-mail** action simply doesn't appear in document menus, with no message explaining why. If users report that "the email button is missing," this page is the fix.

## Where it lives

**Administration** > **System Settings**, then **E-mail Server** in the **Communication** group of the left sidebar (the panel heading reads **E-mail Server Settings**). System Settings requires a full administrator account — there's no narrower permission that grants it.

Changes collect on the page — an **Unsaved changes** banner appears — and nothing takes effect until you click **Save Changes**.

## Set the sending identity

At the top of the category:

1. **From name (i.e. Content Central)** — the display name recipients see.
2. **From address (i.e. noreply@corp.com)** — the sending address. Use one your mail provider allows this account to send as.
3. **Always use "From address" above, overriding user's e-mail address** — with this on, everything sends from the one address above; with it off, mail a user initiates can go out under that user's own address, which some providers refuse. When in doubt, turn it on.

Then pick the **Outgoing mail server type**: **SMTP** or **OAuth2**. The **Username (if required)** field just below serves both paths — it's the account Content Central signs in as.

## Path A — SMTP

1. Enter the **Outgoing mail server (SMTP)** — your provider's server name, like `smtp.example.com`.

2. Pair **Server Port** with **Connection security**. The setting's own description says it best: "STARTTLS and SSL/TLS are alternatives, not settings to combine. Changing this does not change the port."
   
   | Server Port | Connection security |
   |---|---|
   | `587` | **STARTTLS (commonly port 587)** |
   | `465` | **SSL/TLS (commonly port 465)** |
   | `25` | **None** — only if your mail server requires unencrypted |

3. Fill in **Username (if required)** and **Password (if required)** if your server wants authentication (almost all do).

4. Click **Test** in the **Test Connection** row — "Connects and signs in. No message is sent." The test uses the values currently on the form, even unsaved ones. A failure offers a **Show details** disclosure with the raw diagnostics — that text is exactly what your mail administrator will ask for.

*[Screenshot: The healthy pairing: port 587 with STARTTLS, credentials filled in, and the Test Connection row that proves sign-in without sending anything.]*

## Path B — OAuth2 (Microsoft 365 or Google Workspace)

Set **Outgoing mail server type** to **OAuth2**, then choose the **OAuth2 Provider**: **Azure AD / Microsoft 365** or **Google Workspace**. The SMTP fields no longer apply — each provider shows its own small set.

*[Screenshot: Server type switched to OAuth2 with the Azure AD / Microsoft 365 provider chosen: the tenant, application, and secret from your app registration go here, while the Username field above holds the sending mailbox.]*

### Microsoft 365

1. Fill in **Directory Id (Tenant Id)**, **Application Id**, and **Client Secret** from your Entra app registration, and put the sending mailbox's address in **Username (if required)**.
   
   > note: These are the same four values the *email capture* side uses. If you've already registered an app for [capture from Microsoft 365](/content-central/capture/connect-email-capture-to-microsoft-365), you can reuse that registration — the values just have to be entered here as well, since the two settings are stored separately. That article also walks through creating the registration from scratch.

2. Click **Test**. Success reads "Test succeeded!" with a count of messages in the mailbox — the test proves the credentials reach the mailbox; like the SMTP test, it sends nothing. There's no sign-in popup on this path.

### Google Workspace

1. Fill in **Client Id** and **Client Secret** from your Google Cloud Console OAuth client, and the sending account in **Username (if required)**.
   
   The OAuth client's **authorized redirect URI** must be your server's address followed by `/Admin/AdminSystemSettingsGmailOAuth2.aspx` — for example `https://docs.example.com/ContentCentral/Admin/AdminSystemSettingsGmailOAuth2.aspx`. That page exists only to receive Google's response; you never browse to it yourself.

2. Click **Test**. This one *is* interactive: a Google consent window opens — sign in as the sending account and approve. Success reads "Test succeeded! Click Save to persist the new tokens."

3. **Click Save Changes.** The tokens from the consent step aren't stored until you do — a tested-but-unsaved page is still an unconfigured server.

> **NOTE:** Two Google-specific snags, both with on-screen fixes: if the window never opens, your browser blocked the popup — allow it and test again. If authorization fails with "Access denied" (HTTP 403), add `google.com` (or `accounts.google.com`) to **Safe Referrer Domains** under **Security Settings**, save, and test again — the page shows this exact advice before opening the popup.

## Prove it end to end

**Save Changes**, then send something real — the connection test never sends a message, so only a delivered email proves the whole pipeline:

1. Open a document and use the **E-mail** action (its very presence in the menu confirms the settings saved), sending to yourself — or trigger any workflow notification with yourself as recipient.
2. Check your inbox and spam folder.

**Success check:** the message arrives, from the name and address you configured. If it doesn't, [Notification emails aren't sending](/content-central/administration/notification-emails-arent-sending) walks the five layers — connection, sign-in, trigger, template, delivery — in order.

## What's next

- [Notification emails aren't sending](https://help.ademero.com/content-central/administration/notification-emails-arent-sending)
- [Connect email capture to Microsoft 365](https://help.ademero.com/content-central/capture/connect-email-capture-to-microsoft-365)
