5.7.1 Unable to relay
Sample bounce line
550 5.7.1 Unable to relay; mail.contoso.com #<mail.contoso.com #5.7.1 smtp;550 5.7.1 Unable to relay> #SMTP#
What it means
The receiving system is not the final destination for this recipient and will not pass the message on for an unauthenticated sender. Microsoft's own explanation is that the sending system tried to relay through a server that does not accept mail for that domain.
Why it happens
- An MX record pointing at a host that is not configured to accept that domain, so the host is asked to relay for a domain it does not own.
- A device or application relaying through a server without the permission to do so, typically after an authentication setting changed.
- A third party attempting to use the server to send spam, in which case the bounce you received may be the result of a forged sender address and nothing of yours is wrong.
- A domain removed from the tenant or connector while mail is still being addressed to it.
How to fix it
- Check the MX records for the recipient domain and confirm they point at a system that accepts that domain.
- If this is your own device or application, authenticate it, or give the connector the permission to relay for it.
- Confirm the domain is still accepted by the receiving organisation and present in its connector or accepted-domain list.
- If the sender address in the bounce is not yours, treat it as a forged-sender bounce and ignore it.
Check your domain now
Many of these errors come from missing or broken SPF, DKIM, DMARC or reverse DNS records. Enter your domain to run the free check.