Missivus for Nextcloud
Everything Nextcloud sends — password resets, share notifications, activity digests, admin alerts — delivered through Microsoft Graph as one free shared mailbox. No SMTP, no user login, no separate relay daemon to run.
SMTP AUTH basic authentication is disabled by default for Microsoft 365 tenants from the end of December 2026, and unavailable by default for new tenants after that; final removal will be announced for late 2027. Nextcloud's outgoing-mail settings speak only SMTP or sendmail. Updated timeline (January 2026)
What it does
Every email Nextcloud produces
Missivus replaces Nextcloud's system mailer with a decorator that talks to the Graph API directly — core mail and every app that uses Nextcloud's mailer, with nothing to switch over app by app.
One mailbox, enforced by Exchange
Designed around an application access policy scoped to a single free shared mailbox. Even a fully leaked credential can send as exactly one no-reply address — and the install guide treats that step as first-class, with a command to verify it took effect.
Large attachments handled
Files under Graph's ~3 MB inline ceiling go inline; anything larger is uploaded through a Graph upload session automatically. There is no setting that can get this wrong.
Secret or certificate
A client secret is the quickest way in and is the default; certificate authentication is supported as optional hardening. Tokens are cached in Nextcloud's distributed cache with a safety margin.
Secrets can stay out of the database
Every value can come from a missivus array in config.php, which then wins over the settings UI — a file-managed secret never touches the database, and stored secrets are write-only sensitive values.
Fails loudly, never silently
Ships switched off. Every Graph failure is logged at error level and shown on the settings page — never swallowed. A test-email button, occ missivus:test and occ missivus:status prove the chain end to end. The fallback to Nextcloud's own mailer is off by default.
Application permissions, not a delegated login
The usual Microsoft 365 mail routes make a person's account the sender — a human signs in and stays signed in. That is the wrong shape for a server.
| Missivus — application permission | Delegated mailers | |
|---|---|---|
| Who sends | The application itself, as a free shared mailbox | A person's account, connected by clicking "Sign in" |
| Setup | Admin creates an app registration once | A human logs in and stays logged in |
| Someone leaves the company | Nothing happens | Mail breaks |
| Blast radius if the credential leaks | One mailbox, enforced by Exchange | Whatever that person can do |
| Extra services | None | Sometimes an SMTP relay in between |
Requirements
- Nextcloud 33 or 34 (self-hosted), PHP 8.2 or later — no Composer dependencies, no SDK, no third-party runtime code
- A Microsoft 365 tenant and an administrator who can create an app registration, grant admin consent and run one Exchange Online PowerShell command
- A shared mailbox to send from — it needs no licence
- About thirty minutes for the one-time Microsoft setup
Get the app
Download from GitHub
Release tarball in App Store layout, source, changelog and issue tracker.
Nextcloud App Store
The listing in the Nextcloud App Store is in preparation — until it is live, install from the GitHub release tarball.
Two ways to get it running
Install it yourself
The installation guide is written for someone who has never opened Microsoft Entra — every click spelled out. Budget half an hour for the Microsoft side.
Have Solvetus install it
One appointment — Entra app, access policy, mailbox, app install, test email, handover document. The software stays free; you pay for the hour, not the tool.