Tools

550 5.7.509 Access denied, sending domain [sender domain] does not pass DMARC verification and has a DMARC policy of reject

Provider: Microsoft 365 / Outlook

Sample bounce line

550 5.7.509 Access denied, sending domain example.com does not pass DMARC verification and has a DMARC policy of reject.

What it means

The sender's domain in the 5322.From address does not pass DMARC, and that domain's DMARC policy is reject, so the message is refused. The sender also receives this bounce and should contact their email administrator.

Why it happens

How to fix it

  1. If you use (or pay for) a DMARC reporting service, ask it what is occurring.
  2. Read the NDR, including the headers Microsoft includes in the returned bounce (Authentication-Results shows spf/dkim/dmarc results), to trace the reasons for the DMARC failure.
  3. Add, correct, or align the SPF, DKIM, and DMARC records based on the reasons for the failure.

DNS record examples (replace example.com and the values with your own):

example.com.  IN  TXT  "v=spf1 include:_spf.your-mail-provider.example ~all"   ; one SPF record per domain; use your provider's real include value
selector1._domainkey.example.com.  IN  TXT  "v=DKIM1; k=rsa; p=PUBLIC_KEY_FROM_YOUR_PROVIDER"   ; selector and key come from your mail provider
_dmarc.example.com.  IN  TXT  "v=DMARC1; p=none; rua=mailto:[email protected]"   ; start at p=none, tighten only after reports look clean

Check your domain now

Many of these errors come from missing or broken SPF, DKIM, DMARC or reverse DNS records. Enter your domain to run the free check.

Check your domain now

Related errors

Official documentation

Paste another bounce message · All errors