Microsoft 365 tenant domain rejection
Fix Outlook 550 5.7.750 unregistered tenant domain
Microsoft uses 5.7.750 when a Microsoft 365 tenant sends suspicious volume from one or more domains that are not provisioned in that tenant. “Unregistered” here means not added and validated in Microsoft 365—not missing at a domain registrar.
The NDR reports:
550 5.7.750 Service unavailable. Client blocked from sending from unregistered domains
The 550 response is permanent while the tenant remains blocked or uses an unprovisioned sending domain. Retrying unchanged messages will continue to fail.
What to investigate
- Every RFC 5322 From and envelope sender domain used by the tenant.
- Domains used by applications, connectors, relays, and delegated senders.
- Whether each legitimate domain is added and validated in Microsoft 365.
- Compromised accounts, applications, tokens, or unexpected outbound volume.
How to resolve it
- Capture the complete NDR, tenant, sender, and message trace.
- Stop suspicious traffic and secure compromised identities or applications.
- Add every legitimate sending domain to Microsoft 365 as an accepted domain.
- Complete Microsoft's domain-ownership validation workflow.
- Follow Microsoft's current support or unblock route after remediation.
- Resume legitimate traffic gradually and monitor all sending domains.
Frequently asked questions
What does Microsoft 5.7.750 mean?
Microsoft blocked a tenant that sent suspicious volume from domains not provisioned in Microsoft 365.
Does unregistered mean the domain is not registered at a registrar?
No. In this error, Microsoft means the sending domain is not added and validated in the Microsoft 365 tenant.
Will adding a DNS record alone remove the block?
No. An administrator must add and validate the domain through Microsoft 365 and investigate the suspicious sending activity that triggered enforcement.
Related email diagnostics
Primary source: Microsoft Exchange Online NDR reference.