5.1.8 Access denied, bad outbound sender
Sample bounce line
550 5.1.8 Access denied, bad outbound sender
What it means
Microsoft blocked the sending account for sending too much spam. Its published explanation is that this typically happens because the account was compromised through phishing or malware, so the first question is not about deliverability but about whether the account is still yours.
Why it happens
- A compromised mailbox being used to send spam, which is the cause Microsoft names first.
- A legitimate bulk send from a normal user mailbox that tripped the outbound spam policy.
- An application using a user mailbox to send large volumes of notifications.
- A forwarding rule quietly added by an attacker, relaying mail out through the account.
How to fix it
- Treat it as a security incident first: reset the password, revoke sessions, and look for mail rules and forwarding you did not create.
- Check the restricted-users list in the security portal and remove the account once the cause is fixed.
- Move bulk or application mail off user mailboxes and onto a service built for it.
- Turn on multi-factor authentication for the account before putting it back to work.
Check your domain now
Many of these errors come from missing or broken SPF, DKIM, DMARC or reverse DNS records. Enter your domain to run the free check.