550 5.7.133 RESOLVER.RST.SenderNotAuthenticatedForGroup
Sample bounce line
Remote Server returned '550 5.7.133 RESOLVER.RST.SenderNotAuthenticatedForGroup; authentication required; Delivery restriction check failed because the sender was not authenticated when sending to this group'
What it means
The recipient is a group that only accepts mail from authenticated senders, and the sender was not authenticated. Microsoft's NDR table describes it as a group distribution list set up to reject messages from outside its organization.
Why it happens
- The recipient group is configured to reject messages from senders outside the organization.
- Hybrid: senders on-premises are not recognized as authenticated by Exchange Online (X-MS-Exchange-Organization-AuthAs header is 'anonymous'), for example because of Send connector, address space, or certificate settings.
- Hybrid with centralized mail transport: external senders' mail is rejected for Microsoft 365 Groups even if the group accepts external senders. Microsoft says centralized mail transport isn't supported for Microsoft 365 Groups in hybrid.
How to fix it
- Only the group owner or an email admin in the recipient's organization can fix this.
- Method 1: in the Exchange admin center (Recipients > Groups > group > Settings > Edit delivery management), choose 'Allow messages from people inside and outside my organization' and save.
- Method 2: choose the same option and add the specific senders under 'Specified senders'. External senders must first exist as a mail contact or mail user.
- Hybrid senders: check the X-MS-Exchange-Organization-AuthAs header. If 'anonymous', verify the 'Outbound to Office 365' Send connector, that the group's address space is listed, the TLSCertificateName setting, and the inbound connector's CloudServicesMailEnabled and TLSSenderCertificateName settings.
Check your domain now
Many of these errors come from missing or broken SPF, DKIM, DMARC or reverse DNS records. Enter your domain to run the free check.
Related errors
No related errors listed yet.
Official documentation
- https://learn.microsoft.com/en-us/troubleshoot/exchange/email-delivery/microsoft-365-group-email-delivery-fails
- https://learn.microsoft.com/en-us/troubleshoot/exchange/email-delivery/ndr/fix-error-code-5-7-133-in-exchange-online
- https://learn.microsoft.com/en-us/exchange/mail-flow-best-practices/non-delivery-reports-in-exchange-online/non-delivery-reports-in-exchange-online