← Back to Blog
IT Support

Email Bounced With 550 5.7.1? NDR Codes Explained

3 October 2026 · By Ethan Fernandes

Email Bounced With 550 5.7.1? NDR Codes Explained

Got a bounce saying "550 5.7.1", "5.1.1 recipient not found", "5.7.708 access denied" or "5.7.520"? Here's what each Microsoft 365 error means and the fix.

You send an important email and seconds later get a reply from Microsoft Outlook saying "Your message to … couldn't be delivered" or "Delivery has failed to these recipients or groups". Somewhere in the technical details is a code such as 550 5.7.1, 550 5.1.1, 5.7.520, 5.7.708 or 5.4.1 Recipient address rejected: Access denied.

These bounce messages are called NDRs (non-delivery reports). The code tells you exactly what went wrong, if you know how to read it. Here's a plain-English guide to the ones small businesses see most.

Quick answer

Look for the three-part code in the bounce, such as 5.1.1 or 5.7.1. Codes starting 5.1 mean the address is wrong or doesn't exist, 5.7 means a policy or permission blocked the message, and 5.2 means the mailbox is full or the message too big. Also check which server rejected it: your own Microsoft 365 or the recipient's system.

Why This Happens

An NDR code has three parts. The first digit is 5 for a permanent failure (don't just resend) or 4 for a temporary delay. The second is the category: 1 addressing, 2 mailbox, 4 routing, 7 security or policy. The last part gives the detail.

Just as important is who rejected it. In the bounce, look for the "Remote server" or "Generating server" line. If it ends in outlook.com or protection.outlook.com and the recipient is also on Microsoft 365, read carefully: it could be their tenant or yours.

550 5.1.1 and 5.1.10: Recipient Not Found

The address doesn't exist. Usually a typo, a person who has left, or an old address saved in Outlook's autocomplete.

  • Check the spelling, particularly the domain (.co.uk vs .com).
  • Start typing the name in a new email, hover over the suggestion and click the X to delete the cached entry, then type the address fresh.
  • If it's an internal colleague, your admin should check the mailbox still exists and hasn't been renamed.

550 5.4.1 Recipient Address Rejected: Access Denied

The recipient's Microsoft 365 tenant rejected the message because that address doesn't exist in their directory. It's effectively "recipient not found" from the other side. Confirm the address with the recipient by phone. If it's your own domain, your admin should check the address exists as a mailbox, group or alias.

550 5.7.1: Delivery Not Authorised

The most common 5.7 bounce, with several variants:

  • "Delivery not authorized, message refused" or "You do not have permission to send to this recipient": the recipient's mailbox or group only accepts mail from certain senders. Ask the recipient to allow you, or use a different address.
  • "Client was not authenticated to send anonymous mail": usually a scanner, printer or app trying to send through Microsoft 365 without signing in correctly. Your admin needs to fix the device's SMTP settings.
  • Rejections mentioning SPF, DMARC or 5.7.23 / 5.7.26: the recipient's server didn't trust that the email came from your domain. See fixing email authentication.

5.7.133 and Similar: Group Doesn't Accept External Mail

If you're emailing a Microsoft 365 group or distribution list, it may be set to accept mail only from people inside the organisation. If it's your group, the admin can allow external senders in the group's settings in the Microsoft 365 admin centre or Exchange admin centre.

550 5.7.520: Access Denied, External Forwarding Not Allowed

This one confuses people. The full text reads "Access denied, Your organization does not allow external forwarding". It means a mailbox in your organisation tried to automatically forward email to an outside address and Microsoft 365's outbound spam policy blocked it. That's the default, because attackers use forwarding rules to steal email.

  • If you didn't set up forwarding, treat it as a possible compromise. Check inbox rules and forwarding straight away. See what to do if an account is hacked.
  • If forwarding is genuinely needed, your admin can create a separate outbound spam policy in Microsoft Defender that allows automatic forwarding for that specific user only. Don't open it up for everyone.

550 5.1.8 Access Denied, Bad Outbound Sender

Microsoft has blocked your account from sending because it detected spam coming from it. This almost always means the account was compromised. Secure the account first, then an admin can release it from the Restricted entities page in the Microsoft Defender portal. Our guide to a hacked account sending spam walks through it.

550 5.7.708 Access Denied, Traffic Not Accepted From This IP

Microsoft is refusing to relay mail from your tenant, usually because it's new, has low reputation, or has recently sent spam. Microsoft routes such tenants through a higher-risk pool or blocks them. There's no setting to change: make sure accounts are secure and authenticated, then your admin should raise a support request with Microsoft from the Microsoft 365 admin centre.

5.7.606 to 5.7.649: Banned Sending IP

If you're sending to a Microsoft 365 or Outlook.com recipient from your own mail server or a third-party service, and its IP is on Microsoft's blocklist, you'll see these codes. Microsoft's delist portal at sender.office.com lets you request removal once the cause is fixed.

Mailbox and Size Problems

  • 5.2.2 mailbox full: the recipient's mailbox is over quota. Tell them by phone or try later.
  • 5.2.3 or 5.3.4 message too large: send a OneDrive or SharePoint link instead of a big attachment.
  • 4.4.7 message expired: a temporary failure that ran out of retries, often a problem with the recipient's server.

For Your Microsoft 365 Admin

  • Use message trace in the Exchange admin centre (look under Mail flow) to see exactly where a message stopped and why.
  • For restricted users, check the Restricted entities page in Defender, or use Get-BlockedSenderAddress in Exchange Online PowerShell.
  • Review outbound spam policy settings for automatic forwarding in Defender's threat policies.

How to Stop It Happening Again

Most repeat bounces come from three things: weak email authentication, compromised accounts and poorly configured devices or apps that send email. Proper SPF, DKIM and DMARC, MFA on every account, and a modern method for scanners and apps to send email remove the majority of them. Regular checks of outbound forwarding and restricted users catch problems before clients notice.

When to Call in Help

If bounces are affecting everyone, involve 5.1.8 or 5.7.708, or you're not sure whether an account has been compromised, get help quickly. Our IT support team can trace and fix mail flow problems, and our managed IT service monitors them for you. Contact us for help.

Common questions

It means a security or permission policy blocked the message. Common reasons are that the recipient only accepts mail from approved senders, or your domain failed the recipient's authentication checks.

The email address doesn't exist on the recipient's system. Check the spelling and delete any old autocomplete entry in Outlook before typing the address again.

It means automatic forwarding to an external address was blocked by your outbound spam policy. If nobody set up the forwarding, check for a compromised account. If it's legitimate, an admin can allow forwarding for that user only.

Microsoft blocks accounts that appear to be sending spam, usually because they've been compromised. Secure the account first, then an admin can unblock it from the Restricted entities page in Microsoft Defender.

Want to talk about this?

Book a free 15-minute call and we'll discuss how this applies to your business.

Get IT tips in your inbox

Practical advice for small businesses. No spam.