MailFixIt

Microsoft 365 tenant domain rejection

Fix Outlook 550 5.7.750 unregistered tenant domain

Microsoft uses 5.7.750 when a Microsoft 365 tenant sends suspicious volume from one or more domains that are not provisioned in that tenant. “Unregistered” here means not added and validated in Microsoft 365—not missing at a domain registrar.

Problem description

The NDR reports:

550 5.7.750 Service unavailable. Client blocked from sending from unregistered domains
Diagnostic availability: public DNS can participate in Microsoft domain validation, but it cannot reveal tenant provisioning or the security block. This page intentionally has no automated checker or Fix Pack CTA.
Is this temporary or permanent?

The 550 response is permanent while the tenant remains blocked or uses an unprovisioned sending domain. Retrying unchanged messages will continue to fail.

What to investigate

How to resolve it

  1. Capture the complete NDR, tenant, sender, and message trace.
  2. Stop suspicious traffic and secure compromised identities or applications.
  3. Add every legitimate sending domain to Microsoft 365 as an accepted domain.
  4. Complete Microsoft's domain-ownership validation workflow.
  5. Follow Microsoft's current support or unblock route after remediation.
  6. Resume legitimate traffic gradually and monitor all sending domains.

Frequently asked questions

What does Microsoft 5.7.750 mean?

Microsoft blocked a tenant that sent suspicious volume from domains not provisioned in Microsoft 365.

Does unregistered mean the domain is not registered at a registrar?

No. In this error, Microsoft means the sending domain is not added and validated in the Microsoft 365 tenant.

Will adding a DNS record alone remove the block?

No. An administrator must add and validate the domain through Microsoft 365 and investigate the suspicious sending activity that triggered enforcement.

Related email diagnostics

Primary source: Microsoft Exchange Online NDR reference.