5.7.511 Access denied, banned sender
Sample bounce line
550 5.7.511 Access denied, banned sender [203.0.113.10]
What it means
Microsoft has banned the IP address the message was sent from. Its published remedy is to ask for delisting by email to [email protected], quoting the full NDR code and the IP address.
Why it happens
- Spam or malware sent from that address, often by a compromised account or device rather than deliberately.
- An address inherited from a previous tenant with a poor history, which is a known risk of cheap cloud IP ranges.
- A misconfigured relay that allowed third parties to send through it.
- A sudden volume spike from an address with no sending history.
How to fix it
- Find and fix the cause before asking for delisting: a relisting after an unresolved compromise is worse than the first ban.
- Email [email protected] with the full NDR code and the IP address exactly as the bounce shows them.
- Close the relay, reset the credentials of any compromised account, and check for a device sending without your knowledge.
- Publish SPF, DKIM and DMARC for the domain and warm the address up gradually afterwards.
DNS record examples (replace example.com and the values with your own):
example.com. IN TXT "v=spf1 include:_spf.your-mail-provider.example ~all" ; exactly one SPF record per domain; the include value comes from your provider
_dmarc.example.com. IN TXT "v=DMARC1; p=none; rua=mailto:[email protected]" ; start at p=none, tighten only after the reports look clean
Check your domain now
Many of these errors come from missing or broken SPF, DKIM, DMARC or reverse DNS records. Enter your domain to run the free check.
Related errors
- 550 5.7.606-649 Access denied, banned sending IP [IP address]
- 550 5.7.708 Access denied, traffic not accepted from this IP