Enhanced status code

5.7.1: the “delivery not authorized” status code

5.7.1 is not a complete error on its own. It's the enhanced status code that says “a policy stopped this message”, and the three-digit code in front of it decides whether the refusal is final or temporary.

Updated October 9, 2026 · 4 min read

Enhanced code
5.7.1 (RFC 3463)
Official name
Delivery not authorized, message refused
Subject
X.7 Security or policy status
Basic codes used with it
451, 454, 502, 503, 533, 550, 551 (IANA)

Verification would not have caught it

5.7.1 means a policy refused the message: your server, domain, content or the recipient's rules. The address is usually fine, so a mailbox check can't predict it.

Status code 5.7.1 read as class 5 permanent, subject 7 security or policy, detail 1 not authorized, with the variants 550 5.7.1, 554 5.7.1 and 451 4.7.1

Reading 5.7.1: class, subject, detail

5.7.1 is an enhanced status code, and like every enhanced code it has three parts, defined in RFC 3463:

PartValueMeaning
Class5Permanent failure: “not likely to be resolved by resending the message in the current form”
Subject7Security or policy status
Detail1Delivery not authorized, message refused

RFC 3463 (section 3.8) explains the detail: “The sender is not authorized to send to the destination. This can be the result of per-host or per-recipient filtering.” Per-host means your server or IP address; per-recipient means a rule tied to the person or group you wrote to. The RFC also says the code is “useful only as a permanent error”. Yet the IANA registry lists the basic codes 451, 454, 502, 503, 533, 550 and 551 alongside it, so temporary 4.7.1 replies exist too.

5.7.1 is also the generic policy code. RFC 7372 added more specific X.7 codes, such as 5.7.23 for a failed SPF check “in place of 5.7.1”. Servers that don’t use them still say 5.7.1.

SMTP error 5.7.1 in its variants

What you do depends on the full reply. Each variant has its own page:

Full replyPermanent?Typical causeDetails
550 5.7.1YesSpam filter, reputation, malformed message, or a recipient rule at Gmail or Microsoft 365550 5.7.1
554 5.7.1Yes“Relay access denied”, or your IP is on a blocklist554 5.7.1
451 4.7.1NoTemporary policy refusal; your server retriesSMTP error 451
5.7.1 in a Microsoft 365 NDRYesRestricted recipient, relay or authentication, blocklisted IPBelow

Other codes in the same family are more specific and easier to fix: 550 5.7.26 for unauthenticated mail at Gmail, 550 5.7.509 for a DMARC reject at Microsoft, and 550 5.7.520 for blocked forwarding.

5.7.1 in Microsoft 365 NDRs

Microsoft’s article on 5.7.1 covers the whole range from 5.7.0 to 5.7.999 and sums it up: “Typically, this error indicates a security setting in your organization or the recipient’s organization is preventing your message from reaching the recipient.” The texts you’ll meet:

Text in the NDRMeaning
Delivery not authorizedYou aren’t allowed to send to this recipient or group
Unable to relayThe receiving system doesn’t accept mail for that domain from you
Client was not authenticatedYour system had to log in before sending and didn’t
5.7.1 Service unavailable; Client host [xxx.xxx.xxx.xxx] blocked using Blocklist 1Your sending IP is on Microsoft’s blocklist
550 5.7.1 RESOLVER.RST.AuthRequired; authentication requiredA public folder accepts mail only from authenticated (internal) senders
550 5.7.1, with dmarc=fail action=oreject in the headersThe sender’s domain failed DMARC and publishes p=reject

The first three come from Microsoft’s NDR reference, the next two from the 5.7.1 article, and the DMARC case from Microsoft’s DMARC documentation. For the blocklist case, Microsoft tells admins to forward the NDR to the delisting address quoted in the bounce.

How to tell which problem you have

Look at the words after the code. They map to a cause more reliably than the numbers:

When the text is vague, the bounced message’s headers often hold more detail; the email header analyzer shows them.

Would email verification have prevented it?

No. 5.7.1 is a decision about your mail, not about whether the mailbox exists, and a verification would report most of these recipients as deliverable. What verification does protect is your reputation over time: fewer bounces to dead addresses mean one less reason for filters to distrust you. The list of SMTP error codes shows which codes it does catch.

Stop bounces before they happen

Most hard bounces come from addresses that don't exist. An email verification asks the receiving server about the mailbox without sending anything, so you can remove bad addresses before your next send.

Frequently asked questions

What does SMTP error 5.7.1 mean?

The receiving system refused your message because of a policy: the sender isn't authorized to send to that destination. RFC 3463 names it “Delivery not authorized, message refused”. The reason can be a spam filter, a blocklist, a relay restriction or a rule at the recipient's organization.

Is 5.7.1 a permanent error?

As 5.7.1, yes: the first digit 5 marks a permanent failure. The same detail code with a 4, as in 451 4.7.1, is a temporary refusal, and your server tries again.

What is the difference between 550 5.7.1 and 554 5.7.1?

Both are permanent policy refusals. 550 5.7.1 is what Gmail and Microsoft 365 send for spam verdicts and recipient rules. 554 5.7.1 is common for relay denials (“Relay access denied”) and blocklist rejections.

How do I get off Microsoft's blocklist after a 5.7.1 bounce?

Microsoft's 5.7.1 article says to forward the NDR to the delisting address named in the bounce text and points to its delist portal. Fix the cause first: a hacked account or a spam run will get the IP listed again.

Related codes and guides

Email validation API

Validate emails in your app

emailvalidation.io checks syntax, MX records and the mailbox over SMTP, flags disposable, role and free addresses and returns a quality score, in one request.

/v1/info Email validation API Read the documentation

100 free validations every month. No credit card required.

GET https://api.emailvalidation.io/v1/info?email=support@emailvalidation.io

{
  "email": "support@emailvalidation.io",
  "user": "support",
  "tag": "",
  "domain": "emailvalidation.io",
  "format_valid": true,
  "mx_found": true,
  "smtp_check": true,
  "catch_all": null,
  "role": true,
  "disposable": false,
  "free": false,
  "score": 0.64,
  "state": "deliverable",
  "reason": "valid_mailbox",
  "did_you_mean": ""
}

Start using our email validation software today!

Get 100 validations per month for free