MailFixIt

Microsoft temporary suspicious-activity restriction

Fix Outlook 451 4.7.500–699 access denied

Microsoft groups 4.7.500–699 as a temporary sending restriction after suspicious activity is detected. If activity is legitimate, Microsoft says the restriction is normally lifted shortly; investigate compromise before resuming volume.

Problem description

The response contains a code in the range:

451 4.7.500-699 Access denied, please try again later
Diagnostic availability: this is Microsoft provider state, not a public DNS verdict. MailFixIt cannot lift or validate the restriction.
Is this temporary or permanent?

The 451/4.x.x response is temporary. Use backoff and do not create aggressive retries.

Security review

Recovery sequence

  1. Preserve exact code, account, IP, and timestamps privately.
  2. Contain suspicious sending and rotate affected credentials.
  3. Remove malicious rules, tokens, and queued mail.
  4. Allow the temporary evaluation period with normal retry behavior.
  5. Contact Microsoft Support if restriction persists after remediation.

Frequently asked questions

What does Microsoft 4.7.500–699 mean?

Microsoft detected suspicious activity and temporarily restricted sending while it evaluates the activity.

Is 4.7.650 a separate current contract?

Microsoft's current NDR table documents the 4.7.500–699 range, so this page uses the range as the canonical intent rather than inventing subcode-specific meaning.

Can DNS remove the restriction?

No. Secure the sender and follow Microsoft account or support remediation; DNS checks cannot lift provider restrictions.

Related email diagnostics

Primary source: Microsoft Exchange Online NDR reference.