MailFixIt

Microsoft routing or recipient rejection

Fix Outlook 550 5.4.1 relay access denied

Microsoft uses 5.4.1 for at least two distinct conditions: a server does not accept mail for the recipient domain, or the recipient address does not exist. Read the NDR text before assigning ownership.

Problem description

Common Microsoft forms include:

550 5.4.1 Relay Access Denied
550 5.4.1 Recipient address rejected: Access denied
Diagnostic availability: public DNS alone cannot distinguish accepted-domain, connector, tenant-provisioning, and recipient-directory state. This page intentionally has no DNS-check CTA.
Is this temporary or permanent?

The 550 reply is permanent for this attempt. Correct the recipient or routing configuration, then send a new message.

Choose the correct branch

Resolution steps

  1. Copy the complete NDR including the server that generated it.
  2. Verify the recipient through a trusted directory or owner.
  3. For owned domains, confirm accepted-domain and connector configuration.
  4. Compare public MX with the intended receiving platform.
  5. Retest only after the responsible setting changes.

Frequently asked questions

What does Microsoft 5.4.1 mean?

Microsoft documents both a relay/routing branch and an invalid-recipient branch, so the complete NDR wording determines the owner.

Is changing MX always the fix?

No. The recipient may not exist, or Microsoft/domain provisioning may be wrong. Confirm the branch first.

Why is there no checker CTA?

Public MX alone cannot determine connector, accepted-domain, tenant provisioning, or recipient-directory state.

Related email diagnostics

Primary sources: Microsoft Exchange Online NDR reference.