Unauthenticated Email 

Many systems are set up to send emails via the unauthenticated email relay. This is a legacy service hosted by ICT via automail and smarthost

To check if you are currently using unauthenticated email, you can check which host you are sending to. The services will be listed as using the following SMTP hosts:

  • Automail.cc.ic.ac.uk 
  • Smarthost.cc.ic.ac.uk 

As part of our cybersecurity improvements, these services are being retired by the end of October 2026.

All services currently using these servers will need to:

  • be migrated to an authenticated email solution (examples listed below), or;
  • use an alternative service to disseminate information, or;
  • have the email sending service turned off, if no longer required.

After the service is shut down (end of Oct 2026) you will only be able to send authenticated emails.

Authenticated email 

If you are setting up a new service, system or piece of equipment, you may need to set up an outgoing mail (SMTP) server to send automated emails. 
Examples include:  

  • Cloud hosted services, eg MailChimp;
  • Equipment monitoring software, eg freezer alarms;
  • Hosted servers 

We provide different options, depending on your requirements. Please contact the ICT Service Desk if you are unsure which one to use.

Setting up Cloud Hosted Services

We do not allow new services to utilise @imperial.ac.uk email addresses for sending from external providers due to security concerns. 

If you have a new requirement for this service, please complete a new subdomain request form.

Once this new subdomain is set up, ICT will take you through the process of adding email security via tools, such as SPF and DKIM/DMARC, to allow the external provider to send from the new domain 

If you require a service to send emails to university users, we would recommend utilising Poppulo - the university supported internal communications platform. 

Sending mail from Internal Sources 
 

Client sending 
This requires the following steps: 

  • Submission to smtp.office365.com via port 25 or 587

And either: 

  • Use of legitimate username and password combination for Basic Authentication.
  • Use of app registration and then utilise the tokens to send email for OAuth2 connections.

We can allow role account to send as long as they have send as rights over a mailbox.

Email clients will be required to send email utilising Modern Auth via exchange. This is currently in place and for supported clients this is configures automatically as part of the client setup. 

If your system can be configured to use Modern Auth (OAuth2) by registering the application via Azure and following the below instructions: 
Authenticate an IMAP, POP or SMTP connection using OAuth | Microsoft Learn 

Please note: We still support basic authentication for now, but Microsoft plans to remove it in the second half of 2027. If you choose to use basic authentication, you will need to switch to modern authentication (OAuth 2.0) before then.

Please make plans to switch to modern authentication before the deadline or your application may stop working.

High Volume Email 

If you are sending emails purely to internal imperial.ac.uk addresses and require a bulk emailing facility this High Volume Email  service should meet your requirements.  This is an authenticated service requiring a minimum of Basic Auth.  

We have limited numbers of accounts we can currently configure within Microsoft, therefore we recommend that if you are sending regular bulk emails internally that you use the ICT managed Poppulo service. 

In order to utilise High Volume Email you will need to raise a request to the Email and Cloud Team
We recommend this service if sending over 10,000 messages a month to internal recipients only.