Email troubleshooting guides

Microsoft delivery errors, organized by problem

Troubleshoot Microsoft mail rejections involving routing, policy, authentication, and reputation.

Choose the article that matches the provider, record type, or exact error shown in your mail logs.

Outlook 451 4.7.500-699: Access denied, please try again laterResolve Microsoft 451 4.7.500-699 by keeping slow retries and investigating the changed IP volume or suspicious sending activity. Outlook 5.7.321: starttls-not-supported: Destination mail server must support TLS to receive mailFix Microsoft 365 5.7.321 when the destination SMTP server must support STARTTLS but does not advertise or negotiate it. Outlook 5.7.322: certificate-expired: Destination mail server's certificate is expiredFix Microsoft 365 5.7.322 when the destination mail server presents an expired SMTP TLS certificate. Outlook 550 5.4.1: Relay Access DeniedDiagnose Microsoft 365 550 5.4.1 relay access denied or recipient address rejected without assuming one DNS cause. Outlook 550 5.7.23: The message was rejected because of Sender Policy Framework violationDiagnose Outlook and Exchange Online 550 5.7.23 SPF violation using the actual sender IP, MAIL FROM domain and current SPF record. Outlook 550 5.7.25: Access denied, the sending IPv6 address must have a reverse DNS recordFix Microsoft 365 550 5.7.25 when an anonymous sending IPv6 address has no reverse DNS record. Outlook 550 5.7.506: Access Denied, Bad HELOFix Microsoft 365 and Outlook 550 5.7.506 by correcting the SMTP HELO or EHLO hostname and its DNS identity. Outlook 550 5.7.511: Access denied, banned senderResolve Microsoft 550 5.7.511 by securing the sending system, correcting abusive traffic, and using Microsoft's delisting process. Outlook 550 5.7.512: Access denied, message must be RFC 5322 section 3.6.2 compliantFix Microsoft 365 550 5.7.512 when a message lacks a valid RFC 5322 From address. Outlook 550 5.7.515: Access denied, sending domain does not meet the required authentication levelDiagnose Outlook 550 5.7.515 email rejection safely. Check SPF, DKIM and DMARC DNS, interpret the receiver report, and identify the next configuration step. Outlook 550 5.7.520: Your organization does not allow external forwardingResolve Microsoft 550 5.7.520 when an Exchange Online outbound spam policy blocks automatic external forwarding. Outlook 550 5.7.64: TenantAttribution; Relay Access DeniedFix Microsoft 365 550 5.7.64 by reviewing the inbound connector after an on-premises mail environment change. Outlook 550 5.7.750: Service unavailable. Client blocked from sending from unregistered domainsResolve Microsoft 550 5.7.750 by adding and validating every sending domain used by the Microsoft 365 tenant and investigating suspicious mail volume. Outlook 554 5.4.14: Hop count exceeded - possible mail loop ATTR34Fix Exchange Online 550 5.4.14 by tracing a routing loop across Microsoft 365, connectors, gateways, and on-premises Exchange. Fix Microsoft 365 550 5.7.367 relay rejectionFix Microsoft 365 error 550 5.7.367 by checking the relay pool, inbound SPF or DKIM results, connectors, and the downstream relay response. Outlook 5.7.325: certificate-host-mismatch: Remote certificate MUST have a common name or subject alternative name matching the hostname (DANE)Fix Outlook 5.7.325 by installing a certificate whose CN or SAN matches the recipient MX hostname on every destination SMTP server. Outlook 5.7.57: Client was not authenticated to send anonymous mail during MAIL FROMFix Microsoft 365 5.7.57 by configuring the application or device to use the approved authenticated submission or relay method. Outlook 550 5.7.323: tlsa-invalid: The domain failed DANE validationFix Outlook 550 5.7.323 by making the recipient MX certificate match its DNSSEC-authenticated TLSA record. Outlook 550 5.7.509: Access denied, sending domain does not pass DMARC verification and has a DMARC policy of rejectFix Outlook 550 5.7.509 by making an authorized sender pass aligned SPF or DKIM without weakening a valid DMARC reject policy.

Primary sources: Primary technical reference.

Check your email domain