SMTP error code

550 5.7.520: your organization does not allow external forwarding

550 5.7.520 comes from Microsoft 365 when a mailbox tries to forward mail automatically to an address outside the organization and the outbound spam policy doesn't allow it. Nothing is wrong with the address; the forward was stopped on purpose.

Updated October 9, 2026 · 4 min read

Reply code
550 (RFC 5321)
Enhanced code
5.7.520 (Microsoft-specific)
Sent by
Microsoft 365 / Exchange Online
Who can fix it
The Microsoft 365 admin

Verification would not have caught it

The forwarding target may be a perfectly valid address. 550 5.7.520 is a policy on the sending side, so there is nothing for a verification to find.

550 5.7.520: Microsoft 365 blocks an inbox rule that forwards mail automatically to an address outside the organization

What 550 5.7.520 means

The full 550 5.7.520 bounce reads:

550 5.7.520 Access denied, Your organization does not allow external forwarding. Please contact your administrator for further assistance. AS(7555)

Microsoft documents the text after the code in its NDR reference and in the article Control external email forwarding and fix 5.7.520 errors; Zendesk’s help center shows it with the 550 in front. Like every 550 error, it is permanent: the forwarded copy is not delivered. Microsoft explains the trigger: “When Exchange Online detects that a message is forwarded automatically, and an outbound spam filter policy blocks the forwarding activity, the message is restricted and this NDR is sent to the sender.”

The policy covers three kinds of automatic forwarding:

Forwarding between people inside the organization isn’t affected, and neither is a user manually forwarding a message. Other X.7 codes you may get from Microsoft 365 are 550 5.7.509 for a DMARC reject and the generic 5.7.1 status code.

Why Microsoft 365 blocks it

Automatic forwarding is also what an attacker sets up in a hijacked mailbox, to keep receiving copies of its mail. Microsoft’s article says Inbox rules forward externally either “deliberately or as a result of a compromised account”. So the outbound spam policy has three settings for it:

SettingEffect
Automatic - System-controlledThe default. Since 2021 it equals Off for new organizations and those that weren’t actively using it
On - Forwarding is enabledExternal automatic forwarding is allowed
Off - Forwarding is disabledExternal automatic forwarding is blocked, and senders get an NDR

Microsoft recommends choosing On or Off explicitly, “because the behavior can differ by organization”. Turning forwarding off also disables existing Inbox rules and mailbox forwarding that point outside the organization.

When you typically see it

How to fix 550 5.7.520

As a user: ask your admin. Name the external address and the reason. Don’t work around the block with other tools; the policy is there on purpose.

As an admin in Microsoft Defender (configure outbound spam policies):

  1. Decide who really needs to forward. Often it’s one shared mailbox, not the whole company.
  2. Create a custom outbound spam policy that applies to those users, groups or domains, and set its automatic forwarding rules to On - Forwarding is enabled. Microsoft: custom policies are applied in priority order, the default policy always comes last, and “outbound spam protection stops for a sender after the first policy is applied”.
  3. Limit the destinations if you want: remote domains can allow forwarding only to specific outside domains. Where settings conflict, Microsoft notes that “the block typically wins”.
  4. Watch the result in the Auto forwarded messages report, which lists the users who forward externally.
  5. If the forwarding rule wasn’t wanted, remove it, reset the account’s password, check its sign-ins and turn on multifactor authentication.

Would email verification have prevented it?

No. The bounce has nothing to do with whether the target address exists; it’s a decision of the forwarding organization’s policy. If you get this bounce after writing to someone, their organization stopped an automatic forward of your message; ask the recipient whether the original arrived. For the bounces that verification does catch, see the list of SMTP error codes or the guide to MAILER-DAEMON messages.

Stop bounces before they happen

Most hard bounces come from addresses that don't exist. An email verification asks the receiving server about the mailbox without sending anything, so you can remove bad addresses before your next send.

Frequently asked questions

What does 550 5.7.520 mean?

Microsoft 365 detected that a message was being forwarded automatically to an external address, and the organization's outbound spam policy blocks that. The forward is stopped and an NDR with “Your organization does not allow external forwarding” is sent.

How do I allow external forwarding in Microsoft 365?

In Microsoft Defender, edit the outbound spam policy and set automatic forwarding to “On - Forwarding is enabled”. Better: create a custom outbound spam policy for just the users or groups that need it, so forwarding stays off for everyone else.

Why did forwarding stop working when nothing changed?

The default setting, “Automatic - System-controlled”, now behaves like “Off” in many organizations. Microsoft changed it in 2021 for new organizations and for those not actively using it, and recommends setting On or Off explicitly.

Can I fix 550 5.7.520 as a normal user?

No. The block is an organization-wide policy. Ask your admin, and say which address you need to forward to and why; forwarding to a helpdesk tool is a common, legitimate reason.

Related codes and guides

Email validation API

Validate emails in your app

emailvalidation.io checks syntax, MX records and the mailbox over SMTP, flags disposable, role and free addresses and returns a quality score, in one request.

/v1/info Email validation API Read the documentation

100 free validations every month. No credit card required.

GET https://api.emailvalidation.io/v1/info?email=support@emailvalidation.io

{
  "email": "support@emailvalidation.io",
  "user": "support",
  "tag": "",
  "domain": "emailvalidation.io",
  "format_valid": true,
  "mx_found": true,
  "smtp_check": true,
  "catch_all": null,
  "role": true,
  "disposable": false,
  "free": false,
  "score": 0.64,
  "state": "deliverable",
  "reason": "valid_mailbox",
  "did_you_mean": ""
}

Start using our email validation software today!

Get 100 validations per month for free