# Hivemq mqtt\_client: MQTT connect failed

**URL:** <https://community.hivemq.com/t/hivemq-mqtt-client-mqtt-connect-failed/3944>\
**Category:** MQTT\
**Created:** [November 8, 2025, 10:44am UTC](https://community.hivemq.com/t/hivemq-mqtt-client-mqtt-connect-failed/3944 "2025-11-08T10:44:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![misupora](https://avatars.discourse-cdn.com/v4/letter/m/858c86/32.png) [@misupora](https://community.hivemq.com/u/misupora)\
**Post date:** [November 8, 2025, 10:44am UTC](https://community.hivemq.com/t/hivemq-mqtt-client-mqtt-connect-failed/3944/1 "2025-11-08T10:44:07Z")

</div>

I have implemented an esp32 project to connect to a the HiveMQ broker via MQTT. However I constantly receive the message:  
mqtt\_client: Connection refused, not authorized  
mqtt\_client: MQTT connect failed

I have set the CA certificate to ISGR Root X1 as it is instrcuted by the HiveMQ Team members in these posts:

> [@Configuring TLS encryption](https://community.hivemq.com/t/configuring-tls-encryption/3297):
>
> I’m developing a new product around an Espressif ESP32-C3 module, configured with ESP-AT firmware. The ESP-AT manual says that the command AT+MQTTUSERCFG=0,2,… configures a link using MQTT over TLS (no certificate verify). HiveMQ documentation says that using port 8883 set TLS. Can I be sure that using both these does force all messages to be encrypted?

I have also followed the example on

> **[GitHub - espressif/esp-aws-iot: AWS IoT SDK for ESP32 based chipsets](https://github.com/espressif/esp-aws-iot)**
>
> AWS IoT SDK for ESP32 based chipsets

I m sending below my repo

> **[GitHub - MichalPorazko/esp](https://github.com/MichalPorazko/esp)**
>
> Contribute to MichalPorazko/esp development by creating an account on GitHub.

---

<div class="post-metadata">

**Author:** ![Daria\_H](https://avatars.discourse-cdn.com/v4/letter/d/dfb087/32.png) [@Daria\_H](https://community.hivemq.com/u/Daria_H)\
**Post date:** [November 11, 2025, 4:20pm UTC](https://community.hivemq.com/t/hivemq-mqtt-client-mqtt-connect-failed/3944/2 "2025-11-11T16:20:17Z")

</div>

Hi @misupora great to see you join. If you’re experimenting or just beginning with HiveMQ, feel free to share your thoughts and questions.

Typically users have this error when the IoT device does not support TLS-SNI (server name indication). Please verify your device as explained here:

> **[How do I test locally if my IoT device has TLS-SNI? - HiveMQ Knowledge Base -...](https://hivemq.atlassian.net/wiki/spaces/HCSP/pages/2967863346/How+do+I+test+locally+if+my+IoT+device+has+TLS-SNI)**

Best,  
Dasha from HiveMQ Team

---

<div class="post-metadata">

**Author:** ![misupora](https://avatars.discourse-cdn.com/v4/letter/m/858c86/32.png) [@misupora](https://community.hivemq.com/u/misupora)\
**Post date:** [November 23, 2025, 12:22pm UTC](https://community.hivemq.com/t/hivemq-mqtt-client-mqtt-connect-failed/3944/3 "2025-11-23T12:22:30Z")

</div>

Dear Dasha,

thank you for your response,  
I have performed the test according to the tutorial you have sent and my results were

`ACCEPT`  
`Received Record`  
`Header:`  
`Version = TLS 1.2 (0x303)`  
`Content Type = Handshake (22)`  
`Length = 245`  
`ClientHello, Length=241`  
`client_version=0x303 (TLS 1.2)`

and

```auto

extensions, length = 82
extension_type=server_name(0), length=22
0000 - 00 14 00 00 11 37 2e 74-63 70 2e 65 75 2e 6e …7.tcp.eu.n
000f - 67 72 6f 6b 2e 69 6f grok.io

```

that means that my ESP32 support TLS-SNI

I have also followed the tutorial:

> **[How To Generate Client Certificates for TLS Clients - HiveMQ Knowledge Base -...](https://hivemq.atlassian.net/wiki/spaces/HCSP/pages/3246292994/How+To+Generate+Client+Certificates+for+TLS+Clients)**

> **[Hivemq mqtt\_client: MQTT connect failed](https://community.platformio.org/t/hivemq-mqtt-client-mqtt-connect-failed/53033/3)**
>
> I have tried both configurations: mqtt\_cfg.broker.address.port = MQTT\_PORT; mqtt\_cfg.broker.address.transport = MQTT\_TRANSPORT\_OVER\_SSL; mqtt\_cfg.broker.address.hostname = MQTT\_HOST; mqtt\_cfg.broker.address.uri = MQTT\_BROKER\_URI; In...

I constantly receive:

esp-tls: couldn’t get hostname for :xxxxx.s1.eu.hivemq.cloud: getaddrinfo() returns 202, addrinfo=0x0

my broker uri is:  
“mqtts://xxxxxx.s1.eu.hivemq.cloud:8883”

---

<div class="post-metadata">

**Author:** ![Daria\_H](https://avatars.discourse-cdn.com/v4/letter/d/dfb087/32.png) [@Daria\_H](https://community.hivemq.com/u/Daria_H)\
**Post date:** [November 24, 2025, 11:34am UTC](https://community.hivemq.com/t/hivemq-mqtt-client-mqtt-connect-failed/3944/4 "2025-11-24T11:34:39Z")

</div>

Hi @misupora

Thank you for the detailed follow-up and for performing the TLS-SNI verification. It is great to see that your client supports TLS-SNI.

At this stage, it would be helpful to determine whether the issue is specific to resolving the hostname for your HiveMQ Cloud instance (`xxxxxx.s1.eu.hivemq.cloud`) or whether it is a more general DNS resolution issue on the device.

As a next step, could you please test the same client against another public MQTT broker, for example:

**[test.mosquitto.org:8883](http://test.mosquitto.org:8883)**  
(Server certificate: [https://test.mosquitto.org/ssl/mosquitto.org.crt](https://test.mosquitto.org/ssl/mosquitto.org.crt))

If your device is able to successfully resolve and connect to `test.mosquitto.org` but continues to fail with the HiveMQ Cloud hostname, this would indicate that the issue is related to the HiveMQ Cloud endpoint.  
However, if the client is unable to resolve `test.mosquitto.org` as well, then the problem is likely related to your Wi-Fi network’s DNS configuration.

Please let us know the results of this test so we can assist you further.

Best regards,  
Dasha from HiveMQ Team
