Microsoft 365 forwarding policy rejection
Fix Outlook 550 5.7.520 external forwarding blocked
Microsoft returns 5.7.520 when Exchange Online blocks automatic forwarding to an external address under the tenant's outbound spam policy. The tenant administrator must assess and control the forwarding path.
The NDR reports:
550 5.7.520 Access denied, Your organization does not allow external forwarding. Please contact your administrator for further assistance. AS(7555)
The 550 response is permanent while the forwarding rule and tenant policy remain unchanged. Repeated retries do not resolve it.
Why Microsoft blocked the message
- A mailbox rule automatically forwards mail outside the organization.
- A transport rule or forwarding address creates an external route.
- The applicable outbound spam policy disables automatic forwarding.
- The forwarding behavior may look like account compromise or data exfiltration.
How to resolve it safely
- Record the affected mailbox, external destination, and complete NDR.
- Have an administrator inspect inbox rules, mailbox forwarding, and transport rules.
- Confirm the forwarding is authorized and the account is not compromised.
- Use an approved collaboration or shared-mailbox workflow when forwarding is unnecessary.
- If business-required, have the administrator apply the narrowest Microsoft 365 policy allowed by organizational security requirements.
Frequently asked questions
What does Microsoft 5.7.520 mean?
Exchange Online blocked automatic forwarding to an external recipient under the organization's outbound spam policy.
Can changing DNS fix external forwarding?
No. This decision is made by private Microsoft 365 tenant policy, not public SPF, DKIM, DMARC, or MX records.
Who can allow legitimate forwarding?
An authorized Microsoft 365 administrator must review the forwarding path, security risk, and applicable outbound spam policy.
Related email diagnostics
Primary source: Microsoft Exchange Online NDR reference.