Reference

SMTP error codes and bounce messages

When an email bounces, the receiving server's reply code says why. Here is how to read it, a searchable list of the codes you are likely to see, and what to do about each.

Updated October 9, 2026 · 14 min read

SMTP error codes: 250, 4xx temporary and 5xx permanent replies

How to read an SMTP reply

Reply from the receiving server

550 5.1.1 The email account that you tried to reach does not exist.

1 · Reply code 550

Three digits from RFC 5321. The first one decides what happens next: 5 means permanent failure, 4 means try again later.

2 · Enhanced status code 5.1.1

5

class:
permanent

1

subject:
addressing

1

detail: bad
mailbox

3 · Text

Free text from the server. Every provider words it differently, and it often names the real cause: a blocklist, a policy, a full mailbox.

Gmail's reply when a message is sent to an address that doesn't exist. In a bounce message, look for this line under “technical details” or “diagnostic code”.

Every answer a mail server gives starts with a three-digit reply code from RFC 5321. The first digit is all your server needs to decide what to do next:

First digitMeaningWhat the sending server does
2Success, for example 250 OKMoves on to the next step
3More input needed, for example 354 after the DATA commandSends the message body
4Temporary failureKeeps the message and retries later: a soft bounce if it never gets through
5Permanent failureGives up and sends you a bounce: a hard bounce or a block

Most servers add an enhanced status code (RFC 3463) such as 5.1.1. Its first number repeats the class (2, 4 or 5). The second names what went wrong:

SubjectAreaTypical example
X.1.XThe address5.1.1 mailbox doesn’t exist, 5.1.2 domain not found
X.2.XThe mailbox4.2.2 / 5.2.2 mailbox full, 5.2.1 mailbox disabled
X.3.XThe receiving mail system5.3.4 message too big
X.4.XNetwork and routing4.4.7 delivery time expired, 5.4.6 routing loop
X.5.XThe SMTP conversation5.5.1 invalid command
X.6.XMessage content or formatConversion or encoding problems
X.7.XSecurity and policy5.7.1 refused by policy, 5.7.26 failed authentication

The text after the codes is free-form. It is often the most useful part, because providers use it to name the actual reason, from a blocklist to a missing DMARC record.

Common SMTP error codes

Search for the code in your bounce, or for a word from its text. Codes with their own page are linked.

Address problems (hard bounces)

The address or its domain does not exist or does not accept mail. Retrying won't help: remove the address. An email verification before sending catches these.

CodeMeaningWhat the server saysWhat to do
550 5.1.1The mailbox does not exist at this domain.Gmail: “The email account that you tried to reach does not exist.”
Microsoft 365: “Bad destination mailbox address”
Postfix: “Recipient address rejected: User unknown in local recipient table”
Check the address for typos, then remove it. Don't retry. ✓ Caught by verification
550 5.1.10Microsoft 365: recipient not found. (In the IANA registry, X.1.10 means the domain publishes a null MX.)Microsoft 365: “Recipient not found”Check the spelling and remove the address. ✓ Caught by verification
550 5.4.1Microsoft 365: the domain does not accept mail for this address, usually because the address does not exist. (IANA: no answer from host.)Microsoft 365: “Recipient address rejected: Access denied”Check the address. If the domain has just moved to Microsoft 365, its admin must finish the setup. ✓ Caught by verification
553 5.1.2The recipient domain was not found.Gmail: “We weren't able to find the recipient domain.”Check the domain for typos such as gmial.com, and whether it has MX records. ✓ Caught by verification
553 5.1.3The address is not written correctly.Gmail: “The recipient address … is not a valid RFC 5321 address.”Correct the address: no spaces, one @, a valid domain. ✓ Caught by verification
550 5.2.1The mailbox is disabled or inactive.Gmail: “The email account that you tried to reach is inactive.”Remove the address: nobody uses it anymore. ✓ Caught by verification
552 5.2.2Mailbox full. Gmail sends it when the mailbox is full and inactive. Microsoft 365 uses 5.2.2 for a sender-side limit instead.Gmail: “The recipient's inbox is out of storage space and inactive.”
Microsoft 365: “Submission quota exceeded”
Gmail: remove the address. Microsoft 365: your account hit its sending limit; wait or reduce volume.
554Yahoo's reply for an account that doesn't exist (no enhanced code).Yahoo: “This user doesn't have a yahoo.com account”Remove the address. ✓ Caught by verification
551User not local. The server may name the address to use instead.–Use the new address if the reply gives one; otherwise remove it.
553Mailbox name not allowed, usually invalid address syntax.–Correct the address. ✓ Caught by verification
552Exceeded storage allocation: mailbox full or message too big. A permanent reply, though some email services count a mailbox-full 552 as a soft bounce.–Read the enhanced code: 5.2.2 is a full mailbox, 5.3.4 a message that is too large.

Temporary failures (soft bounces)

The receiving server asks you to try again later. Your server retries on its own; it only becomes a bounce if the problem lasts until the message expires.

CodeMeaningWhat the server saysWhat to do
452 4.2.2The mailbox is full.Gmail: “The recipient's inbox is out of storage space.”Your server retries. Remove the address if it keeps bouncing for weeks.
450 4.2.1The recipient is receiving mail faster than the server allows.Gmail: “The user you are trying to contact is receiving email too quickly.”Retry later; don't send the same message again by hand.
451 4.3.0Temporary error on the receiving server.Gmail: “Email server has temporarily rejected this message.”Your server retries automatically.
451 4.7.1Temporarily refused for a policy reason. Often greylisting: the server refuses the first attempt from an unknown sender on purpose.–Make sure your server retries; greylisted mail goes through on a later attempt.
421 4.7.0Connection refused for now: low reputation, a missing PTR record, or TLS required.Gmail: “Try again later, closing connection.”
Gmail: “TLS required for RCPT domain, closing connection.”
Check reverse DNS and TLS on your server, slow down, and look at your sending reputation.
421 4.7.28Rate limited because of an unusual volume of mail.Gmail: “Gmail has detected an unusual rate of email …”Send more slowly and spread campaigns out; check complaint rates.
421 4.7.26Rate limited because the message is not authenticated.Gmail: “This email has been rate limited because it is unauthenticated.”Set up SPF and DKIM for your sending domain.
421 4.7.27Rate limited because SPF did not pass.Gmail: “Your email has been rate limited because SPF authentication didn't pass for this message.”Fix your SPF record.
421 4.7.30Rate limited because DKIM did not pass.Gmail: “Your email has been rate limited because DKIM authentication didn't pass for this message.”Turn on DKIM signing at your email service.
421 4.7.40Rate limited because the sending domain has no DMARC record.Gmail: “Your email has been rate limited because the sending domain doesn't have a DMARC record …”Publish a DMARC record.
4.4.7The message expired in the queue before the receiving server accepted it. You get it as a bounce at the end.Microsoft 365: “Message expired”Check the recipient domain's MX records and servers; ask its admin.
421Service not available, closing the connection.–Your server retries later.
450Mailbox unavailable for now, for example busy or temporarily blocked.–Your server retries later.
451Local error in processing on the receiving side.–Your server retries later.
452Insufficient system storage, or too many recipients in one message.–Retry later; split large recipient lists.

Blocked by the receiver

The address may be fine; the receiver refused your mail because of authentication, reputation, content or a local rule. Fix the cause before you send again.

CodeMeaningWhat the server saysWhat to do
550Mailbox unavailable: not found, no access, or refused by policy. The text after the code says which.Barracuda-style gateways: “550 permanent failure for one or more recipients (…:blocked)”Read the enhanced code and text; see the 550 page.
550 5.7.1Refused by the receiver's policy: spam filter, sender restrictions or a local rule.Gmail: “This message is likely unsolicited email.”
Microsoft 365: “Delivery not authorized”
Read the rest of the reply; check authentication, content and whether the recipient accepts outside mail.
554 5.7.1Refused by policy. With “Relay access denied”, the server will not pass your mail on.Postfix: “Relay access denied”Log in to your outgoing server before sending; check that the recipient domain's MX points to the right server.
550 5.7.26Blocked because the message is unauthenticated, or fails the sender domain's DMARC policy.Gmail: “This email has been blocked because the sender is unauthenticated.”
Gmail: “Unauthenticated email from domain-name is not accepted due to domain's DMARC policy.”
Set up SPF and DKIM so they align with your From domain.
550 5.7.27Gmail: SPF did not pass (bulk senders). In the IANA registry, X.7.27 means the sender's domain has a null MX.Gmail: “This message was blocked because it didn't pass SPF authentication.”Fix your SPF record.
550 5.7.30Gmail: DKIM did not pass (bulk senders). In the IANA registry, X.7.30 means REQUIRETLS support is required.Gmail: “This message was blocked because it didn't pass DKIM authentication.”Turn on DKIM signing with your own domain.
550 5.7.40Gmail: the sending domain has no DMARC record.Gmail: “Your message was blocked because the sending domain doesn't have a DMARC record …”Publish a DMARC record.
550 5.7.25The sending IP address has no matching PTR (reverse DNS) record.Gmail: “This message was blocked because the sending IP address doesn't have a PTR record …”Ask your server host to set a PTR record that matches your mail server's name.
550 5.7.28Blocked for an unusual amount of unsolicited mail from your IP address.Gmail: “There is an unusual rate of unsolicited email originating from your IP address.”Stop the campaign, check for hacked accounts and send only to people who opted in.
550 5.7.509Microsoft 365: the From domain fails DMARC and its policy is reject.Microsoft 365: “Access denied, sending domain … does not pass DMARC verification and has a DMARC policy of reject.”Make SPF or DKIM pass for your From domain.
550 5.7.515Outlook.com: the sender misses the authentication rules for high-volume senders (SPF, DKIM, DMARC).Outlook.com: “Access denied, sending domain … does not meet the required authentication level.”Publish SPF, DKIM and a DMARC record, aligned with your From domain.
550 5.7.23Rejected because of an SPF violation.Microsoft 365: “The message was rejected because of Sender Policy Framework violation”Add the sending server to your SPF record.
5.7.606–5.7.649Microsoft 365: the sending IP address is banned.Microsoft 365: “Access denied, banned sending IP”Request delisting through Microsoft's delist portal after fixing the cause.
552 5.3.4The message is too large.Gmail: “Your message exceeded Google's message size limits.”Send large files as a link.
554Transaction failed, often a spam or policy rejection. At the start of a connection: no SMTP service here.–Read the rest of the reply.

Sending setup and protocol errors

Your own side refused or failed to send: an account blocked for outbound spam, a forwarding rule, a missing login, the wrong port, relay not allowed, broken commands.

CodeMeaningWhat the server saysWhat to do
5.7.708Microsoft 365: traffic from this IP is not accepted.Microsoft 365: “Access denied, traffic not accepted from this IP”Most mail from the tenant looked suspicious; contact Microsoft support.
5.7.520Microsoft 365: your organization does not allow automatic forwarding to outside addresses.Microsoft 365: “Access denied, Your organization does not allow external forwarding.”Your admin must allow external forwarding in the outbound spam policy.
5.1.8Microsoft 365: your account was blocked for sending spam, often after a break-in.Microsoft 365: “Access denied, bad outbound sender”Secure the account (password, MFA); the admin removes the restriction.
530 5.7.0Authentication required: log in before sending (RFC 4954).–Turn on SMTP authentication in your mail program, usually on port 587.
535 5.7.8Authentication credentials invalid: wrong user name or password (RFC 4954).–Check the login; some providers need an app password.
5.7.57Microsoft 365: an app or device tried to send through smtp.office365.com without logging in.Microsoft 365: “Client was not authenticated to send anonymous mail during MAIL FROM”Configure SMTP authentication or a connector for the device.
554 5.7.0Too many commands before logging in.Gmail: “Too many unauthenticated commands.”Authenticate first.
554 5.4.6Mail loop: the message passed through too many servers.Gmail: “Message exceeded 50 hops, this may indicate an email loop.”
Microsoft 365: “Routing loop detected (5.4.6 or 5.4.14)”
Look for forwarding rules or MX records that point back to each other.
500Syntax error, command unrecognized.–A bug or a wrong port in the sending program.
501Syntax error in parameters, often a malformed address.–Check the sender and recipient addresses.
502Command not implemented.–The server does not support what the client asked for.
503Bad sequence of commands, for example RCPT before MAIL, or sending without logging in.–Check the client's settings, especially authentication.
504Command parameter not implemented.–Update or reconfigure the sending program.
555MAIL FROM or RCPT TO parameters not recognized.–Update or reconfigure the sending program.

Sources: RFC 5321 (SMTP reply codes) · RFC 3463 and the IANA registry of enhanced status codes · Gmail SMTP errors and codes · Microsoft: NDRs in Exchange Online · Yahoo Sender Hub: SMTP error codes. Provider texts are short excerpts, checked October 9, 2026.

Provider-specific codes: Gmail, Microsoft 365, Yahoo

The three-digit codes mean the same everywhere. Enhanced codes do not: large providers use them for their own purposes, so the same 5.x.x can mean different things depending on who sent it.

Fix by symptom

The bounce saysMost likely causeWhat to do
“does not exist”, “user unknown”, “recipient not found”The address is wrong or was deletedCheck for typos, then remove the address. Read 550 5.1.1.
“blocked”, “rejected”, “policy”, “unsolicited”Your mail failed a check at the receiverCheck SPF, DKIM and DMARC; look for your IP on blocklists; read the full text.
“unauthenticated”, “DMARC policy”SPF or DKIM don’t pass for your From domainFix SPF with the SPF record generator, turn on DKIM signing in your email service, and publish DMARC with the DMARC generator.
“out of storage space”, “mailbox full”The recipient’s mailbox is fullWait: your server retries. Remove the address if it keeps happening.
“Relay access denied”The server won’t pass on your mailLog in to your outgoing server (port 587), or check the recipient domain’s MX records with the MX lookup.
“try again later”, “rate limited”, “unusual rate”You send too much, too fast, or your reputation droppedSlow down and spread out campaigns; send only to people who opted in.
“message expired”, “delivery time expired”Temporary errors lasted too longCheck that the recipient domain’s mail servers are reachable.

Whether a failure counts as a hard or a soft bounce decides what your email tool does next. The guide to hard vs. soft bounces explains the difference, and Mail Delivery Subsystem explains the bounce messages Gmail sends you.

Would email verification have prevented it?

Only for the address problems in the first table. An email verification connects to the recipient’s mail server and asks whether it accepts the mailbox, then disconnects before anything is sent. If the server would answer 550 5.1.1 to your message, it gives the same answer to the check, and you can remove the address before you send. Blocks and authentication errors are about your sending setup; verification can’t fix those, but the free SPF, DKIM and DMARC checkers show what to fix.

Most 5.1.x bounces are bad addresses

550 5.1.1, 550 5.1.10, 553 5.1.2 and their relatives all mean the address or its domain doesn't exist. An email verification asks the receiving server the same question before you send, without sending anything.

Frequently asked questions

What does SMTP error 550 mean?

The receiving server refused the message for good. Most often the mailbox doesn't exist (550 5.1.1), but 550 is also used when your mail is blocked by a policy (550 5.7.1, 550 5.7.26). The enhanced code and the text after it tell you which. See SMTP error 550.

What is the difference between 4xx and 5xx errors?

A 4xx reply is temporary: your server keeps the message and tries again, and you only get a bounce if the problem lasts until the message expires. A 5xx reply is permanent: the message bounces at once, and sending it again unchanged will fail again.

Why was my email blocked?

Blocks (mostly 5.7.x codes) are about the sender, not the address: missing SPF, DKIM or DMARC, a sending IP on a blocklist, a poor sending reputation, suspicious content, or a rule at the recipient's organization. The text after the code usually names the reason.

What is an enhanced status code?

The second code in a reply, such as 5.1.1 (RFC 3463). Its three parts give the class (2 success, 4 temporary, 5 permanent), the subject (1 addressing, 2 mailbox, 7 security or policy, and so on) and a detail. It is more precise than the three-digit reply code.

Are SMTP error codes the same at every provider?

The three-digit codes are. Enhanced codes and texts differ: Gmail uses 5.7.30 for failed DKIM, where the registry says REQUIRETLS, and Microsoft 365 uses 5.1.10 for an unknown recipient, where the registry says null MX. Always read the text.

Bounce guides

Email validation API

Validate emails in your app

emailvalidation.io checks syntax, MX records and the mailbox over SMTP, flags disposable, role and free addresses and returns a quality score, in one request.

/v1/info Email validation API Read the documentation

100 free validations every month. No credit card required.

GET https://api.emailvalidation.io/v1/info?email=support@emailvalidation.io

{
  "email": "support@emailvalidation.io",
  "user": "support",
  "tag": "",
  "domain": "emailvalidation.io",
  "format_valid": true,
  "mx_found": true,
  "smtp_check": true,
  "catch_all": null,
  "role": true,
  "disposable": false,
  "free": false,
  "score": 0.64,
  "state": "deliverable",
  "reason": "valid_mailbox",
  "did_you_mean": ""
}

Start using our email validation software today!

Get 100 validations per month for free