Microsoft routing or recipient rejection
Fix Outlook 550 5.4.1 relay access denied
Microsoft uses 5.4.1 for at least two distinct conditions: a server does not accept mail for the recipient domain, or the recipient address does not exist. Read the NDR text before assigning ownership.
Common Microsoft forms include:
550 5.4.1 Relay Access Denied 550 5.4.1 Recipient address rejected: Access denied
The 550 reply is permanent for this attempt. Correct the recipient or routing configuration, then send a new message.
Choose the correct branch
- Relay Access Denied: verify accepted domains, tenant provisioning, connectors, and where MX delivers.
- Recipient rejected: verify the exact address, aliases, synchronization, and directory state.
- Recent DNS move: ensure old and new systems are not splitting responsibility.
Resolution steps
- Copy the complete NDR including the server that generated it.
- Verify the recipient through a trusted directory or owner.
- For owned domains, confirm accepted-domain and connector configuration.
- Compare public MX with the intended receiving platform.
- Retest only after the responsible setting changes.
Frequently asked questions
What does Microsoft 5.4.1 mean?
Microsoft documents both a relay/routing branch and an invalid-recipient branch, so the complete NDR wording determines the owner.
Is changing MX always the fix?
No. The recipient may not exist, or Microsoft/domain provisioning may be wrong. Confirm the branch first.
Why is there no checker CTA?
Public MX alone cannot determine connector, accepted-domain, tenant provisioning, or recipient-directory state.
Related email diagnostics
Primary sources: Microsoft Exchange Online NDR reference.