FAQ

Frequently asked questions

Everything people actually ask before and after installing Missivus, for every platform in the family. The deep technical detail lives in each product's documentation on GitHub; this is the honest short form.

Which platforms does Missivus support?

Four, all carrying the same vendored Graph transport. Missivus for Matomo (available) hooks Piwik\Mail, so password resets, scheduled reports and alerts all go through Graph — oversized report PDFs take the chunked-upload path automatically. Missivus for WordPress (available) short-circuits wp_mail() through WordPress's own pre_wp_mail seam — order confirmations and form notifications included. Missivus for Nextcloud (available) replaces the system mailer, catching core mail and every app that uses Nextcloud's mailer. Missivus for Ghost (available) is an SMTP-to-Graph shim for Ghost's transactional mail — staff invites, password resets, member sign-in links; newsletters stay with your newsletter service.

Does the shared mailbox need a Microsoft 365 licence?

No. An Exchange Online shared mailbox is free up to 50 GB and needs no licence assigned to it — which is the point. Missivus authenticates as an application, not as the mailbox, so nobody signs in as it and nothing is paid for it. A licence only becomes necessary if you convert it to a user mailbox, put it under litigation hold, or give it an archive.

Why not just use SMTP? My platform already supports it.

Because Microsoft is retiring it. All other Basic-auth protocols were switched off in 2022; SMTP AUTH basic authentication stays unchanged until December 2026, is disabled by default for existing tenants at the end of December 2026 and unavailable by default for new tenants after that, with the final removal date to be announced in the second half of 2027. What remains is SMTP AUTH with OAuth2, which none of these platforms' mail paths speak, or a legacy flow that many tenants already block and that turns a licensed user's password into a shared server credential. Graph with application permissions has none of those problems — no password, no user, no licence, and a credential scoped by Exchange to one mailbox.

Are there Microsoft sending limits I should know about?

Yes — Exchange Online's standard sending limits apply, and app-only Graph sending counts against the shared mailbox it sends as. As of Microsoft's current limits page: 10,000 recipients per mailbox per 24 hours, 30 messages per minute, and a per-message cap of 500 recipients by default (admins can raise it to 1,000). For password resets, reports and notifications those ceilings are effectively invisible. Which is the point to say plainly: Missivus carries transactional mail, not newsletters — if you need bulk or marketing sending, use a bulk email service, not a shared mailbox.

Client secret or certificate — which should I use?

Start with a client secret — two clicks in Entra, nothing on the filesystem, and the route the guides document. A certificate is stronger, because the credential never travels in a request body, and worth it if your security policy asks for it. Both are fully implemented on every platform; you can switch at any time from the settings page.

How do I rotate the client secret?

Create the new secret in Entra — the old one keeps working until expiry, so there is no outage window. Copy the new Value (not the Secret ID), paste it into Missivus's settings, save, send a test email, then delete the old secret. Missivus caches the access token briefly, never the secret, so nothing needs restarting.

What happens with attachments over 3 MB?

They send. Graph limits inline attachments to about 3 MB, so above that Missivus automatically switches to Graph's chunked upload path — create a draft, upload in chunks, send. The decision is per message and size-aware, on every platform. There is no setting for this, deliberately — a scheduled-report PDF must never fail on size.

Why do the guides ask for Mail.ReadWrite as well as Mail.Send?

Only for that large-attachment path — creating a draft and opening an upload session are not covered by Mail.Send. If you never send attachments over 3 MB, Mail.Send alone is enough; if one day you do, the failure is loud and names the missing permission. Both permissions are bounded by the same access policy, so Mail.ReadWrite grants nothing outside the one shared mailbox.

Is the application access policy really necessary?

Yes — treat it as part of the installation, not optional hardening. Without it, Mail.Send as an application permission lets the app send as any mailbox in your tenant. The policy narrows it to one. The guides include the verification commands, and ask you not to continue until the second test comes back Denied.

Will Missivus break my email if I install it and do nothing?

No, on any platform. Every Missivus product ships switched off — installing and activating it changes nothing until you explicitly enable Graph sending in its settings. Deactivating restores the platform's stock transport with nothing to clean up. The optional fallback to the platform's own mail path is also off by default — a failure you can see beats an email that quietly goes nowhere.

I got an AADSTS error code from Microsoft. What does it mean?

The usual suspects — AADSTS7000215 means the secret is wrong, almost always because the Secret ID was copied instead of the Value. AADSTS900023 is a wrong tenant ID. ErrorAccessDenied means the access policy doesn't cover the mailbox or admin consent was never granted. Each product's installation guide has the full table with fixes — and secrets are redacted before anything is logged, so the errors are safe to paste into an issue.

My Matomo runs in Docker and I can't drop files into plugins/. Can I upload the zip?

Yes, with one temporary setting change — enable_plugin_upload. It ships off because it lets any superuser upload PHP that Matomo executes, so the guide walks you through switching it on, uploading, activating, and — importantly — switching it straight back off. On WordPress and Nextcloud the normal plugin/app upload paths apply and nothing special is needed.

Does it work with other plugins and apps that send email?

Anything that sends through the platform's mail layer goes through Missivus — on Matomo that is Piwik\Mail, on WordPress wp_mail(), on Nextcloud the system mailer used by core and apps alike. A plugin that opens its own SMTP connection bypasses the platform's mail layer and is untouched.

Need more depth?

The installation guides, the security reviews and the issue trackers live in each product's repository.

The Missivus repositories on GitHub