SMTP error codes: every documented Gmail and Microsoft 365 bounce code, explained
Updated 24 September 2026 // by Mark Glazer, ReplyLead // from the providers' own pages
- 121Gmail and Google Workspace responses, from Google's own list
- 92Microsoft 365 delivery status codes
- 62%of Google's responses are in the security or policy class (x.7)
- 5 of 121Google responses that say the recipient address is invalid or inactive
The short answer: an SMTP error code has three parts: a basic reply code (4xx is temporary, 5xx is permanent, under RFC 5321), an enhanced status code in class.subject.detail form (RFC 3463), and the provider's own text. Only 5 of the 121 responses Google documents for Gmail say the recipient address is invalid or inactive; 87 (72%) are about the sender or the message - authentication, sending rate, account setup, or content and reputation rules - where the address may be valid and the fix is on the sending side. Look up any code below.
Look up a code, or paste the whole bounce
Interactive: look up a code or paste a bounce
2 matches for 5.1.1.
- Gmail / Google Workspace550 5.1.1The email account that you tried to reach does not exist. Please double-check the recipient's email address for typos or unnecessary spaces.Permanent - Addressing status - Invalid or inactive recipientThe recipient address is invalid or inactive: check it for typos; if it is spelled right, suppress it permanently and check the list source that produced it.
- Microsoft 3655.1.1Bad destination mailbox address: The following conditions might cause this failure: The sender incorrectly entered the recipient's email address. The recipient's email address doesn't exist in the destination email system. The recipient's mailbox was moved, and the sender's Outlook recipient cache didn't update. An invalid legacy domain name (DN) exists for the recipient's mailbox Active Directory Domain Service.Permanent - Addressing status - Invalid or inactive recipientThe recipient address is invalid or inactive: check it for typos; if it is spelled right, suppress it permanently and check the list source that produced it.
Provider texts are quoted from Google's and Microsoft's own pages; the "what to do" line is ReplyLead's operating guidance for cold outreach. Nothing you paste leaves your browser.
How to read an SMTP error code
Take 550 5.1.1. The first number, 550, is the basic reply code from RFC 5321: a 5 means permanent, a 4 means try again later. The second, 5.1.1, is the enhanced status code from RFC 3463, read as class.subject.detail: the class repeats the temporary or permanent verdict, the subject says what kind of problem it is, and the detail narrows it down. The text after the codes is the provider's own explanation, and in cold outreach it is the part that tells you whether to delete the address or fix your sending. A 5.7.x code, for example, is usually a security or policy decision, not a statement that the mailbox does not exist - though Microsoft uses 5.7.504 and 5.7.505 for recipients that are not valid, so read the text.
The subject classes, and what each means for a cold email
| Enhanced code | Class (RFC 3463) | Google responses | What the class usually means (ReplyLead reading of RFC 3463) |
|---|---|---|---|
| x.1.x | Addressing status | 4 | Addressing: an address in the envelope is wrong. Usually the recipient (5.1.1 unknown user, 5.1.2 bad domain); 5.1.7 is the sender's own address. |
| x.2.x | Mailbox status | 7 | Mailbox: the recipient mailbox is full, inactive, disabled or receiving too fast. |
| x.3.x | Mail system status | 12 | Mail system: the receiving system cannot take the message for a system reason, including a message too big for it (x.3.4). |
| x.4.x | Network and routing status | 5 | Network and routing: the message could not be routed, often DNS, MX or connection problems. |
| x.5.x | Mail delivery protocol status | 17 | Mail delivery protocol: the sending software broke the SMTP protocol or a command limit, or the connection was unreliable. |
| x.6.x | Message content or media status | 1 | Message content or media: the format or encoding of the message was refused. |
| x.7.x | Security or policy status | 75 | Security or policy: authentication, reputation, rate or content rules. The address may be valid. |
What Google's 121 documented responses are about
Most bounce advice assumes a bounce means a bad address. Google's own list shows how many other reasons exist: 75 of its 121 documented responses are in the security or policy class, and only 5, by the rules in the method below, say the recipient address is invalid or inactive. Our own campaign data is consistent with this - recipients behind a security gateway bounced 3.51x as often as unprotected Microsoft 365 or Google Workspace recipients in the same campaigns, as the bounce page shows.
Every code, as the providers publish it
All 121 Gmail and Google Workspace responses
| Code | Class | Google's text |
|---|---|---|
| 450 4.2.1 | Temporary | The user you are trying to contact is receiving email too quickly. Please resend your message at a later time. If the user is able to receive email at that time, your message will be delivered. |
| 450 4.2.1 | Temporary | The user you are trying to contact is receiving email at a rate that prevents additional messages from being delivered. Please resend your message at a later time. If the user is able to receive email at that time, your message will be delivered. |
| 450 4.2.1 | Temporary | Peak SMTP relay limit exceeded for this customer. This is a temporary error. |
| 452 4.2.2 | Temporary | The recipient's inbox is out of storage space. Please direct the recipient to Manage files in your Google Drive storage. |
| 451 4.3.0 | Temporary | Email server has temporarily rejected this message. |
| 451 4.3.0 | Temporary | Multiple destination domains per transaction is unsupported. Please try again. |
| 421 4.3.0 | Temporary | Temporary System Problem. Try again later. |
| 451 4.4.2 | Temporary | Timeout - closing connection. |
| 421 4.4.5 | Temporary | Server busy, try again later. |
| 451 4.5.0 | Temporary | SMTP protocol violation. |
| 452 4.5.3 | Temporary | Domain policy size per transaction exceeded, please try this recipient in a separate transaction. |
| 452 4.5.3 | Temporary | Your message has too many recipients. |
| 421 4.7.0 | Temporary | Connection expired, try reconnecting. |
| 421 4.7.0 | Temporary | IP not in whitelist for RCPT domain, closing connection. |
| 421 4.7.0 | Temporary | Try again later, closing connection. ([command]) |
| 421 4.7.0 | Temporary | The IP address sending this message does not have a PTR record, or the corresponding forward DNS entry does not point to the sending IP. To protect our users from spam, email sent from your IP address has been temporarily rate limited. |
| 454 4.7.0 | Temporary | Too many login attempts, please try again later. |
| 454 4.7.0 | Temporary | Cannot authenticate due to a temporary system problem. Try again later. |
| 421 4.7.0 | Temporary | TLS required for RCPT domain, closing connection. |
| 421 4.7.0 | Temporary | This message is suspicious due to the very low reputation of the sending IP address. To protect our users from spam, email sent from your IP address has been temporarily rate limited. |
| 421 4.7.0 | Temporary | This message is suspicious due to the very low reputation of the sending domain. To best protect our users from spam, the message has been blocked. |
| 421 4.7.0 | Temporary | This message is suspicious due to the nature of the content or the links within. To best protect our users from spam, the message has been blocked. |
| 451 4.7.23 | Temporary | [ip-address] The sending IP address for this message doesn't have a PTR record, or the PTR record's forward DNS entry doesn't match the sending IP address. To protect users from spam, your email has been temporarily rate limited. |
| 451 4.7.24 | Temporary | The SPF record of the sending domain has one or more suspicious entries. To protect our users from spam, email sent from your IP address has been temporarily rate limited. |
| 451 4.7.26 | Temporary | Unauthenticated email from domain-name is not accepted due to domain's DMARC policy, but temporary DNS failures prevent authentication. Please contact the administrator of [domain-name] domain if this was a legitimate email. |
| 421 4.7.26 | Temporary | This email has been rate limited because it is unauthenticated. Gmail requires all senders to authenticate with either SPF or DKIM. Authentication results: DKIM = did not pass SPF [domain-name] with ip: [ip-address] = did not pass. |
| 421 4.7.27 | Temporary | Your email has been rate limited because SPF authentication didn't pass for this message. Gmail requires all bulk email senders to authenticate their email with SPF. Authentication results: SPF [domain-name] with IP address: [ip-address] = Did not pass. |
| 421 4.7.28 | Temporary | Gmail has detected an unusual rate of email. To protect our users from spam, email has been temporarily rate limited. |
| 421 4.7.28 | Temporary | Gmail has detected an unusual rate of email originating from your IP address [ip-address]. To protect our users from spam, email sent from your IP address has been temporarily rate limited. |
| 421 4.7.28 | Temporary | Gmail has detected an unusual rate of unsolicited email originating from your IP Netblock [ip-address]. To protect our users from spam, email sent from your IP Netblock has been temporarily rate limited. |
| 421 4.7.28 | Temporary | Gmail has detected an unusual rate of unsolicited email originating from your DKIM domain [domain-name]. To protect our users from spam, email sent from your domain has been temporarily rate limited. |
| 421 4.7.28 | Temporary | Gmail has detected an unusual rate of unsolicited email originating from your SPF domain [domain-name]. To protect our users from spam, email sent from your domain has been temporarily rate limited. |
| 421 4.7.28 | Temporary | Gmail has detected an unusual rate of unsolicited email containing one of your URL domains. To protect our users from spam, email with the URL has been temporarily rate limited. |
| 421 4.7.28 | Temporary | Gmail has detected an unusual amount of unsolicited email originating from your IP address. To protect our users from spam, email sent from your IP address has been temporarily blocked. |
| 421 4.7.28 | Temporary | Gmail has detected this sender exceeded the quota for sending messages that have the same Message-ID:. To best protect our users, the message has been temporarily rejected. |
| 421 4.7.29 | Temporary | Your email has been rate limited because you're not using a TLS connection. Gmail requires all bulk email senders to use TLS/SSL for SMTP connections. |
| 421 4.7.30 | Temporary | Your email has been rate limited because DKIM authentication didn't pass for this message. Gmail requires all email bulk senders to authenticate their email with DKIM. Authentication results: DKIM = Did not pass. |
| 421 4.7.40 | Temporary | Your email has been rate limited because the sending domain doesn't have a DMARC record, or the DMARC record doesn't specify a DMARC policy. Gmail requires all bulk email senders to add a DMARC record to their sending domain. |
| 421 4.7.32 | Temporary | Your email has been rate limited because the From: header (RFC5322) in this message isn't aligned with either the authenticated SPF or DKIM organizational domain. |
| 421 5.7.32 | Temporary | Your email was blocked because the From: header (RFC5322) in this message isn't aligned with either the authenticated SPF or DKIM organizational domain. |
| 550 5.1.1 | Permanent | The email account that you tried to reach does not exist. Please double-check the recipient's email address for typos or unnecessary spaces. |
| 553 5.1.2 | Permanent | We weren't able to find the recipient domain. Please check for any spelling errors and make sure you didn't enter any spaces, periods, or other punctuation after the recipient's email address. |
| 553 5.1.3 | Permanent | The recipient address [address] is not a valid RFC 5321 address. |
| 553 5.1.7 | Permanent | The sender address [address] is not a valid RFC 5321 address. |
| 550 5.2.1 | Permanent | The email account that you tried to reach is inactive. |
| 550 5.2.1 | Permanent | The user you are trying to contact is receiving email at a rate that prevents additional messages from being delivered. |
| 552 5.2.2 | Permanent | The recipient's inbox is out of storage space and inactive. Please direct the recipient to Manage files in your Google Drive storage. |
| 552 5.3.4 | Permanent | Your message exceeded Google's message size limits. |
| 552 5.3.4 | Permanent | The number of attachments ([num-attachments]) exceeds Google's limit of [limit] attachments. |
| 552 5.3.4 | Permanent | The size of your message ([size] bytes) exceeded Google's message size limits of [limit] bytes. |
| 552 5.3.4 | Permanent | Your message exceeded Google's message header size limits. |
| 552 5.3.4 | Permanent | Your message exceeded Google's message header size limits. Messages must not exceed [limit] total header bytes or [limit] header fields. |
| 552 5.3.4 | Permanent | The size of the [header name] header value ([size] bytes) exceeds Google's limit of [limit] bytes per individual header size. |
| 552 5.3.4 | Permanent | The size of one of the header values ([size] bytes) exceeds Google's limit of [limit] bytes per individual header size. |
| 552 5.3.4 | Permanent | The size of a header name ([size] bytes) exceeds Google's header name limit of [limit] bytes. |
| 552 5.3.4 | Permanent | Your message has a Subject: header that exceeds Google's message header size limits. |
| 550 5.4.5 | Permanent | Daily user sending limit exceeded. |
| 550 5.4.5 | Permanent | Daily SMTP relay limit exceeded for user. |
| 554 5.4.6 | Permanent | Message exceeded 50 hops, this may indicate an email loop. |
| 503 5.5.1 | Permanent | Bad sequence of commands. |
| 502 5.5.1 | Permanent | Unimplemented command. |
| 502 5.5.1 | Permanent | Unrecognized command. |
| 502 5.5.1 | Permanent | Too many unrecognized commands, goodbye. |
| 503 5.5.1 | Permanent | No DATA after BDAT. An email transaction protocol command was issued out of sequence. |
| 503 5.5.1 | Permanent | EHLO/HELO first. An email transaction protocol command was issued out of sequence. |
| 503 5.5.1 | Permanent | An email transaction protocol command was issued out of sequence. |
| 503 5.5.1 | Permanent | RCPT first. An email transaction protocol command was issued out of sequence. |
| 501 5.5.2 | Permanent | Syntax error, cannot decode response. |
| 555 5.5.2 | Permanent | Syntax error. |
| 555 5.5.2 | Permanent | Syntax error, goodbye. |
| 550 5.5.3 | Permanent | Too many recipients for this sender. |
| 501 5.5.4 | Permanent | HELO/EHLO argument [argument] invalid closing connection. |
| 501 5.5.4 | Permanent | Empty HELO/EHLO argument not allowed, closing connection. |
| 554 5.6.0 | Permanent | Email message is malformed. Not accepted. |
| 552 5.7.0 | Permanent | This message was blocked because its content presents a potential security issue. |
| 503 5.7.0 | Permanent | No identity changes permitted. |
| 550 5.7.0 | Permanent | Email relay denied [ip-address]. Invalid credentials for relay for one of the domains in: [domain-name] (as obtained from HELO and (E)MAIL FROM). Email is being sent from a domain or IP address which isn't registered in your Workspace account. Please login to your Workspace account and verify that your sending device IP address has been registered within the Workspace SMTP Relay Settings. |
| 550 5.7.0 | Permanent | Email relay denied [ip-address]. The sending email account has been temporarily suspended due to abuse. |
| 550 5.7.0 | Permanent | Email sending denied. |
| 554 5.7.0 | Permanent | Too many unauthenticated commands. |
| 530 5.7.0 | Permanent | Authentication required. |
| 530 5.7.0 | Permanent | Must issue a STARTTLS command first. |
| 552 5.7.0 | Permanent | This message was blocked because its content presents a potential security issue. |
| 550 5.7.1 | Permanent | The user or domain that you are sending to (or from) has a policy that prohibits the email that you sent. Contact your domain administrator for assistance. |
| 550 5.7.1 | Permanent | Invalid credentials for relay [ip-address]. The IP address you've registered in your Workspace SMTP Relay service doesn't match the domain of the account this email is being sent from. If you are trying to relay email from a domain that isn't registered under your Workspace account or has empty envelope-from:, you must configure your email server either to use SMTP AUTH to identify the sending domain or to present one of your domain names in the HELO or EHLO command. |
| 550 5.7.1 | Permanent | This message is likely unsolicited email. To reduce the amount of spam sent to Gmail, this message has been blocked. |
| 550 5.7.1 | Permanent | This message does not meet IPv6 sending guidelines regarding PTR records and authentication. |
| 550 5.7.1 | Permanent | This message is likely suspicious due to the very low reputation of the sending IP address. To best protect our users from spam, the message has been blocked. |
| 550 5.7.1 | Permanent | This message is likely suspicious due to the very low reputation of the sending domain. To best protect our users from spam, the message has been blocked. |
| 550 5.7.1 | Permanent | Messages missing a valid address in the From: header, or having no From: header, are not accepted. |
| 550 5.7.1 | Permanent | Messages missing a valid Message-ID: header are not accepted. |
| 550 5.7.1 | Permanent | Messages with multiple addresses in the From: header are not accepted. |
| 550 5.7.1 | Permanent | The message contains a unicode character in a disallowed header. |
| 550 5.7.1 | Permanent | This message is not RFC 5322 compliant because it has duplicate headers. To reduce the amount of spam sent to Gmail, this message has been blocked. |
| 550 5.7.1 | Permanent | This message is not RFC 5322 compliant because the From: header is missing. To reduce the amount of spam sent to Gmail, this message has been blocked. |
| 550 5.7.1 | Permanent | This message is not RFC 5322 compliant because it has multiple From: headers. To reduce the amount of spam sent to Gmail, this message has been blocked. |
| 550 5.7.1 | Permanent | This message is not RFC 5322 compliant because the From: header has a non-compliant domain name. To reduce the amount of spam sent to Gmail, this message has been blocked. |
| 550 5.7.1 | Permanent | This email has been rate limited. |
| 550 5.7.1 | Permanent | The IP you're using to send email is not authorized to send email directly to our servers. Use the SMTP relay at your service provider instead. |
| 550 5.7.1 | Permanent | Daily SMTP relay sending limit exceeded for this customer. |
| 550 5.7.1 | Permanent | Encoded-word syntax is not permitted in message header [header-name]. To reduce the amount of spam sent to Gmail, this message has been blocked. |
| 550 5.7.1 | Permanent | This message is not RFC 5322 compliant. There are multiple [header-name] headers. To reduce the amount of spam sent to Gmail, this message has been blocked. |
| 550 5.7.1 | Permanent | This message is not RFC 5322 compliant. There is a malformed [header- name] header. To reduce the amount of spam sent to Gmail, this message has been blocked. |
| 523 5.7.10 | Permanent | SMTP protocol violation, no commands allowed to pipeline after STARTTLS. |
| 501 5.7.11 | Permanent | Syntax error (no parameters allowed). |
| 534 5.7.14 | Permanent | Please log in through your web browser and then try again. |
| 550 5.7.24 | Permanent | The SPF record of the sending domain has one or more suspicious entries. |
| 550 5.7.25 | Permanent | This message was blocked because the sending IP address doesn't have a PTR record, or the forwarding DNS entry doesn't reference the sending IP address. Gmail requires that sending IP addresses have a PTR record. |
| 550 5.7.26 | Permanent | This email has been blocked because the sender is unauthenticated. Gmail requires all senders to authenticate with either SPF or DKIM. Authentication results: DKIM = did not pass SPF [[domain-name]] with ip: [[ip-address]] = did not pass. |
| 550 5.7.26 | Permanent | The (E)MAIL FROM domain [[domain-name]] has an SPF record with a hard fail policy (-all) but it fails to pass SPF checks with the ip: [[ip-address]]. To best protect our users from spam and phishing, the message has been blocked. |
| 550 5.7.26 | Permanent | Unauthenticated email from domain-name is not accepted due to domain's DMARC policy. Contact the administrator of [domain-name] domain if this was legitimate email. |
| 550 5.7.27 | Permanent | This message was blocked because it didn't pass SPF authentication. Gmail requires bulk email senders to authenticate their email with SPF. Authentication results: SPF with [ip-address] = did not pass |
| 550 5.7.28 | Permanent | There is an unusual rate of unsolicited email originating from your IP address. To protect our users from spam, email sent from your IP address has been blocked. |
| 550 5.7.29 | Permanent | This message was blocked because it wasn't sent over a TLS connection. Gmail requires all bulk email senders to use TLS/SSL for SMTP connections. |
| 550 5.7.30 | Permanent | This message was blocked because it didn't pass DKIM authentication. Gmail requires bulk email senders to authenticate their email with DKIM. Authentication results: DKIM = did not pass |
| 550 5.7.40 | Permanent | Your message was blocked because the sending domain doesn't have a DMARC record or the DMARC record doesn't specify a DMARC policy. Gmail requires all bulk email senders to add a DMARC record to their sending domain. |
| 504 5.7.40 | Permanent | Unrecognized authentication type. |
| 504 5.7.40 | Permanent | XOAUTH is no longer supported. |
| 535 5.7.80 | Permanent | Username and Password not accepted. |
| 534 5.7.90 | Permanent | Application-specific password required. |
| 534 5.7.90 | Permanent | Please log in with your web browser and then try again. |
All 92 Microsoft 365 codes
| Code | Class | Microsoft's description: possible cause |
|---|---|---|
| 432 4.3.2 | Temporary | STOREDRV.Deliver; recipient thread limit exceeded: The ability of the recipient mailbox to accept messages is throttled because it's receiving too many messages too quickly. Throttling is done so that a single recipient's mail processing doesn't unfairly affect other recipients who are sharing the mailbox database. |
| 4.4.7 | Temporary | Message expired: The message in the queue expired. The sending server tried to relay or deliver the message, but the action wasn't completed before the message expiration time. This message can also indicate that a message header limit was reached on a remote server, or some other protocol timeout occurred during server communication. |
| 4.4.8 | Temporary | MX hosts of <domain> failed MTA-STS validation: The destination MX host isn't the expected host per the domain's Strict Transport Security (STS) policy. |
| 4.4.316 | Temporary | Connection refused [Message=Socket error code 10061]: Microsoft 365 or Office 365 is trying to send a message to an email server outside Microsoft 365 or Office 365, but all attempts to connect are failing because of a network connection issue at the external server's location. |
| 450 4.4.317 | Temporary | Cannot connect to remote server [Message=UntrustedRoot]: During the Transport Layer Security (TLS) handshake, Exchange Online can't verify the authenticity of a leaf certificate sent without the full certificate chain by a remote email server. |
| 4.5.3 | Temporary | Too many recipients: The message has more than 200 SMTP envelope recipients from the same domain. |
| 4.7.5 | Temporary | Remote certificate failed MTA-STS validation. Reason: <validityStatus>: The destination mail server's certificate must chain to a trusted root Certificate Authority and the Common Name or Subject Alternative Name must contain an entry for the host name in the STS policy. |
| 4.7.26 | Temporary | Access denied, a message sent over IPv6 [2a01:111:f200:2004::240] must pass either SPF or DKIM validation, this message is not signed: The sending message sent over IPv6 must pass either SPF or DKIM. |
| 4.7.321 | Temporary | starttls-not-supported: Destination mail server must support TLS to receive mail.: DNSSEC checks passed. However, upon establishing the connection, the destination mail server doesn't respond to the STARTTLS command. The destination server responds to the STARTTLS command, but the TLS handshake fails. |
| 4.7.322 | Temporary | certificate-expired: Destination mail server's certificate is expired.: DNSSEC checks passed. However, upon establishing the connection, the destination mail server provides an expired certificate. |
| 4.7.323 | Temporary | tlsa-invalid: The domain failed DANE validation.: Records are DNSSEC authentic, but one or multiple of these scenarios occurred: The destination mail server's certificate doesn't match the authentic TLSA record requirements. Authentic TLSA record is misconfigured. Destination domain is being attacked. Any other DANE failure. |
| 4.7.324 | Temporary | dnssec-invalid: Destination domain returned invalid DNSSEC records: The destination domain indicated that it was DNSSEC-authentic, but Exchange Online wasn't able to verify it as DNSSEC-authentic. |
| 4.7.325 | Temporary | certificate-host-mismatch: Remote certificate MUST have a common name or subject alternative name that matches the hostname (DANE): This error occurs if the presented certificate identities (CN and SAN) of a destination SMTP target host don't match any of the domains or MX host. |
| 4.7.500-699 | Temporary | Access denied, please try again later: Suspicious activity was detected and sending was temporarily restricted for further evaluation. |
| 4.7.850-899 | Temporary | Access denied, please try again later: Suspicious activity was detected on the IP in question, and the address is temporarily restricted while being further evaluated. |
| 5.0.350 | Permanent | Generic error, x-dg-ref header is too long, or Requested action not taken: policy violation detected (AS345): 5.0.350 is a generic catch-all error code for a wide variety of nonspecific errors from the recipient's email organization. The specific x-dg-ref header is too long message is related to Rich Text-formatted messages. The specific Requested action not taken: policy violation detected (AS345) message is related to nested attachments. |
| 5.1.0 | Permanent | Sender denied: This NDR commonly occurs when someone saves an email message to a file in Outlook, opens it offline, and then replies. The message property preserves only the legacyExchangeDN attribute when Outlook delivers the message. Therefore, the lookup could fail. |
| 5.1.1 | Permanent | Bad destination mailbox address: The following conditions might cause this failure: The sender incorrectly entered the recipient's email address. The recipient's email address doesn't exist in the destination email system. The recipient's mailbox was moved, and the sender's Outlook recipient cache didn't update. An invalid legacy domain name (DN) exists for the recipient's mailbox Active Directory Domain Service. |
| 5.1.8 | Permanent | Access denied, bad outbound sender: The account was blocked for sending too much spam. Typically, this problem occurs because the account was compromised (hacked) by phishing or malware. |
| 5.1.10 | Permanent | Recipient not found: SMTP address lookup didn't find the recipient's <SMTP Address>. |
| 550 5.1.20 | Permanent | Multiple From addresses are not allowed without Sender address: An email message has multiple email addresses in the From field, but no email address in the Sender field. |
| 5.1.90 | Permanent | Your message can't be sent because you've reached your daily limit for message recipients: The sender exceeded the recipient rate limit, as described in Sending limits. |
| 5.2.2 | Permanent | Submission quota exceeded: The sender exceeded the recipient rate limit or the message rate limit as described in Sending limits. |
| 5.2.121 | Permanent | Recipient's per hour message receive limit from specific sender exceeded: The sender exceeded the maximum number of messages that they're allowed to send per hour to a specific recipient in Exchange Online. |
| 5.2.122 | Permanent | Recipient's per hour message receive limit exceeded: The Microsoft 365 or Office 365 recipient exceeded the number of messages that they can receive per hour from all senders. |
| 5.3.190 | Permanent | Journaling on-premises messages to Microsoft 365 or Office 365 not supported when Journaling Archive is disabled: Journaling on-premises messages to Microsoft 365 or Office 365 isn't supported for this organization because Journaling Archive isn't enabled in the organization's settings. |
| 5.4.1 | Permanent | Relay Access Denied: The mail server that's generating the error doesn't accept mail for the recipient's domain. Mail server or DNS misconfiguration causes this error. |
| 5.4.1 | Permanent | Recipient address rejected: Access denied: The recipient's address doesn't exist. |
| 5.4.6 or 5.4.14 | Permanent | Routing loop detected: A configuration error caused an email loop. On-premises Exchange server generates error 5.4.6 (you see this code in hybrid environments). Exchange Online generates error 5.4.14. By default, after 20 iterations of an email loop, Exchange interrupts the loop and generates an NDR to the sender of the message. |
| 5.4.8 | Permanent | MX hosts of <domain> failed MTA-STS validation: The destination MX host wasn't the host expected per the domain's STS policy. |
| 5.4.300 | Permanent | Message expired: The email message wasn't delivered in time. The destination server didn't respond, or an error occurred, and the NDR could not be delivered to the sender. |
| 5.5.0 | Permanent | 550 5.5.0 Requested action not taken: mailbox unavailable: The recipient's <SMTP Address> domain is @hotmail.com or @outlook.com and it wasn't found by SMTP address lookup. |
| 5.6.11 | Permanent | Invalid characters: Your email program added invalid characters (bare line feed characters) to a message that you sent. |
| 5.7.1 | Permanent | Delivery not authorized: The sender of the message isn't allowed to send messages to the recipient. |
| 5.7.1 | Permanent | Unable to relay: The sending email system isn't allowed to send a message to an email system that isn't the final destination of the message. |
| 5.7.1 | Permanent | Client was not authenticated: The sending email system didn't authenticate with the receiving email system. The receiving email system requires authentication before message submission. |
| 5.7.5 | Permanent | Remote certificate failed MTA-STS validation. Reason: <validityStatus>: The destination mail server's certificate must chain to a trusted root Certificate Authority and the Common Name or Subject Alternative Name must contain an entry for the host name in the STS policy. |
| 5.7.12 | Permanent | Sender was not authenticated by organization: The sender's message is rejected because the recipient address is set up to reject messages sent from outside its organization. Only an email administrator for the recipient's organization can change this configuration. |
| 5.7.23 | Permanent | The message was rejected because of Sender Policy Framework violation: The destination email system uses SPF to validate inbound mail, and an issue affects your SPF configuration. |
| 5.7.25 | Permanent | Access denied, the sending IPv6 address [2a01:111:f200:2004::240] must have a reverse DNS record: The sending IPv6 address must have a reverse DNS record to send email over IPv6. |
| 5.7.57 | Permanent | Client was not authenticated to send anonymous mail during MAIL FROM: You configured an application or device to send (relay) email messages in Microsoft 365 or Office 365 using the smtp.office365.com endpoint, and an issue affects the configuration of the application or device. |
| 5.7.64 | Permanent | TenantAttribution; Relay Access Denied: You use an inbound connector to receive messages from your on-premises email environment, and something changed in your on-premises environment that makes the inbound connector's configuration incorrect. |
| 5.7.124 | Permanent | Sender not in allowed-senders list: The sender doesn't have permission to send to the distribution group because the sender isn't in the group's allowed-senders list. Depending how the group is set up, even the group's owner might have to be added to the allowed sender list in order to send messages to the group. |
| 5.7.133 | Permanent | Sender not authenticated for group: The recipient address is a group distribution list that's set up to reject messages sent from outside its organization. Only an email administrator for the recipient's organization or the group owner can change this configuration. |
| 5.7.134 | Permanent | Sender was not authenticated for mailbox: The recipient address is a mailbox that's set up to reject messages sent from outside its organization. Only an email administrator for the recipient's organization can change this configuration. |
| 5.7.13 or 135 | Permanent | Sender was not authenticated for public folder: The recipient address is a public folder that's set up to reject messages sent from outside its organization. Only an email administrator for the recipient's organization can change this configuration. |
| 5.7.136 | Permanent | Sender was not authenticated: The recipient address is a mail user that's set up to reject messages sent from outside its organization. Only an email administrator for the recipient's organization can change this configuration. |
| 5.7.232 | Permanent | Your message can't be sent because your trial tenant has exceeded its daily limit for sending email to external recipients (tenant external recipient rate limit): The number of external recipients emailed in a 24-hour period exceeds the external recipient rate limit in Exchange Online. The limit applies per trial tenant. |
| 5.7.233 | Permanent | Your message can't be sent because your tenant exceeded its daily limit for sending email to external recipients (tenant external recipient rate limit): The number of external recipients emailed in a 24-hour period exceeds the external recipient rate limit in Exchange Online. The limit applies per tenant. |
| 5.7.236 | Permanent | Your message can't be sent because your tenant has exceeded its daily limit for sending email to external recipients from your tenant's onmicrosoft.com domains: Your organization exceeded the limit of sending emails to 100 external recipients from your organization's onmicrosoft.com (MOERA) domain within a 24-hour rolling window. This limit is enforced per tenant. |
| 5.7.321 | Permanent | starttls-not-supported: Destination mail server must support TLS to receive mail.: DNSSEC checks passed. However, upon establishing the connection, the destination mail server doesn't respond to the STARTTLS command. The destination server responds to the STARTTLS command, but the TLS handshake fails. |
| 5.7.322 | Permanent | certificate-expired: Destination mail server's certificate is expired.: DNSSEC checks passed. However, upon establishing the connection, the destination mail server provides a certificate that's expired. |
| 5.7.323 | Permanent | tlsa-invalid: The domain failed DANE validation.: Records are DNSSEC authentic but one or more of the following things occurred: The destination mail server's certificate doesn't match what is expected per the authentic TLSA record. The authentic TLSA record is misconfigured. The destination domain is being attacked. The certificate start date is in the future. Any other DANE failure. |
| 5.7.324 | Permanent | dnssec-invalid: Destination domain returned invalid DNSSEC records: The destination domain indicated it was DNSSEC authentic but Exchange Online wasn't able to verify it as DNSSEC authentic. |
| 5.7.325 | Permanent | certificate-host-mismatch: Remote certificate MUST have a common name or subject alternative name matching the hostname (DANE): This error occurs if the presented certificate identities (CN and SAN) of a destination SMTP target host don't match any of the domains or MX host. |
| 5.7.367 | Permanent | Remote server returned not permitted to relay: This error occurs because of SPF or DKIM authentication failures in forwarded or relayed emails. This problem occurs more frequently in mail flows that include non-Microsoft gateways. |
| 5.7.501 | Permanent | Access denied, spam abuse detected: The sending account was banned because of detected spam activity. |
| 5.7.502 | Permanent | Access denied, banned sender: The sending account was banned because of detected spam activity. |
| 5.7.503 | Permanent | Access denied, banned sender: The sending account was banned because of detected spam activity. |
| 5.7.504 | Permanent | [email@contoso.com]: Recipient address rejected: Access denied: The recipient address that you're trying to contact isn't valid. |
| 5.7.505 | Permanent | Access denied, banned recipient: The recipient that you're trying to contact isn't valid. |
| 5.7.506 | Permanent | Access Denied, Bad HELO: Your server is trying to introduce itself (HELO according to RFC 821) as the server it's trying to connect to, rather than its own fully qualified domain name. |
| 5.7.507 | Permanent | Access denied, rejected by recipient: The recipient's organization blocked the IP from which you're trying to send. |
| 5.7.508 | Permanent | Access denied, [$SenderIPAddress] has exceeded permitted limits within $range range: The sender's IPv6 range tried to send too many messages in too short a time period. |
| 5.7.509 | Permanent | Access denied, sending domain [$SenderDomain] does not pass DMARC verification and has a DMARC policy of reject.: The sender's domain in the 5322.From address doesn't pass DMARC. |
| 5.7.510 | Permanent | Access denied, [contoso.com] does not accept email over IPv6: The sender is trying to transmit a message to the recipient over IPv6, but the recipient doesn't accept email messages over IPv6. |
| 5.7.511 | Permanent | Access denied, banned sender: The IP that you're trying to send from was banned. |
| 5.7.512 | Permanent | Access denied, message must be RFC 5322 section 3.6.2 compliant: Message was sent without a valid "From" email address. |
| 5.7.513 | Permanent | Service unavailable, Client host [$ConnectingIP] blocked by $recipientDomain using Customer Block list (AS16012607): The recipient domain added your sending IP address to its custom block list. |
| 5.7.520 | Permanent | Access denied, Your organization does not allow external forwarding. Please contact your administrator for further assistance. AS(7555): When Exchange Online detects that a message is forwarded automatically, and an outbound spam filter policy blocks the forwarding activity, the message is restricted and this NDR is sent to the sender. |
| 5.7.606-649 | Permanent | Access denied, banned sending IP [IP1.IP2.IP3.IP4]: The IP that you're trying to send from was banned. |
| 5.7.703 | Permanent | Your message can't be delivered because messages to XXX, YYY are blocked by your organization using Tenant Allow Block List.: Someone in your organization sent mail to an email address or domain that's blocked in the Tenant Allow/Block List. The whole message is blocked for all internal and external recipients of the message, even if only one recipient email address or domain is defined in a block entry. |
| 5.7.705 5.7.708 | Permanent | 5.7.705 Access denied, tenant has exceeded threshold, 5.7.708 Access denied, traffic not accepted from this IP: Most of the traffic from this tenant is detected as suspicious. Therefore, a ban is put on the sending ability of the tenant. |
| 5.7.750 | Permanent | Service unavailable. Client blocked from sending from unregistered domains: A suspicious number of messages from unprovisioned domains is coming from this tenant. |
| 5.7.800 | Permanent | Access denied, banned sender: The EHLO, P1, or P2 sender domain of this message was banned because of detected spam activity. |
| 421 4.3.240 | Temporary | The maximum number of concurrent server connections has exceeded a per authenticated source limit, closing transmission channel.: The sender opened too many simultaneous authenticated connections to the service, and exceeded the allowed limit of 250. |
| 450 4.4.244 | Temporary | The HVE message can't be submitted because the recipient rate limit was exceeded.: The sender tried to send many messages to a small number of recipients within a short time window, and caused this submission to be throttled. |
| 535 5.7.142 | Permanent | XOAUTH2 authentication failed. Token will expire soon.: The OAuth access token that's used for authentication was close to expiration and was rejected. The client must request a new token, and retry authentication. |
| 535 5.7.143 | Permanent | XOAUTH2 authentication failed. Expired token.: The client tried to authenticate by using an OAuth access token that's already expired. |
| 535 5.7.144 | Permanent | XOAUTH2 authentication failed. Invalid API permissions.: An invalid token that has the wrong permission is set on the app that's registered to use HVE with OAuth. |
| 550 5.1.241 | Permanent | The message can't be delivered because the recipient is an HVE account. HVE accounts do not have associated mailboxes and can only send messages.: The recipient address belongs to an HVE account that's designed for sending only, and it can't receive email messages. |
| 550 5.2.240 | Permanent | The email account is not set up properly for the HVE service. Contact your administrator.: The sending account isn't set up correctly for the HVE service. Therefore, the message submission was rejected. |
| 550 5.2.241 | Permanent | The HVE account is not properly set up for billing. Contact your administrator.: The HVE account doesn't have a valid billing configuration. |
| 550 5.6.240 | Permanent | One of MIME Headers is not allowed.: The message contains a MIME header that isn't permitted. |
| 550 5.6.241 | Permanent | Mandatory From Header is missing or invalid.: The message is missing a valid From header, or the From header is incorrectly formatted. |
| 550 5.7.240 | Permanent | The application is not allowed for use with an HVE account. Contact your administrator.: The application that's used to send the message isn't authorized for HVE accounts. |
| 550 5.7.241 | Permanent | Trial tenant is not able to use HVE. Contact your administrator.: The sender is using a trial tenant that isn't supported for HVE. |
| 550 5.7.242 | Permanent | Inactive tenant is not able to use HVE. Contact your administrator.: The sender is using an inactive tenant that isn't supported for HVE. |
| 550 5.7.243 | Permanent | This tenant is blocked from using HVE. Contact your administrator.: The tenant is blocked from using HVE. |
| 550 5.7.244 | Permanent | Message rejected. External sending is not supported for HVE accounts. This message cannot be delivered to external recipients. Please remove any external recipients and try sending again.: HVE accounts can't send messages to external recipients. |
| 550 5.7.245 | Permanent | External sending is not supported for HVE accounts. The message can't be delivered to this recipient.: HVE accounts can't send messages to external recipients. |
| 550 5.7.246 | Permanent | Removed external recipients that were not originally specified on submission.: External recipients that weren't explicitly specified in the message (for example, through distribution list expansion) were removed because HVE doesn't support external recipients. |
When this page does not apply
- You run a mail server. This page reads codes from the sender's side of a cold email programme; server configuration is covered by your vendor's documentation, linked below.
- Your provider is not Google or Microsoft. Other providers use the same RFC 3463 classes but their own texts; the class table still applies, the quoted texts do not.
- You need the provider's current text. Texts are quoted as published on 24 September 2026; providers change them, so check the linked pages.
- You want to know why your campaign bounces overall. One code explains one rejection. Bounce rates by recipient mail environment are on the hard vs soft bounce page.
How this page was built and checked
Google's table (basic code, enhanced code, error text) and Microsoft's Exchange Online NDR tables (code, description, possible cause) were fetched and parsed on 24 September 2026; Google's texts are quoted with their closing 'for more information' sentences and links removed and placeholders in brackets, and Microsoft rows quote the description and the possible cause joined by a colon; Microsoft's 'additional information' column and one uncoded row are not copied. Both pages are licensed CC BY 4.0. Google's table repeats one 552 5.7.0 row and pairs 421 with 5.7.32; they are kept as published. Temporary or permanent follows the basic reply code where the provider gives one, otherwise the enhanced code. Each code is classed by its enhanced status code under RFC 3463 (first digit: 4 persistent transient failure, 5 permanent failure; second digit: the subject). Each row is also sorted into one of twelve kinds by keyword rules on the provider's own text, first match wins, in this order: temporary system problem; invalid or inactive recipient (does not exist, not found, invalid, inactive or disabled); recipient accepts only internal or listed senders; sender TLS, login or relay credentials; unusual sending rate; sender authentication; banned sender or low reputation; sending software or protocol; recipient domain or server problem; sender account or route; recipient receiving too fast; sending volume or rate; mailbox full; content, format or reputation; then temporary or permanent other. The 'what to do' line follows the kind. The counts in the figure are Google's documented responses per class, not how often each occurs in real sending. The 'what to do' guidance is ReplyLead's own practice for cold outreach. ReplyLead runs cold email and LinkedIn outbound.
Common questions
What does 550 5.1.1 mean?
It is a permanent failure: the address does not exist. Google's text is "The email account that you tried to reach does not exist. Please double-check the recipient's email address for typos or unnecessary spaces." and Microsoft titles 5.1.1 "Bad destination mailbox address". In cold outreach, suppress the address permanently and check the list source that produced it.
What does 550 5.7.1 mean?
It is a permanent security or policy rejection, and Google lists 20 different texts for it, from "The user or domain that you are sending to (or from) has a policy that prohibits the email that you sent. Contact your domain administrator for assistance." to reputation, relay and header-compliance blocks. The address may be valid: fix authentication, volume and reputation, or read the text for the specific rule, before deleting the lead.
What does 421 4.7.0 mean?
It is a temporary security or policy deferral; Google lists 8 texts for 421 4.7.0 (and 2 more under 454 4.7.0), including "This message is suspicious due to the very low reputation of the sending IP address. To protect our users from spam, email sent from your IP address has been temporarily rate limited." Slow down, check authentication and TLS, and let the retry run; a deferral that persists usually points at reputation, authentication or TLS, not a bad address.
What does 550 5.4.1 mean?
Microsoft lists two meanings for 5.4.1 in Exchange Online: "Relay Access Denied" and "Recipient address rejected: Access denied". For the second, Microsoft's cause is "The recipient's address doesn't exist" and it links to Directory Based Edge Blocking, so suppress that address; the first is a routing problem with the recipient's domain, so check the domain and its MX records before deleting anything.
What does 550 5.7.26 mean?
Gmail rejected the message because it failed authentication; one of Google's texts is "This email has been blocked because the sender is unauthenticated. Gmail requires all senders to authenticate with either SPF or DKIM. Authentication results: DKIM = did not pass SPF [[domain-name]] with ip: [[ip-address]] = did not pass." Fix SPF, DKIM and DMARC alignment for the sending domain before sending again.
What is the difference between 4xx and 5xx SMTP errors?
Under RFC 5321 a 4xx reply is a transient negative completion - try again later - and a 5xx reply is permanent. RFC 3463 carries the same split in the enhanced code: 4.X.X is a persistent transient failure, 5.X.X a permanent failure. In cold outreach, let 4xx retry and treat 5xx as final unless the text names a policy you can fix.
Sources and check dates
ReplyLead pages that use these codes:
- Hard bounce vs soft bounce: the bounce classifier and bounce rates by recipient mail environment.
- Why verified lists still bounce: gateway rejections behind valid addresses.
- Email header analyzer: reading the headers of a message that bounced.
- Deliverability checker: SPF, DKIM and DMARC checks for your sending domain.
Outside primary sources, each read on the date shown:
- Google Workspace: Gmail SMTP errors and codes: the 121 Gmail and Google Workspace responses listed here, with Google's own error text. checked 24 September 2026.
- Microsoft Learn: Email nondelivery reports (NDRs) and SMTP errors in Exchange Online: the 92 Microsoft 365 delivery status codes, their descriptions and possible causes. checked 24 September 2026.
- RFC 5321, Simple Mail Transfer Protocol (IETF): basic reply codes: 4yz transient negative completion, 5yz permanent negative completion. checked 24 September 2026.
- RFC 3463, Enhanced Mail System Status Codes (IETF): the class.subject.detail format, 4.X.X persistent transient and 5.X.X permanent failure, and the eight subject classes. checked 24 September 2026.
- IANA: Simple Mail Transfer Protocol (SMTP) Enhanced Status Codes registry: the registered enhanced status codes and their meanings. checked 24 September 2026.
- RFC 3464, An Extensible Message Format for Delivery Status Notifications (IETF): the non-delivery report format these codes arrive in. checked 24 September 2026.
Bounces under control are part of every programme we run: how ReplyLead runs outbound.