Microsoft temporary suspicious-activity restriction
Fix Outlook 451 4.7.500–699 access denied
Microsoft groups 4.7.500–699 as a temporary sending restriction after suspicious activity is detected. If activity is legitimate, Microsoft says the restriction is normally lifted shortly; investigate compromise before resuming volume.
The response contains a code in the range:
451 4.7.500-699 Access denied, please try again later
The 451/4.x.x response is temporary. Use backoff and do not create aggressive retries.
Security review
- Unexpected sign-ins, OAuth grants, API tokens, or mailbox rules.
- Compromised applications or SMTP credentials.
- Sudden recipient or volume changes.
- Open relay, malicious queue, or unauthorized campaign.
Recovery sequence
- Preserve exact code, account, IP, and timestamps privately.
- Contain suspicious sending and rotate affected credentials.
- Remove malicious rules, tokens, and queued mail.
- Allow the temporary evaluation period with normal retry behavior.
- Contact Microsoft Support if restriction persists after remediation.
Frequently asked questions
What does Microsoft 4.7.500–699 mean?
Microsoft detected suspicious activity and temporarily restricted sending while it evaluates the activity.
Is 4.7.650 a separate current contract?
Microsoft's current NDR table documents the 4.7.500–699 range, so this page uses the range as the canonical intent rather than inventing subcode-specific meaning.
Can DNS remove the restriction?
No. Secure the sender and follow Microsoft account or support remediation; DNS checks cannot lift provider restrictions.
Related email diagnostics
Primary source: Microsoft Exchange Online NDR reference.