Tools

550 5.4.1 Recipient address rejected: Access denied

Provider: Microsoft 365 / Outlook

Sample bounce line

550 5.4.1 Recipient address rejected: Access denied

What it means

Directory-based edge blocking in Exchange Online rejected the message because the recipient's email address is invalid (it doesn't exist in the recipient organization's Exchange Online directory).

Why it happens

How to fix it

  1. Sender: check the spelling of the recipient's address in the NDR.
  2. Admin: determine whether one recipient or every recipient in the domain is affected.
  3. Domain-wide: in the Exchange admin center (Mail flow > Accepted domains), switch the domain from Authoritative to Internal relay and back to Authoritative.
  4. Hybrid on-premises mailbox: reset the recipient's SMTP proxy address (change to a temporary address and revert). Allow up to 24 hours for directory-based edge blocking to update.
  5. Hybrid mail-enabled public folder: sync it with the Sync-ModernMailPublicFolder script.
  6. Hybrid dynamic distribution group: create a mail contact in Exchange Online with the same external address.
  7. During a migration, leave the accepted domain as Internal relay until all recipients are added and synced, then set it to Authoritative.

Check your domain now

Many of these errors come from missing or broken SPF, DKIM, DMARC or reverse DNS records. Enter your domain to run the free check.

Check your domain now

Related errors

Official documentation

Paste another bounce message · All errors