NLog.MailKit.Oauth2 6.0.2-oauthfork

This is a prerelease version of NLog.MailKit.Oauth2.
dotnet add package NLog.MailKit.Oauth2 --version 6.0.2-oauthfork
                    
NuGet\Install-Package NLog.MailKit.Oauth2 -Version 6.0.2-oauthfork
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="NLog.MailKit.Oauth2" Version="6.0.2-oauthfork" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="NLog.MailKit.Oauth2" Version="6.0.2-oauthfork" />
                    
Directory.Packages.props
<PackageReference Include="NLog.MailKit.Oauth2" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add NLog.MailKit.Oauth2 --version 6.0.2-oauthfork
                    
#r "nuget: NLog.MailKit.Oauth2, 6.0.2-oauthfork"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package NLog.MailKit.Oauth2@6.0.2-oauthfork
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=NLog.MailKit.Oauth2&version=6.0.2-oauthfork&prerelease
                    
Install as a Cake Addin
#tool nuget:?package=NLog.MailKit.Oauth2&version=6.0.2-oauthfork&prerelease
                    
Install as a Cake Tool

NLog.MailKit

NuGet Build Status Bugs Vulnerabilities alternate text is missing from this package README image Coverage

Alternative Mail target for NLog using MailKit. Compatible with .NET standard 2+

Including this package will replace the original mail target and has the same options as the original mail target, see docs of the original mailTarget

Currently not implemented:

  • NTLM auth

This library is integration tested with the SmtpServer NuGet package

How to use

  1. Install the package:

    Install-Package NLog.MailKit or in your csproj:

    <PackageReference Include="NLog.MailKit" Version="6.*" />
    
  2. Add to your nlog.config:

    <extensions>
        <add assembly="NLog.MailKit"/>
    </extensions>
    

    Alternative register from code using fluent configuration API:

    LogManager.Setup().SetupExtensions(ext => ext.RegisterTarget<NLog.MailKit.MailTarget>());
    

See the NLog Wiki for available options and examples.

Note that the option skipCertificateValidation="true" can prevent AuthenticationException if your remote certificate for smtpServer is invalid - not recommend!

OAuth2 Support (SMTP Client Credentials Flow)

NLog.MailKit now supports authenticating with SmtpAuthenticationMode.OAuth2 so you can send mail through servers such as Office 365 / Exchange Online using the Azure AD (Entra ID) Client Credentials grant. It might work with other OAuth2 services but was only tested with Azure / Exchange Online.

For Exchange Online, your Application (Service Principal) must have the proper application permissions (full access) as described in Microsoft documentation:
Use client credentials grant flow to authenticate SMTP, IMAP and POP connections

Parameters for nlog.config / app.config

SmtpAuthentication = SmtpAuthenticationMode.OAuth2,
SmtpServer = "smtp.office365.com",
SmtpPort = 587,
SmtpUserName = "",
To = "",
From = "",
ApplicationId = "",
// Use SecretId or Thumbprint
SecretId = "",
SecretWindowsStoreCertificateThumbprint = "",
OAuthTokenUrl = "https://login.microsoftonline.com/{tenantId}/oauth2/v2.0/token",
OAuthScope = "https://outlook.office365.com/.default",
RequireTLS = true

Key notes:

  • Provide either SecretId (client secret) OR SecretWindowsStoreCertificateThumbprint (certificate in local Machine\My) for credential authentication (not both unless fallback is supported).
  • OAuthTokenUrl usually contains your tenant id: https://login.microsoftonline.com/{tenant-id}/oauth2/v2.0/token. Insert tenant id if needed.
  • OAuthScope for SMTP with application permissions is typically https://outlook.office365.com/.default.
  • SmtpUserName is the mailbox you are sending from. Note it can differ from the From email, as long as it has Send-As permissions.
  • OAuthTokenUrl is the URL where you retrive Token. Replace the tenantId for Azure.
  • Ensure SMTP AUTH is enabled for the mailbox/tenant if your organization security settings have disabled it.

Example nlog.config target (OAuth2)

<target xsi:type="Mail"
        name="mail-oauth2"
        SmtpAuthentication="OAuth2"
        SmtpServer="smtp.office365.com"
        SmtpPort="587"
        RequireTLS="true"
        From=""
        To=""
        Subject="My OAuth2 Test Log ${longdate}"
        Body="Log Message: ${message}${newline}Level: ${level}${newline}Logger: ${logger}"
        ApplicationId=""
        SecretId=""
        SecretWindowsStoreCertificateThumbprint=""
        OAuthTokenUrl="https://login.microsoftonline.com//oauth2/v2.0/token"
        OAuthScope="https://outlook.office365.com/.default"
        SmtpUserName="">
</target>

Fluent configuration (C#) example

LogManager.Setup().SetupExtensions(ext => ext.RegisterTarget<NLog.MailKit.MailTarget>());

var mailTarget = new NLog.MailKit.MailTarget
{
    Name = "mail-oauth2",
    SmtpAuthentication = NLog.MailKit.SmtpAuthenticationMode.OAuth2,
    SmtpServer = "smtp.office365.com",
    SmtpPort = 587,
    RequireTLS = true,
    From = "",
    To = "",
    Subject = "My OAuth2 Test Log ${longdate}",
    Body = "Log Message: ${message}${newline}Level: ${level}${newline}Logger: ${logger}",
    ApplicationId = "",
    SecretId = "", // Or leave empty if using certificate
    SecretWindowsStoreCertificateThumbprint = "",
    OAuthTokenUrl = "https://login.microsoftonline.com//oauth2/v2.0/token",
    OAuthScope = "https://outlook.office365.com/.default",
    SmtpUserName = ""
};

var config = LogManager.Configuration ?? new NLog.Config.LoggingConfiguration();
config.AddTarget(mailTarget);
config.AddRuleForAllLevels(mailTarget);
LogManager.Configuration = config;

Security considerations

  • Do NOT commit secrets; store them in environment variables, secret managers, or Azure Key Vault.
  • Prefer certificate authentication (SecretWindowsStoreCertificateThumbprint) over client secrets where possible.
  • Verify tenant policies: SMTP AUTH and application permissions must be appropriately configured.

License

BSD. License of MailKit is MIT

Product Compatible and additional computed target framework versions.
.NET net5.0 was computed.  net5.0-windows was computed.  net6.0 was computed.  net6.0-android was computed.  net6.0-ios was computed.  net6.0-maccatalyst was computed.  net6.0-macos was computed.  net6.0-tvos was computed.  net6.0-windows was computed.  net7.0 was computed.  net7.0-android was computed.  net7.0-ios was computed.  net7.0-maccatalyst was computed.  net7.0-macos was computed.  net7.0-tvos was computed.  net7.0-windows was computed.  net8.0 was computed.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 was computed.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
.NET Core netcoreapp2.0 was computed.  netcoreapp2.1 was computed.  netcoreapp2.2 was computed.  netcoreapp3.0 was computed.  netcoreapp3.1 was computed. 
.NET Standard netstandard2.0 is compatible.  netstandard2.1 is compatible. 
.NET Framework net461 was computed.  net462 is compatible.  net463 was computed.  net47 was computed.  net471 was computed.  net472 was computed.  net48 was computed.  net481 was computed. 
MonoAndroid monoandroid was computed. 
MonoMac monomac was computed. 
MonoTouch monotouch was computed. 
Tizen tizen40 was computed.  tizen60 was computed. 
Xamarin.iOS xamarinios was computed. 
Xamarin.Mac xamarinmac was computed. 
Xamarin.TVOS xamarintvos was computed. 
Xamarin.WatchOS xamarinwatchos was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
6.0.2-oauthfork 343 10/14/2025

Changelog:

- Updated NLog v6.0.2

See https://github.com/NLog/NLog.MailKit/releases