Outlook / Microsoft 365 email rejection
Fix Outlook 550 5.7.515 safely
An Outlook or Microsoft 365 rejection with 550 5.7.515 means the receiving service reported an authentication problem. It is a useful symptom, not proof that one particular SPF, DKIM or DMARC record is the only cause.
What to check first
- Confirm the sending domain. Check the public domain used by the sending service, rather than a website URL or a recipient address.
- Read the receiver report as context. MailFixIt recognizes the Outlook code and only exposes a safe, structured symptom—not the raw bounce text.
- Review SPF, DKIM and DMARC together. SPF authorizes the envelope sender, DKIM signs with a selector and signing domain, and DMARC checks alignment for the visible From domain.
- Use problem-message headers when available. The free check can extract reported SPF, DKIM and DMARC outcomes, DKIM selectors and safe domain identities from Authentication-Results, Return-Path and From. These observations are not independent verification of the message.
Common safe fixes
There is no universal record to paste for this error. The appropriate correction depends on the evidence:
- If the receiver reported
spf=fail, verify that the actual sending service and envelope domain are still authorized by the one selected SPF record. - If it reported
dkim=fail, use the DKIM selector and signing domain from the message to check the published public key and the sender's signing configuration. - If it reported
dmarc=fail, compare the visible From domain with the authenticated SPF and DKIM domains. A policy record alone does not make a message aligned. - If DNS looks correct but the symptom remains, the sending provider may need configuration changes. Public DNS cannot prove message signing, sending reputation or recipient-specific filtering.
What not to do
- Do not add a second SPF record; multiple selected SPF records create their own error.
- Do not remove existing SPF mechanisms until every legitimate sender is inventoried.
- Do not move DMARC directly to
p=rejectjust to clear one rejection. Verify aligned authentication first. - Do not treat a successful DNS check as a guarantee of inbox placement or delivery to every Outlook recipient.
Need a scoped application plan?
After a fresh check identifies a supported DNS warning or error, the one-time $5 Email Fix Pack can prepare a domain-specific plan. It includes records to preserve, a rollback path, three rechecks within seven days and an option to request assistance after granting temporary least-privilege DNS access.