Exclaimer incident
Client side signature fails to apply and the message 'Failed to acquire auth token' is displayed.
Exclaimer experienced a minor incident on May 28, 2026 affecting UK: Client Side: Signature Application - Office 365 and AU: Client-Side: Signature Application - Office 365 and 1 more component, lasting 1d 2h. The incident has been resolved; the full update timeline is below.
Affected components
Update timeline
- investigating May 28, 2026, 08:01 AM UTC
Engineers are aware of an issue impacting our ability to apply signatures to messages as they are composed, the message 'Failed to acquire auth token' is displayed. There is no impact to email delivery at this time, once the issue has been resolved signatures will start to be applied again. If you have our server-side offering configured, then you will find that signatures are applied to messages after they are sent. If you have any other issues, please contact our support team who will be happy to help
- identified May 28, 2026, 12:16 PM UTC
Our team have identified the issue and are actively working on a resolution. Further updates will follow once a fix has been identified.
- monitoring May 28, 2026, 02:17 PM UTC
Engineering has successfully tested and deployed a fix for the add-in to resolve this issue. We will continue to closely monitor the add-in’s performance following the release. Please note that the speed of adoption may vary depending on Outlook cache. If you are currently experiencing any further issues with Exclaimer, please contact our Support team for assistance.
- monitoring May 28, 2026, 04:04 PM UTC
We continue to see a reduction of errors as the new version rolls out and are monitoring its progress. Please note that the speed of adoption may vary depending on Outlook cache. If you are currently experiencing any further issues with Exclaimer, please contact our Support team for assistance.
- resolved May 29, 2026, 10:47 AM UTC
Microsoft have confirmed that the original issue impacting customers was the result of a server-side change that has since been reverted. Our telemetry also confirms that over 40% of customer requests are coming from the newly released version that similarly resolved customer issues prior to Microsoft's deployment reversal, this continues to roll out. We intend to leave this fix in place as it improves the add-ins resilience to possible authentication issues. If you are currently experiencing any further issues with Exclaimer, please contact our Support team for assistance.
- postmortem Jun 10, 2026, 05:46 PM UTC
Issue: Client side signature fails to apply and the message 'Failed to acquire auth token' is displayed. Incident Length: 10 Day\(s\) and 3 hour\(s\) Incident Date: 18/05/2026, 11:00 UTC - 28/05/2026, 14:05 UTC Incident Status: Resolved **Summary** When composing a new email, the Exclaimer add-in was unable to acquire an authentication token, resulting in signatures not being inserted and an error message being displayed for customers using Outlook for iOS. All other platforms, including Windows desktop, New Outlook, Mac, Web, and Android, were unaffected. Server-side signatures continued to apply normally for customers with that configuration. **Root Cause** The Exclaimer Outlook Add-in uses a Microsoft authentication flow designed for Office add-ins, which is intended to authenticate users silently in the background without any user interaction. Around 18 May, this silent authentication flow stopped working on Outlook for iOS. Following an investigation, Microsoft confirmed that a change on their side had caused the silent authentication failure, and that this change was subsequently rolled back. **Mitigation** On identifying where the authentication flow was failing, Exclaimer Engineers updated the Outlook Add-in \(v1.29.200\) to introduce a fallback path for when silent authentication cannot complete. Rather than surfacing an error, the add-in now prompts the user to sign in interactively, allowing authentication to complete and the signature to be applied, improving authentication flow resilience. This was deployed on 28 May and has been retained permanently as a resilience improvement. **Incident Timeline** 18/05, ~11:00 UTC - Silent authentication begins failing on Outlook for iOS. Customers start experiencing signature failures on this platform 18/05, 12:51 – Exclaimer releases a new version of the Exclaimer Add-in \(v1.27.200\) 21/05, 19:01 - First report of errors from the Add-in reaches Exclaimer Engineering. Investigation begins. 22/05, 07:26 Engineering confirmed a review of the latest Add-in release had been completed; no active indicators of the issue are present based on the changes made. 10:14 – Active theory was composed on the cause of the issue; code changes are then prepared by Engineering to be released the following week to prevent potential issues over the weekend. 26/05, 10:01 UTC - First code change deployed to improve logging and extend authentication timeouts. 12:10 – Add-in v.1.28.0 is released to the production channel of the Add-in. Review of impacted systems indicates no improvement. 27/05, 13:25 UTC - v.1.29.0 is deployed to both channels to surface more detail from the authentication failure on iOS. 28/05, 07:44 UTC - Severity escalated given customer impact and duration. 10:42 – Issue confirmed to only impact iOS, with other errors likely being unrelated. 11:03 – Internal investigation is prioritized to identify the cause. 11:30 - Internal reproduction of the issue achieved for the first time, enabling rapid iteration on a fix. 13:02 - The point of failure in the authentication flow fully identified, Exclaimer Engineers also identify development of a Fix and begin prioritizing a full release. 13:50 – Add-in version \(v1.29.200\) is prepared for release, awaiting confirmation of the resolution within the preview channel before being released to the production channel. 14:05 - Updated add-in \(v1.29.200\) verified in preview and released out to production channel. 14:31 - Customer confirmation of resolution is received 29/05, 08:10 UTC - Microsoft confirms that a change on their side caused the authentication failure and that it has been rolled back. Exclaimer Engineers agree to keep the changes applied based on this information at this time.