554 5.7.1 Relay access denied
Sample bounce line
554 5.7.1 <[email protected]>: Relay access denied
What it means
The server refused to relay the message. The sender or client is not authorized to send to that destination, which RFC 3463 defines as X.7.1 (Delivery not authorized, message refused) and marks as useful only as a permanent error. RFC 5321 section 3.6.2 says a server that declines to relay for policy reasons SHOULD return 550; 554 with 'Relay access denied' is Postfix's wording and reply.
Why it happens
- The client is neither in mynetworks nor SASL-authenticated, and the recipient domain is not one the server accepts mail for
- An upgraded Postfix with the newer default smtpd_relay_restrictions rejects clients that lack permit_mynetworks or permit_sasl_authenticated (COMPATIBILITY_README)
- A virtual alias domain missing its 'virtual-alias.domain anything' entry (virtual(5): without it, mail is rejected with 'relay access denied')
How to fix it
- Sender: enable SMTP authentication and use the provider's submission settings instead of sending unauthenticated on port 25
- Postfix admin: allow your clients with permit_mynetworks and/or permit_sasl_authenticated before reject_unauth_destination, for example smtpd_relay_restrictions = permit_mynetworks, permit_sasl_authenticated, reject_unauth_destination (Dovecot SASL howto)
- For virtual alias domains, add the required 'virtual-alias.domain anything' entry and do not list the domain in mydestination or relay_domains (virtual(5))
Check your domain now
Many of these errors come from missing or broken SPF, DKIM, DMARC or reverse DNS records. Enter your domain to run the free check.
Related errors
No related errors listed yet.