SMTP error code

550 5.7.509: your domain's DMARC policy rejected the email

Microsoft returns 550 5.7.509 when a message's From domain fails DMARC and that domain's own DMARC record says p=reject. The receiver is enforcing your policy, so the fix is in your DNS and your sending services.

Updated October 9, 2026 · 3 min read

Reply code
550 (RFC 5321)
Enhanced code
5.7.509 (Microsoft-specific, not in the IANA registry)
Sent by
Microsoft 365 / Exchange Online
Retry?
After SPF or DKIM passes and aligns

Verification would not have caught it

The recipient's address is fine. 550 5.7.509 is decided by your From domain's DMARC result, which a mailbox check doesn't look at.

550 5.7.509: Microsoft rejects the email because example.com fails DMARC and its own DMARC record says p=reject

What 550 5.7.509 means

Microsoft sends 550 5.7.509 with this text, as listed in its NDR reference:

Access denied, sending domain [$SenderDomain] does not pass DMARC verification and has a DMARC policy of reject.

Its stated cause: “The sender’s domain in the 5322.From address doesn’t pass DMARC.” The 5322.From address is the one people see in the From line. The code is Microsoft’s own; the IANA registry has no X.7.509.

Two conditions have to come together for a 550 5.7.509. Your domain publishes a DMARC record with p=reject, and this message failed DMARC. According to Microsoft’s DMARC documentation, “a message passes DMARC if one or both of the described SPF or DKIM checks pass”, where a check passes only if its domain is aligned with the From domain. The same documentation shows these rejections in Microsoft 365 as 550 5.7.1 with dmarc=fail action=oreject in the headers, so a DMARC rejection can reach you under either code.

Why DMARC fails

Microsoft names three groups of causes:

In practice it usually looks like this. A service sends with your domain in From, but uses its own domain for the bounce address and its own DKIM key. SPF passes, for the service’s domain. DKIM passes, also for the service’s domain. Neither matches your From domain, so DMARC fails, and your p=reject turns that into a bounce.

How to fix 550 5.7.509

  1. Read the NDR and the headers. The Authentication-Results header of a bounced copy shows the SPF, DKIM and DMARC results with their domains. The email header analyzer makes them readable.
  2. Find every sending source. DMARC aggregate reports list the IPs and services sending as your domain and whether they pass. If you pay a DMARC report service, Microsoft suggests asking it first.
  3. Fix DKIM for each service. Turn on signing with your own domain and publish the keys the service gives you. Check them with the DKIM checker.
  4. Fix SPF alignment where you can. If a service offers a custom bounce (return-path) domain under your own domain, set it up so SPF aligns too. Add the services to your SPF record with the SPF record generator.
  5. Check the DMARC record itself with the DMARC checker. A typical strict record:
_dmarc.example.com.  TXT  "v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com"

If legitimate mail fails at scale and you can’t fix it quickly, lowering the policy to p=quarantine or p=none stops the bounces, at the cost of less protection against spoofing. Treat that as a pause, not a fix. The guide what is a DMARC record explains the policy levels.

If you run the receiving tenant

When a partner’s legitimate mail fails DMARC because it passes through a service that changes it, Microsoft’s DMARC documentation lists three ways to let it through. The preferred one is to configure that service as a trusted ARC sealer. The alternatives are a mail flow rule matching the sender’s IP and domain that skips spam filtering, or a temporary allow entry in the Tenant Allow/Block List, which expires after 30 days. If a third-party filter sits in front of Microsoft 365, Enhanced Filtering for Connectors lets Microsoft evaluate SPF and DMARC against the real source.

Would email verification have prevented it?

No. The recipient exists, and a verification would report the address as deliverable. 550 5.7.509 depends only on your domain’s authentication; once SPF or DKIM passes and aligns, the same message to the same address is accepted.

Stop bounces before they happen

Most hard bounces come from addresses that don't exist. An email verification asks the receiving server about the mailbox without sending anything, so you can remove bad addresses before your next send.

Frequently asked questions

What does 550 5.7.509 mean?

The domain in the message's From address failed DMARC, and that domain publishes a DMARC policy of reject, so Microsoft refused the message. Microsoft's text: “Access denied, sending domain … does not pass DMARC verification and has a DMARC policy of reject.”

How do I fix 550 5.7.509?

Make SPF or DKIM pass for a domain that matches your From domain, for every service that sends as your domain. DKIM signing with your own domain is the most reliable route. Your DMARC reports show which sources fail.

Why do only some of my emails get 5.7.509?

Usually only one sending path fails: a newsletter tool, CRM or helpdesk that isn't set up for your domain, or mail that was forwarded on the way. Messages from your main mail system pass and are delivered.

Should I change my DMARC policy to p=none?

Only as a temporary measure while you fix the failing source. With p=none, receivers no longer reject spoofed mail in your name either. Fix authentication, then go back to quarantine or reject.

Related codes and guides

Email validation API

Validate emails in your app

emailvalidation.io checks syntax, MX records and the mailbox over SMTP, flags disposable, role and free addresses and returns a quality score, in one request.

/v1/info Email validation API Read the documentation

100 free validations every month. No credit card required.

GET https://api.emailvalidation.io/v1/info?email=support@emailvalidation.io

{
  "email": "support@emailvalidation.io",
  "user": "support",
  "tag": "",
  "domain": "emailvalidation.io",
  "format_valid": true,
  "mx_found": true,
  "smtp_check": true,
  "catch_all": null,
  "role": true,
  "disposable": false,
  "free": false,
  "score": 0.64,
  "state": "deliverable",
  "reason": "valid_mailbox",
  "did_you_mean": ""
}

Start using our email validation software today!

Get 100 validations per month for free