5.7.12 Sender was not authenticated by organization
Sample bounce line
550 5.7.12 Sender was not authenticated by organization
What it means
The recipient's address is configured to refuse mail from outside its own organisation, so an external sender is rejected whatever the message says. Microsoft is explicit that only an email administrator in the recipient's organisation can change this.
Why it happens
- The recipient mailbox or group has the require-sender-authentication setting switched on.
- An address intended for internal notifications only, which was shared outside by mistake.
- A distribution group restricted to members, where the sender is not a member.
- A migration that re-created the recipient with its default restriction in place.
How to fix it
- As the sender, there is nothing to fix at your end: tell the recipient their address is refusing external mail and ask them to raise it with their administrator.
- Ask for a different address, or to be added to the group's allowed senders.
- If the recipient is in your own organisation, turn off the require-sender-authentication setting on that mailbox or group.
- Do not retry from a different address of your own: the restriction is about external senders in general, not about you.
Check your domain now
Many of these errors come from missing or broken SPF, DKIM, DMARC or reverse DNS records. Enter your domain to run the free check.
Related errors
- 550 5.7.133 RESOLVER.RST.SenderNotAuthenticatedForGroup
- 550 5.4.1 Recipient address rejected: Access denied