MailFixIt

Microsoft 365 forwarding policy rejection

Fix Outlook 550 5.7.520 external forwarding blocked

Microsoft returns 5.7.520 when Exchange Online blocks automatic forwarding to an external address under the tenant's outbound spam policy. The tenant administrator must assess and control the forwarding path.

Problem description

The NDR reports:

550 5.7.520 Access denied, Your organization does not allow external forwarding. Please contact your administrator for further assistance. AS(7555)
Diagnostic availability: MailFixIt cannot inspect private inbox rules, transport rules, or Microsoft 365 outbound spam policies. This page intentionally has no DNS or Fix Pack CTA.
Is this temporary or permanent?

The 550 response is permanent while the forwarding rule and tenant policy remain unchanged. Repeated retries do not resolve it.

Why Microsoft blocked the message

How to resolve it safely

  1. Record the affected mailbox, external destination, and complete NDR.
  2. Have an administrator inspect inbox rules, mailbox forwarding, and transport rules.
  3. Confirm the forwarding is authorized and the account is not compromised.
  4. Use an approved collaboration or shared-mailbox workflow when forwarding is unnecessary.
  5. If business-required, have the administrator apply the narrowest Microsoft 365 policy allowed by organizational security requirements.

Frequently asked questions

What does Microsoft 5.7.520 mean?

Exchange Online blocked automatic forwarding to an external recipient under the organization's outbound spam policy.

Can changing DNS fix external forwarding?

No. This decision is made by private Microsoft 365 tenant policy, not public SPF, DKIM, DMARC, or MX records.

Who can allow legitimate forwarding?

An authorized Microsoft 365 administrator must review the forwarding path, security risk, and applicable outbound spam policy.

Related email diagnostics

Primary source: Microsoft Exchange Online NDR reference.