SMTP error code

550 5.4.1: recipient address rejected by Microsoft 365

When a Microsoft 365 domain answers 550 5.4.1, the address typically doesn't exist there: Microsoft rejects such mail at the edge of its network, before any filtering. A second variant, “Relay Access Denied”, means the receiving domain isn't set up correctly.

Updated October 9, 2026 · 4 min read

Reply code
550 (RFC 5321)
Enhanced code
5.4.1 (registry: No answer from host)
Sent by
Microsoft 365 / Exchange Online
Bounce type
Hard bounce

Verification would have caught it

Microsoft 365 refuses unknown recipients before it accepts a message. A verification that asks about the mailbox gets the same refusal and reports the address as undeliverable.

550 5.4.1 Recipient address rejected: Access denied, at the edge of Microsoft 365 before any filtering

What 550 5.4.1 means

550 5.4.1 is a Microsoft 365 bounce. In the IANA registry and RFC 3463, X.4.1 means “No answer from host”, which is “useful only as a persistent transient error”. Microsoft uses it differently, as a permanent refusal behind 550, and with two texts:

ReplyWhat Microsoft says it meansWhose problem
550 5.4.1 Recipient address rejected: Access deniedThe recipient address doesn’t exist in the Microsoft 365 organizationThe address: a hard bounce
550 5.4.1 Relay Access DeniedThe server “doesn’t accept email from the sender’s domain”, “generally caused by email server or DNS misconfiguration”The receiving domain’s setup

Microsoft 365 also reports unknown recipients as 550 5.1.10 and 550 5.1.1. “Relay Access Denied” shows up when a domain is being moved to Microsoft 365 or its DNS points to the wrong place. Sources: Microsoft’s NDR reference and its article Fix NDR error 550 5.4.1.

Why Microsoft rejects the address at the edge

The “Access denied” text comes from Directory-Based Edge Blocking (DBEB). In Microsoft’s words, DBEB rejects “messages for invalid recipients at the service network perimeter”, and “if the address doesn’t exist, the service blocks the message before filtering even occurs”.

DBEB is active when the domain is set to Authoritative in Exchange Online. During a migration, Microsoft recommends keeping it on Internal relay “until all of your valid recipients have been added to Exchange Online and replicated through the system”. That explains many surprising 550 5.4.1 bounces: a real person whose mailbox isn’t known to Microsoft 365 yet.

What causes 550 5.4.1

How to fix 550 5.4.1 as the sender

  1. Check the address character by character against a recent email or signature from that person.
  2. Ask for the current address through another channel if it looks right but bounces.
  3. Remove it from your lists once you know it’s gone. Repeated sends to unknown addresses hurt your email bounce rate.
  4. If every address at the domain bounces, especially with “Relay Access Denied”, the receiving domain is misconfigured. Tell the people you’re writing to through another channel. The MX lookup shows where the domain’s mail is supposed to go.

If you run the Microsoft 365 tenant

For “Recipient address rejected: Access denied”, Microsoft’s steps are:

  1. Check the spelling of the address in the NDR.
  2. Find out whether one recipient or the whole domain is affected.
  3. Whole domain: in the Exchange admin center under Mail flow > Accepted domains, switch the domain from Authoritative to Internal relay and back to Authoritative.
  4. One synced hybrid mailbox: change the recipient’s SMTP proxy address to a temporary one and back, then allow up to 24 hours for DBEB to update.
  5. An on-premises dynamic distribution group: create a mail contact in Exchange Online with the group’s external address.

For “Relay Access Denied”, check that the domain is listed under accepted domains and shows as active in the Microsoft 365 admin center. Its MX record must use the form <domain>.mail.protection.outlook.com, and Microsoft doesn’t support more than one MX record for a domain in Exchange Online. In hybrid setups, check the connectors that the Hybrid Configuration Wizard created.

Would email verification have prevented it?

For the common variant, yes. Because DBEB refuses unknown recipients before a message is accepted, an email verification gets the same answer when it asks about the mailbox: the address comes back as undeliverable. Check single addresses with the email checker, or a whole list with the bulk email verifier.

For “Relay Access Denied” the result is less clear-cut. A verification will flag addresses at that domain while it is misconfigured, even though the people behind them are real. Re-check them once the domain’s admin has fixed the setup.

Stop bounces before they happen

Most hard bounces come from addresses that don't exist. An email verification asks the receiving server about the mailbox without sending anything, so you can remove bad addresses before your next send.

Frequently asked questions

What does 550 5.4.1 Recipient address rejected: Access denied mean?

The recipient's domain uses Microsoft 365, and Microsoft 365 has no recipient with that address. Directory-Based Edge Blocking rejected the message at the edge of Microsoft's network before any other check. Check the address for typos, then remove it.

Is 550 5.4.1 a hard bounce?

Yes, in its common form: the address doesn't exist in the recipient's Microsoft 365 organization, so every retry fails. The “Relay Access Denied” variant is a setup problem on the receiving side that its admin has to fix.

Why does 550 5.4.1 appear after a move to Microsoft 365?

When users haven't all been added or synchronized yet, Microsoft 365 rejects the missing ones. Microsoft recommends keeping the domain on Internal relay until all recipients are in Exchange Online, and allowing up to 24 hours for changes to synced hybrid recipients.

What is Directory-Based Edge Blocking?

A Microsoft 365 feature that rejects mail for addresses that don't exist in the organization at the perimeter, before spam filtering. It is in effect when the accepted domain is set to Authoritative, and it causes the 550 5.4.1 bounce.

Related codes and guides

Email validation API

Validate emails in your app

emailvalidation.io checks syntax, MX records and the mailbox over SMTP, flags disposable, role and free addresses and returns a quality score, in one request.

/v1/info Email validation API Read the documentation

100 free validations every month. No credit card required.

GET https://api.emailvalidation.io/v1/info?email=support@emailvalidation.io

{
  "email": "support@emailvalidation.io",
  "user": "support",
  "tag": "",
  "domain": "emailvalidation.io",
  "format_valid": true,
  "mx_found": true,
  "smtp_check": true,
  "catch_all": null,
  "role": true,
  "disposable": false,
  "free": false,
  "score": 0.64,
  "state": "deliverable",
  "reason": "valid_mailbox",
  "did_you_mean": ""
}

Start using our email validation software today!

Get 100 validations per month for free