Microsoft delivery troubleshooting
Outlook and Microsoft 365 errors, explained
Diagnose Outlook.com and Microsoft 365 SMTP rejections involving authentication, relay, routing, TLS and tenant policy.
Match the numeric code and Microsoft wording before changing DNS or connector settings.
Fix Outlook 451 4.7.500–699 access deniedResolve Microsoft 451 4.7.500–699 temporary restrictions after suspicious sending activity is detected.
Fix Outlook 5.7.321 STARTTLS not supportedFix Microsoft 365 5.7.321 when the destination SMTP server must support STARTTLS but does not advertise or negotiate it.
Fix Outlook 5.7.322 expired destination certificateFix Microsoft 365 5.7.322 when the destination mail server presents an expired SMTP TLS certificate.
Fix Outlook 5.7.323 DANE/TLSA validation failureFix Microsoft 365 5.7.323 when a destination domain's DNSSEC-authenticated TLSA record does not validate the SMTP certificate.
Fix Outlook 5.7.325 certificate hostname mismatchFix Microsoft 365 5.7.325 when a destination SMTP certificate name does not match the MX hostname required by DANE validation.
Fix Outlook 550 5.4.1 relay access deniedDiagnose Microsoft 365 550 5.4.1 relay access denied or recipient address rejected without assuming one DNS cause.
Fix Outlook 550 5.4.14 routing loop detectedFix Exchange Online 550 5.4.14 by tracing a routing loop across Microsoft 365, connectors, gateways, and on-premises Exchange.
Fix Outlook 550 5.7.25 IPv6 reverse DNSFix Microsoft 365 550 5.7.25 when an anonymous sending IPv6 address has no reverse DNS record.
Fix Outlook 550 5.7.367 relay rejectionFix Microsoft 365 550 5.7.367 by tracing SPF or DKIM authentication through forwarding and non-Microsoft gateways.
Fix Outlook 550 5.7.506 bad HELOFix Microsoft 365 and Outlook 550 5.7.506 by correcting the SMTP HELO or EHLO hostname and its DNS identity.
Fix Outlook 550 5.7.511 banned sender IPResolve Microsoft 550 5.7.511 by securing the sending system, correcting abusive traffic, and using Microsoft's delisting process.
Fix Outlook 550 5.7.512 invalid From headerFix Microsoft 365 550 5.7.512 when a message lacks a valid RFC 5322 From address.
Fix Outlook 550 5.7.520 external forwarding blockedResolve Microsoft 550 5.7.520 when an Exchange Online outbound spam policy blocks automatic external forwarding.
Fix Outlook 550 5.7.57 client not authenticatedFix Microsoft 365 550 5.7.57 when an application or device submits anonymous mail through smtp.office365.com.
Fix Outlook 550 5.7.64 TenantAttribution relay denialFix Microsoft 365 550 5.7.64 by reviewing the inbound connector after an on-premises mail environment change.
Fix Outlook 550 5.7.750 unregistered tenant domainResolve Microsoft 550 5.7.750 by adding and validating every sending domain used by the Microsoft 365 tenant and investigating suspicious mail volume.
Fix Outlook 550 5.7.23 SPF violationDiagnose Outlook and Exchange Online 550 5.7.23 SPF violation using the actual sender IP, MAIL FROM domain and current SPF record.
Fix Outlook 550 5.7.509 DMARC failureDiagnose Outlook and Exchange Online 550 5.7.509 when a sending domain fails DMARC and publishes p=reject. Check policy and authentication identities safely.
Fix Outlook 550 5.7.515 safelyDiagnose Outlook 550 5.7.515 email rejection safely. Check SPF, DKIM and DMARC DNS, interpret the receiver report, and identify the next configuration step.
Primary sources: Microsoft Exchange Online NDR reference.