SMTP ERROR CODES  //  every documented Gmail and Microsoft 365 bounce code, from the providers' own pagesApply
Deliverability

SMTP error codes: every documented Gmail and Microsoft 365 bounce code, explained

Updated 24 September 2026 // by , ReplyLead // from the providers' own pages

  • 121Gmail and Google Workspace responses, from Google's own list
  • 92Microsoft 365 delivery status codes
  • 62%of Google's responses are in the security or policy class (x.7)
  • 5 of 121Google responses that say the recipient address is invalid or inactive

The short answer: an SMTP error code has three parts: a basic reply code (4xx is temporary, 5xx is permanent, under RFC 5321), an enhanced status code in class.subject.detail form (RFC 3463), and the provider's own text. Only 5 of the 121 responses Google documents for Gmail say the recipient address is invalid or inactive; 87 (72%) are about the sender or the message - authentication, sending rate, account setup, or content and reputation rules - where the address may be valid and the fix is on the sending side. Look up any code below.

Look up a code, or paste the whole bounce

Interactive: look up a code or paste a bounce

2 matches for 5.1.1.

  • Gmail / Google Workspace550 5.1.1The email account that you tried to reach does not exist. Please double-check the recipient's email address for typos or unnecessary spaces.Permanent - Addressing status - Invalid or inactive recipientThe recipient address is invalid or inactive: check it for typos; if it is spelled right, suppress it permanently and check the list source that produced it.
  • Microsoft 3655.1.1Bad destination mailbox address: The following conditions might cause this failure: The sender incorrectly entered the recipient's email address. The recipient's email address doesn't exist in the destination email system. The recipient's mailbox was moved, and the sender's Outlook recipient cache didn't update. An invalid legacy domain name (DN) exists for the recipient's mailbox Active Directory Domain Service.Permanent - Addressing status - Invalid or inactive recipientThe recipient address is invalid or inactive: check it for typos; if it is spelled right, suppress it permanently and check the list source that produced it.

Provider texts are quoted from Google's and Microsoft's own pages; the "what to do" line is ReplyLead's operating guidance for cold outreach. Nothing you paste leaves your browser.

How to read an SMTP error code

Take 550 5.1.1. The first number, 550, is the basic reply code from RFC 5321: a 5 means permanent, a 4 means try again later. The second, 5.1.1, is the enhanced status code from RFC 3463, read as class.subject.detail: the class repeats the temporary or permanent verdict, the subject says what kind of problem it is, and the detail narrows it down. The text after the codes is the provider's own explanation, and in cold outreach it is the part that tells you whether to delete the address or fix your sending. A 5.7.x code, for example, is usually a security or policy decision, not a statement that the mailbox does not exist - though Microsoft uses 5.7.504 and 5.7.505 for recipients that are not valid, so read the text.

The subject classes, and what each means for a cold email

RFC 3463 subject classes, how many of Google's 121 documented responses fall in each, and what the class usually means for a cold email
Enhanced codeClass (RFC 3463)Google responsesWhat the class usually means (ReplyLead reading of RFC 3463)
x.1.xAddressing status4Addressing: an address in the envelope is wrong. Usually the recipient (5.1.1 unknown user, 5.1.2 bad domain); 5.1.7 is the sender's own address.
x.2.xMailbox status7Mailbox: the recipient mailbox is full, inactive, disabled or receiving too fast.
x.3.xMail system status12Mail system: the receiving system cannot take the message for a system reason, including a message too big for it (x.3.4).
x.4.xNetwork and routing status5Network and routing: the message could not be routed, often DNS, MX or connection problems.
x.5.xMail delivery protocol status17Mail delivery protocol: the sending software broke the SMTP protocol or a command limit, or the connection was unreliable.
x.6.xMessage content or media status1Message content or media: the format or encoding of the message was refused.
x.7.xSecurity or policy status75Security or policy: authentication, reputation, rate or content rules. The address may be valid.

What Google's 121 documented responses are about

Bar chart of Google's 121 documented SMTP responses by RFC 3463 class: Security or policy (x.7) 75; Mail delivery protocol (x.5) 17; Mail system (x.3) 12; Mailbox (x.2) 7; Network and routing (x.4) 5; Addressing (x.1) 4; Message content or media (x.6) 1.
Google's own list of Gmail SMTP responses, counted by RFC 3463 subject class: 75 of 121 are security or policy responses (x.7) and 4 are addressing responses (x.1).

Most bounce advice assumes a bounce means a bad address. Google's own list shows how many other reasons exist: 75 of its 121 documented responses are in the security or policy class, and only 5, by the rules in the method below, say the recipient address is invalid or inactive. Our own campaign data is consistent with this - recipients behind a security gateway bounced 3.51x as often as unprotected Microsoft 365 or Google Workspace recipients in the same campaigns, as the bounce page shows.

Every code, as the providers publish it

All 121 Gmail and Google Workspace responses
Gmail SMTP responses from Gmail SMTP errors and codes, read 24 September 2026, licensed CC BY 4.0; closing "for more information" sentences and links removed, placeholders shown in brackets
CodeClassGoogle's text
450 4.2.1TemporaryThe user you are trying to contact is receiving email too quickly. Please resend your message at a later time. If the user is able to receive email at that time, your message will be delivered.
450 4.2.1TemporaryThe user you are trying to contact is receiving email at a rate that prevents additional messages from being delivered. Please resend your message at a later time. If the user is able to receive email at that time, your message will be delivered.
450 4.2.1TemporaryPeak SMTP relay limit exceeded for this customer. This is a temporary error.
452 4.2.2TemporaryThe recipient's inbox is out of storage space. Please direct the recipient to Manage files in your Google Drive storage.
451 4.3.0TemporaryEmail server has temporarily rejected this message.
451 4.3.0TemporaryMultiple destination domains per transaction is unsupported. Please try again.
421 4.3.0TemporaryTemporary System Problem. Try again later.
451 4.4.2TemporaryTimeout - closing connection.
421 4.4.5TemporaryServer busy, try again later.
451 4.5.0TemporarySMTP protocol violation.
452 4.5.3TemporaryDomain policy size per transaction exceeded, please try this recipient in a separate transaction.
452 4.5.3TemporaryYour message has too many recipients.
421 4.7.0TemporaryConnection expired, try reconnecting.
421 4.7.0TemporaryIP not in whitelist for RCPT domain, closing connection.
421 4.7.0TemporaryTry again later, closing connection. ([command])
421 4.7.0TemporaryThe IP address sending this message does not have a PTR record, or the corresponding forward DNS entry does not point to the sending IP. To protect our users from spam, email sent from your IP address has been temporarily rate limited.
454 4.7.0TemporaryToo many login attempts, please try again later.
454 4.7.0TemporaryCannot authenticate due to a temporary system problem. Try again later.
421 4.7.0TemporaryTLS required for RCPT domain, closing connection.
421 4.7.0TemporaryThis message is suspicious due to the very low reputation of the sending IP address. To protect our users from spam, email sent from your IP address has been temporarily rate limited.
421 4.7.0TemporaryThis message is suspicious due to the very low reputation of the sending domain. To best protect our users from spam, the message has been blocked.
421 4.7.0TemporaryThis message is suspicious due to the nature of the content or the links within. To best protect our users from spam, the message has been blocked.
451 4.7.23Temporary[ip-address] The sending IP address for this message doesn't have a PTR record, or the PTR record's forward DNS entry doesn't match the sending IP address. To protect users from spam, your email has been temporarily rate limited.
451 4.7.24TemporaryThe SPF record of the sending domain has one or more suspicious entries. To protect our users from spam, email sent from your IP address has been temporarily rate limited.
451 4.7.26TemporaryUnauthenticated email from domain-name is not accepted due to domain's DMARC policy, but temporary DNS failures prevent authentication. Please contact the administrator of [domain-name] domain if this was a legitimate email.
421 4.7.26TemporaryThis email has been rate limited because it is unauthenticated. Gmail requires all senders to authenticate with either SPF or DKIM. Authentication results: DKIM = did not pass SPF [domain-name] with ip: [ip-address] = did not pass.
421 4.7.27TemporaryYour email has been rate limited because SPF authentication didn't pass for this message. Gmail requires all bulk email senders to authenticate their email with SPF. Authentication results: SPF [domain-name] with IP address: [ip-address] = Did not pass.
421 4.7.28TemporaryGmail has detected an unusual rate of email. To protect our users from spam, email has been temporarily rate limited.
421 4.7.28TemporaryGmail has detected an unusual rate of email originating from your IP address [ip-address]. To protect our users from spam, email sent from your IP address has been temporarily rate limited.
421 4.7.28TemporaryGmail has detected an unusual rate of unsolicited email originating from your IP Netblock [ip-address]. To protect our users from spam, email sent from your IP Netblock has been temporarily rate limited.
421 4.7.28TemporaryGmail has detected an unusual rate of unsolicited email originating from your DKIM domain [domain-name]. To protect our users from spam, email sent from your domain has been temporarily rate limited.
421 4.7.28TemporaryGmail has detected an unusual rate of unsolicited email originating from your SPF domain [domain-name]. To protect our users from spam, email sent from your domain has been temporarily rate limited.
421 4.7.28TemporaryGmail has detected an unusual rate of unsolicited email containing one of your URL domains. To protect our users from spam, email with the URL has been temporarily rate limited.
421 4.7.28TemporaryGmail has detected an unusual amount of unsolicited email originating from your IP address. To protect our users from spam, email sent from your IP address has been temporarily blocked.
421 4.7.28TemporaryGmail has detected this sender exceeded the quota for sending messages that have the same Message-ID:. To best protect our users, the message has been temporarily rejected.
421 4.7.29TemporaryYour email has been rate limited because you're not using a TLS connection. Gmail requires all bulk email senders to use TLS/SSL for SMTP connections.
421 4.7.30TemporaryYour email has been rate limited because DKIM authentication didn't pass for this message. Gmail requires all email bulk senders to authenticate their email with DKIM. Authentication results: DKIM = Did not pass.
421 4.7.40TemporaryYour email has been rate limited because the sending domain doesn't have a DMARC record, or the DMARC record doesn't specify a DMARC policy. Gmail requires all bulk email senders to add a DMARC record to their sending domain.
421 4.7.32TemporaryYour email has been rate limited because the From: header (RFC5322) in this message isn't aligned with either the authenticated SPF or DKIM organizational domain.
421 5.7.32TemporaryYour email was blocked because the From: header (RFC5322) in this message isn't aligned with either the authenticated SPF or DKIM organizational domain.
550 5.1.1PermanentThe email account that you tried to reach does not exist. Please double-check the recipient's email address for typos or unnecessary spaces.
553 5.1.2PermanentWe weren't able to find the recipient domain. Please check for any spelling errors and make sure you didn't enter any spaces, periods, or other punctuation after the recipient's email address.
553 5.1.3PermanentThe recipient address [address] is not a valid RFC 5321 address.
553 5.1.7PermanentThe sender address [address] is not a valid RFC 5321 address.
550 5.2.1PermanentThe email account that you tried to reach is inactive.
550 5.2.1PermanentThe user you are trying to contact is receiving email at a rate that prevents additional messages from being delivered.
552 5.2.2PermanentThe recipient's inbox is out of storage space and inactive. Please direct the recipient to Manage files in your Google Drive storage.
552 5.3.4PermanentYour message exceeded Google's message size limits.
552 5.3.4PermanentThe number of attachments ([num-attachments]) exceeds Google's limit of [limit] attachments.
552 5.3.4PermanentThe size of your message ([size] bytes) exceeded Google's message size limits of [limit] bytes.
552 5.3.4PermanentYour message exceeded Google's message header size limits.
552 5.3.4PermanentYour message exceeded Google's message header size limits. Messages must not exceed [limit] total header bytes or [limit] header fields.
552 5.3.4PermanentThe size of the [header name] header value ([size] bytes) exceeds Google's limit of [limit] bytes per individual header size.
552 5.3.4PermanentThe size of one of the header values ([size] bytes) exceeds Google's limit of [limit] bytes per individual header size.
552 5.3.4PermanentThe size of a header name ([size] bytes) exceeds Google's header name limit of [limit] bytes.
552 5.3.4PermanentYour message has a Subject: header that exceeds Google's message header size limits.
550 5.4.5PermanentDaily user sending limit exceeded.
550 5.4.5PermanentDaily SMTP relay limit exceeded for user.
554 5.4.6PermanentMessage exceeded 50 hops, this may indicate an email loop.
503 5.5.1PermanentBad sequence of commands.
502 5.5.1PermanentUnimplemented command.
502 5.5.1PermanentUnrecognized command.
502 5.5.1PermanentToo many unrecognized commands, goodbye.
503 5.5.1PermanentNo DATA after BDAT. An email transaction protocol command was issued out of sequence.
503 5.5.1PermanentEHLO/HELO first. An email transaction protocol command was issued out of sequence.
503 5.5.1PermanentAn email transaction protocol command was issued out of sequence.
503 5.5.1PermanentRCPT first. An email transaction protocol command was issued out of sequence.
501 5.5.2PermanentSyntax error, cannot decode response.
555 5.5.2PermanentSyntax error.
555 5.5.2PermanentSyntax error, goodbye.
550 5.5.3PermanentToo many recipients for this sender.
501 5.5.4PermanentHELO/EHLO argument [argument] invalid closing connection.
501 5.5.4PermanentEmpty HELO/EHLO argument not allowed, closing connection.
554 5.6.0PermanentEmail message is malformed. Not accepted.
552 5.7.0PermanentThis message was blocked because its content presents a potential security issue.
503 5.7.0PermanentNo identity changes permitted.
550 5.7.0PermanentEmail relay denied [ip-address]. Invalid credentials for relay for one of the domains in: [domain-name] (as obtained from HELO and (E)MAIL FROM). Email is being sent from a domain or IP address which isn't registered in your Workspace account. Please login to your Workspace account and verify that your sending device IP address has been registered within the Workspace SMTP Relay Settings.
550 5.7.0PermanentEmail relay denied [ip-address]. The sending email account has been temporarily suspended due to abuse.
550 5.7.0PermanentEmail sending denied.
554 5.7.0PermanentToo many unauthenticated commands.
530 5.7.0PermanentAuthentication required.
530 5.7.0PermanentMust issue a STARTTLS command first.
552 5.7.0PermanentThis message was blocked because its content presents a potential security issue.
550 5.7.1PermanentThe user or domain that you are sending to (or from) has a policy that prohibits the email that you sent. Contact your domain administrator for assistance.
550 5.7.1PermanentInvalid credentials for relay [ip-address]. The IP address you've registered in your Workspace SMTP Relay service doesn't match the domain of the account this email is being sent from. If you are trying to relay email from a domain that isn't registered under your Workspace account or has empty envelope-from:, you must configure your email server either to use SMTP AUTH to identify the sending domain or to present one of your domain names in the HELO or EHLO command.
550 5.7.1PermanentThis message is likely unsolicited email. To reduce the amount of spam sent to Gmail, this message has been blocked.
550 5.7.1PermanentThis message does not meet IPv6 sending guidelines regarding PTR records and authentication.
550 5.7.1PermanentThis message is likely suspicious due to the very low reputation of the sending IP address. To best protect our users from spam, the message has been blocked.
550 5.7.1PermanentThis message is likely suspicious due to the very low reputation of the sending domain. To best protect our users from spam, the message has been blocked.
550 5.7.1PermanentMessages missing a valid address in the From: header, or having no From: header, are not accepted.
550 5.7.1PermanentMessages missing a valid Message-ID: header are not accepted.
550 5.7.1PermanentMessages with multiple addresses in the From: header are not accepted.
550 5.7.1PermanentThe message contains a unicode character in a disallowed header.
550 5.7.1PermanentThis message is not RFC 5322 compliant because it has duplicate headers. To reduce the amount of spam sent to Gmail, this message has been blocked.
550 5.7.1PermanentThis message is not RFC 5322 compliant because the From: header is missing. To reduce the amount of spam sent to Gmail, this message has been blocked.
550 5.7.1PermanentThis message is not RFC 5322 compliant because it has multiple From: headers. To reduce the amount of spam sent to Gmail, this message has been blocked.
550 5.7.1PermanentThis message is not RFC 5322 compliant because the From: header has a non-compliant domain name. To reduce the amount of spam sent to Gmail, this message has been blocked.
550 5.7.1PermanentThis email has been rate limited.
550 5.7.1PermanentThe IP you're using to send email is not authorized to send email directly to our servers. Use the SMTP relay at your service provider instead.
550 5.7.1PermanentDaily SMTP relay sending limit exceeded for this customer.
550 5.7.1PermanentEncoded-word syntax is not permitted in message header [header-name]. To reduce the amount of spam sent to Gmail, this message has been blocked.
550 5.7.1PermanentThis message is not RFC 5322 compliant. There are multiple [header-name] headers. To reduce the amount of spam sent to Gmail, this message has been blocked.
550 5.7.1PermanentThis message is not RFC 5322 compliant. There is a malformed [header- name] header. To reduce the amount of spam sent to Gmail, this message has been blocked.
523 5.7.10PermanentSMTP protocol violation, no commands allowed to pipeline after STARTTLS.
501 5.7.11PermanentSyntax error (no parameters allowed).
534 5.7.14PermanentPlease log in through your web browser and then try again.
550 5.7.24PermanentThe SPF record of the sending domain has one or more suspicious entries.
550 5.7.25PermanentThis message was blocked because the sending IP address doesn't have a PTR record, or the forwarding DNS entry doesn't reference the sending IP address. Gmail requires that sending IP addresses have a PTR record.
550 5.7.26PermanentThis email has been blocked because the sender is unauthenticated. Gmail requires all senders to authenticate with either SPF or DKIM. Authentication results: DKIM = did not pass SPF [[domain-name]] with ip: [[ip-address]] = did not pass.
550 5.7.26PermanentThe (E)MAIL FROM domain [[domain-name]] has an SPF record with a hard fail policy (-all) but it fails to pass SPF checks with the ip: [[ip-address]]. To best protect our users from spam and phishing, the message has been blocked.
550 5.7.26PermanentUnauthenticated email from domain-name is not accepted due to domain's DMARC policy. Contact the administrator of [domain-name] domain if this was legitimate email.
550 5.7.27PermanentThis message was blocked because it didn't pass SPF authentication. Gmail requires bulk email senders to authenticate their email with SPF. Authentication results: SPF with [ip-address] = did not pass
550 5.7.28PermanentThere is an unusual rate of unsolicited email originating from your IP address. To protect our users from spam, email sent from your IP address has been blocked.
550 5.7.29PermanentThis message was blocked because it wasn't sent over a TLS connection. Gmail requires all bulk email senders to use TLS/SSL for SMTP connections.
550 5.7.30PermanentThis message was blocked because it didn't pass DKIM authentication. Gmail requires bulk email senders to authenticate their email with DKIM. Authentication results: DKIM = did not pass
550 5.7.40PermanentYour message was blocked because the sending domain doesn't have a DMARC record or the DMARC record doesn't specify a DMARC policy. Gmail requires all bulk email senders to add a DMARC record to their sending domain.
504 5.7.40PermanentUnrecognized authentication type.
504 5.7.40PermanentXOAUTH is no longer supported.
535 5.7.80PermanentUsername and Password not accepted.
534 5.7.90PermanentApplication-specific password required.
534 5.7.90PermanentPlease log in with your web browser and then try again.
All 92 Microsoft 365 codes
Microsoft 365 (Exchange Online) delivery status codes from Microsoft Learn, read 24 September 2026, licensed CC BY 4.0; each row joins Microsoft's description and possible cause with a colon
CodeClassMicrosoft's description: possible cause
432 4.3.2TemporarySTOREDRV.Deliver; recipient thread limit exceeded: The ability of the recipient mailbox to accept messages is throttled because it's receiving too many messages too quickly. Throttling is done so that a single recipient's mail processing doesn't unfairly affect other recipients who are sharing the mailbox database.
4.4.7TemporaryMessage expired: The message in the queue expired. The sending server tried to relay or deliver the message, but the action wasn't completed before the message expiration time. This message can also indicate that a message header limit was reached on a remote server, or some other protocol timeout occurred during server communication.
4.4.8TemporaryMX hosts of <domain> failed MTA-STS validation: The destination MX host isn't the expected host per the domain's Strict Transport Security (STS) policy.
4.4.316TemporaryConnection refused [Message=Socket error code 10061]: Microsoft 365 or Office 365 is trying to send a message to an email server outside Microsoft 365 or Office 365, but all attempts to connect are failing because of a network connection issue at the external server's location.
450 4.4.317TemporaryCannot connect to remote server [Message=UntrustedRoot]: During the Transport Layer Security (TLS) handshake, Exchange Online can't verify the authenticity of a leaf certificate sent without the full certificate chain by a remote email server.
4.5.3TemporaryToo many recipients: The message has more than 200 SMTP envelope recipients from the same domain.
4.7.5TemporaryRemote certificate failed MTA-STS validation. Reason: <validityStatus>: The destination mail server's certificate must chain to a trusted root Certificate Authority and the Common Name or Subject Alternative Name must contain an entry for the host name in the STS policy.
4.7.26TemporaryAccess denied, a message sent over IPv6 [2a01:111:f200:2004::240] must pass either SPF or DKIM validation, this message is not signed: The sending message sent over IPv6 must pass either SPF or DKIM.
4.7.321Temporarystarttls-not-supported: Destination mail server must support TLS to receive mail.: DNSSEC checks passed. However, upon establishing the connection, the destination mail server doesn't respond to the STARTTLS command. The destination server responds to the STARTTLS command, but the TLS handshake fails.
4.7.322Temporarycertificate-expired: Destination mail server's certificate is expired.: DNSSEC checks passed. However, upon establishing the connection, the destination mail server provides an expired certificate.
4.7.323Temporarytlsa-invalid: The domain failed DANE validation.: Records are DNSSEC authentic, but one or multiple of these scenarios occurred: The destination mail server's certificate doesn't match the authentic TLSA record requirements. Authentic TLSA record is misconfigured. Destination domain is being attacked. Any other DANE failure.
4.7.324Temporarydnssec-invalid: Destination domain returned invalid DNSSEC records: The destination domain indicated that it was DNSSEC-authentic, but Exchange Online wasn't able to verify it as DNSSEC-authentic.
4.7.325Temporarycertificate-host-mismatch: Remote certificate MUST have a common name or subject alternative name that matches the hostname (DANE): This error occurs if the presented certificate identities (CN and SAN) of a destination SMTP target host don't match any of the domains or MX host.
4.7.500-699TemporaryAccess denied, please try again later: Suspicious activity was detected and sending was temporarily restricted for further evaluation.
4.7.850-899TemporaryAccess denied, please try again later: Suspicious activity was detected on the IP in question, and the address is temporarily restricted while being further evaluated.
5.0.350PermanentGeneric error, x-dg-ref header is too long, or Requested action not taken: policy violation detected (AS345): 5.0.350 is a generic catch-all error code for a wide variety of nonspecific errors from the recipient's email organization. The specific x-dg-ref header is too long message is related to Rich Text-formatted messages. The specific Requested action not taken: policy violation detected (AS345) message is related to nested attachments.
5.1.0PermanentSender denied: This NDR commonly occurs when someone saves an email message to a file in Outlook, opens it offline, and then replies. The message property preserves only the legacyExchangeDN attribute when Outlook delivers the message. Therefore, the lookup could fail.
5.1.1PermanentBad destination mailbox address: The following conditions might cause this failure: The sender incorrectly entered the recipient's email address. The recipient's email address doesn't exist in the destination email system. The recipient's mailbox was moved, and the sender's Outlook recipient cache didn't update. An invalid legacy domain name (DN) exists for the recipient's mailbox Active Directory Domain Service.
5.1.8PermanentAccess denied, bad outbound sender: The account was blocked for sending too much spam. Typically, this problem occurs because the account was compromised (hacked) by phishing or malware.
5.1.10PermanentRecipient not found: SMTP address lookup didn't find the recipient's <SMTP Address>.
550 5.1.20PermanentMultiple From addresses are not allowed without Sender address: An email message has multiple email addresses in the From field, but no email address in the Sender field.
5.1.90PermanentYour message can't be sent because you've reached your daily limit for message recipients: The sender exceeded the recipient rate limit, as described in Sending limits.
5.2.2PermanentSubmission quota exceeded: The sender exceeded the recipient rate limit or the message rate limit as described in Sending limits.
5.2.121PermanentRecipient's per hour message receive limit from specific sender exceeded: The sender exceeded the maximum number of messages that they're allowed to send per hour to a specific recipient in Exchange Online.
5.2.122PermanentRecipient's per hour message receive limit exceeded: The Microsoft 365 or Office 365 recipient exceeded the number of messages that they can receive per hour from all senders.
5.3.190PermanentJournaling on-premises messages to Microsoft 365 or Office 365 not supported when Journaling Archive is disabled: Journaling on-premises messages to Microsoft 365 or Office 365 isn't supported for this organization because Journaling Archive isn't enabled in the organization's settings.
5.4.1PermanentRelay Access Denied: The mail server that's generating the error doesn't accept mail for the recipient's domain. Mail server or DNS misconfiguration causes this error.
5.4.1PermanentRecipient address rejected: Access denied: The recipient's address doesn't exist.
5.4.6 or 5.4.14PermanentRouting loop detected: A configuration error caused an email loop. On-premises Exchange server generates error 5.4.6 (you see this code in hybrid environments). Exchange Online generates error 5.4.14. By default, after 20 iterations of an email loop, Exchange interrupts the loop and generates an NDR to the sender of the message.
5.4.8PermanentMX hosts of <domain> failed MTA-STS validation: The destination MX host wasn't the host expected per the domain's STS policy.
5.4.300PermanentMessage expired: The email message wasn't delivered in time. The destination server didn't respond, or an error occurred, and the NDR could not be delivered to the sender.
5.5.0Permanent550 5.5.0 Requested action not taken: mailbox unavailable: The recipient's <SMTP Address> domain is @hotmail.com or @outlook.com and it wasn't found by SMTP address lookup.
5.6.11PermanentInvalid characters: Your email program added invalid characters (bare line feed characters) to a message that you sent.
5.7.1PermanentDelivery not authorized: The sender of the message isn't allowed to send messages to the recipient.
5.7.1PermanentUnable to relay: The sending email system isn't allowed to send a message to an email system that isn't the final destination of the message.
5.7.1PermanentClient was not authenticated: The sending email system didn't authenticate with the receiving email system. The receiving email system requires authentication before message submission.
5.7.5PermanentRemote certificate failed MTA-STS validation. Reason: <validityStatus>: The destination mail server's certificate must chain to a trusted root Certificate Authority and the Common Name or Subject Alternative Name must contain an entry for the host name in the STS policy.
5.7.12PermanentSender was not authenticated by organization: The sender's message is rejected because the recipient address is set up to reject messages sent from outside its organization. Only an email administrator for the recipient's organization can change this configuration.
5.7.23PermanentThe message was rejected because of Sender Policy Framework violation: The destination email system uses SPF to validate inbound mail, and an issue affects your SPF configuration.
5.7.25PermanentAccess denied, the sending IPv6 address [2a01:111:f200:2004::240] must have a reverse DNS record: The sending IPv6 address must have a reverse DNS record to send email over IPv6.
5.7.57PermanentClient was not authenticated to send anonymous mail during MAIL FROM: You configured an application or device to send (relay) email messages in Microsoft 365 or Office 365 using the smtp.office365.com endpoint, and an issue affects the configuration of the application or device.
5.7.64PermanentTenantAttribution; Relay Access Denied: You use an inbound connector to receive messages from your on-premises email environment, and something changed in your on-premises environment that makes the inbound connector's configuration incorrect.
5.7.124PermanentSender not in allowed-senders list: The sender doesn't have permission to send to the distribution group because the sender isn't in the group's allowed-senders list. Depending how the group is set up, even the group's owner might have to be added to the allowed sender list in order to send messages to the group.
5.7.133PermanentSender not authenticated for group: The recipient address is a group distribution list that's set up to reject messages sent from outside its organization. Only an email administrator for the recipient's organization or the group owner can change this configuration.
5.7.134PermanentSender was not authenticated for mailbox: The recipient address is a mailbox that's set up to reject messages sent from outside its organization. Only an email administrator for the recipient's organization can change this configuration.
5.7.13 or 135PermanentSender was not authenticated for public folder: The recipient address is a public folder that's set up to reject messages sent from outside its organization. Only an email administrator for the recipient's organization can change this configuration.
5.7.136PermanentSender was not authenticated: The recipient address is a mail user that's set up to reject messages sent from outside its organization. Only an email administrator for the recipient's organization can change this configuration.
5.7.232PermanentYour message can't be sent because your trial tenant has exceeded its daily limit for sending email to external recipients (tenant external recipient rate limit): The number of external recipients emailed in a 24-hour period exceeds the external recipient rate limit in Exchange Online. The limit applies per trial tenant.
5.7.233PermanentYour message can't be sent because your tenant exceeded its daily limit for sending email to external recipients (tenant external recipient rate limit): The number of external recipients emailed in a 24-hour period exceeds the external recipient rate limit in Exchange Online. The limit applies per tenant.
5.7.236PermanentYour message can't be sent because your tenant has exceeded its daily limit for sending email to external recipients from your tenant's onmicrosoft.com domains: Your organization exceeded the limit of sending emails to 100 external recipients from your organization's onmicrosoft.com (MOERA) domain within a 24-hour rolling window. This limit is enforced per tenant.
5.7.321Permanentstarttls-not-supported: Destination mail server must support TLS to receive mail.: DNSSEC checks passed. However, upon establishing the connection, the destination mail server doesn't respond to the STARTTLS command. The destination server responds to the STARTTLS command, but the TLS handshake fails.
5.7.322Permanentcertificate-expired: Destination mail server's certificate is expired.: DNSSEC checks passed. However, upon establishing the connection, the destination mail server provides a certificate that's expired.
5.7.323Permanenttlsa-invalid: The domain failed DANE validation.: Records are DNSSEC authentic but one or more of the following things occurred: The destination mail server's certificate doesn't match what is expected per the authentic TLSA record. The authentic TLSA record is misconfigured. The destination domain is being attacked. The certificate start date is in the future. Any other DANE failure.
5.7.324Permanentdnssec-invalid: Destination domain returned invalid DNSSEC records: The destination domain indicated it was DNSSEC authentic but Exchange Online wasn't able to verify it as DNSSEC authentic.
5.7.325Permanentcertificate-host-mismatch: Remote certificate MUST have a common name or subject alternative name matching the hostname (DANE): This error occurs if the presented certificate identities (CN and SAN) of a destination SMTP target host don't match any of the domains or MX host.
5.7.367PermanentRemote server returned not permitted to relay: This error occurs because of SPF or DKIM authentication failures in forwarded or relayed emails. This problem occurs more frequently in mail flows that include non-Microsoft gateways.
5.7.501PermanentAccess denied, spam abuse detected: The sending account was banned because of detected spam activity.
5.7.502PermanentAccess denied, banned sender: The sending account was banned because of detected spam activity.
5.7.503PermanentAccess denied, banned sender: The sending account was banned because of detected spam activity.
5.7.504Permanent[email@contoso.com]: Recipient address rejected: Access denied: The recipient address that you're trying to contact isn't valid.
5.7.505PermanentAccess denied, banned recipient: The recipient that you're trying to contact isn't valid.
5.7.506PermanentAccess Denied, Bad HELO: Your server is trying to introduce itself (HELO according to RFC 821) as the server it's trying to connect to, rather than its own fully qualified domain name.
5.7.507PermanentAccess denied, rejected by recipient: The recipient's organization blocked the IP from which you're trying to send.
5.7.508PermanentAccess denied, [$SenderIPAddress] has exceeded permitted limits within $range range: The sender's IPv6 range tried to send too many messages in too short a time period.
5.7.509PermanentAccess denied, sending domain [$SenderDomain] does not pass DMARC verification and has a DMARC policy of reject.: The sender's domain in the 5322.From address doesn't pass DMARC.
5.7.510PermanentAccess denied, [contoso.com] does not accept email over IPv6: The sender is trying to transmit a message to the recipient over IPv6, but the recipient doesn't accept email messages over IPv6.
5.7.511PermanentAccess denied, banned sender: The IP that you're trying to send from was banned.
5.7.512PermanentAccess denied, message must be RFC 5322 section 3.6.2 compliant: Message was sent without a valid "From" email address.
5.7.513PermanentService unavailable, Client host [$ConnectingIP] blocked by $recipientDomain using Customer Block list (AS16012607): The recipient domain added your sending IP address to its custom block list.
5.7.520PermanentAccess denied, Your organization does not allow external forwarding. Please contact your administrator for further assistance. AS(7555): When Exchange Online detects that a message is forwarded automatically, and an outbound spam filter policy blocks the forwarding activity, the message is restricted and this NDR is sent to the sender.
5.7.606-649PermanentAccess denied, banned sending IP [IP1.IP2.IP3.IP4]: The IP that you're trying to send from was banned.
5.7.703PermanentYour message can't be delivered because messages to XXX, YYY are blocked by your organization using Tenant Allow Block List.: Someone in your organization sent mail to an email address or domain that's blocked in the Tenant Allow/Block List. The whole message is blocked for all internal and external recipients of the message, even if only one recipient email address or domain is defined in a block entry.
5.7.705 5.7.708Permanent5.7.705 Access denied, tenant has exceeded threshold, 5.7.708 Access denied, traffic not accepted from this IP: Most of the traffic from this tenant is detected as suspicious. Therefore, a ban is put on the sending ability of the tenant.
5.7.750PermanentService unavailable. Client blocked from sending from unregistered domains: A suspicious number of messages from unprovisioned domains is coming from this tenant.
5.7.800PermanentAccess denied, banned sender: The EHLO, P1, or P2 sender domain of this message was banned because of detected spam activity.
421 4.3.240TemporaryThe maximum number of concurrent server connections has exceeded a per authenticated source limit, closing transmission channel.: The sender opened too many simultaneous authenticated connections to the service, and exceeded the allowed limit of 250.
450 4.4.244TemporaryThe HVE message can't be submitted because the recipient rate limit was exceeded.: The sender tried to send many messages to a small number of recipients within a short time window, and caused this submission to be throttled.
535 5.7.142PermanentXOAUTH2 authentication failed. Token will expire soon.: The OAuth access token that's used for authentication was close to expiration and was rejected. The client must request a new token, and retry authentication.
535 5.7.143PermanentXOAUTH2 authentication failed. Expired token.: The client tried to authenticate by using an OAuth access token that's already expired.
535 5.7.144PermanentXOAUTH2 authentication failed. Invalid API permissions.: An invalid token that has the wrong permission is set on the app that's registered to use HVE with OAuth.
550 5.1.241PermanentThe message can't be delivered because the recipient is an HVE account. HVE accounts do not have associated mailboxes and can only send messages.: The recipient address belongs to an HVE account that's designed for sending only, and it can't receive email messages.
550 5.2.240PermanentThe email account is not set up properly for the HVE service. Contact your administrator.: The sending account isn't set up correctly for the HVE service. Therefore, the message submission was rejected.
550 5.2.241PermanentThe HVE account is not properly set up for billing. Contact your administrator.: The HVE account doesn't have a valid billing configuration.
550 5.6.240PermanentOne of MIME Headers is not allowed.: The message contains a MIME header that isn't permitted.
550 5.6.241PermanentMandatory From Header is missing or invalid.: The message is missing a valid From header, or the From header is incorrectly formatted.
550 5.7.240PermanentThe application is not allowed for use with an HVE account. Contact your administrator.: The application that's used to send the message isn't authorized for HVE accounts.
550 5.7.241PermanentTrial tenant is not able to use HVE. Contact your administrator.: The sender is using a trial tenant that isn't supported for HVE.
550 5.7.242PermanentInactive tenant is not able to use HVE. Contact your administrator.: The sender is using an inactive tenant that isn't supported for HVE.
550 5.7.243PermanentThis tenant is blocked from using HVE. Contact your administrator.: The tenant is blocked from using HVE.
550 5.7.244PermanentMessage rejected. External sending is not supported for HVE accounts. This message cannot be delivered to external recipients. Please remove any external recipients and try sending again.: HVE accounts can't send messages to external recipients.
550 5.7.245PermanentExternal sending is not supported for HVE accounts. The message can't be delivered to this recipient.: HVE accounts can't send messages to external recipients.
550 5.7.246PermanentRemoved external recipients that were not originally specified on submission.: External recipients that weren't explicitly specified in the message (for example, through distribution list expansion) were removed because HVE doesn't support external recipients.

When this page does not apply

  • You run a mail server. This page reads codes from the sender's side of a cold email programme; server configuration is covered by your vendor's documentation, linked below.
  • Your provider is not Google or Microsoft. Other providers use the same RFC 3463 classes but their own texts; the class table still applies, the quoted texts do not.
  • You need the provider's current text. Texts are quoted as published on 24 September 2026; providers change them, so check the linked pages.
  • You want to know why your campaign bounces overall. One code explains one rejection. Bounce rates by recipient mail environment are on the hard vs soft bounce page.

How this page was built and checked

Google's table (basic code, enhanced code, error text) and Microsoft's Exchange Online NDR tables (code, description, possible cause) were fetched and parsed on 24 September 2026; Google's texts are quoted with their closing 'for more information' sentences and links removed and placeholders in brackets, and Microsoft rows quote the description and the possible cause joined by a colon; Microsoft's 'additional information' column and one uncoded row are not copied. Both pages are licensed CC BY 4.0. Google's table repeats one 552 5.7.0 row and pairs 421 with 5.7.32; they are kept as published. Temporary or permanent follows the basic reply code where the provider gives one, otherwise the enhanced code. Each code is classed by its enhanced status code under RFC 3463 (first digit: 4 persistent transient failure, 5 permanent failure; second digit: the subject). Each row is also sorted into one of twelve kinds by keyword rules on the provider's own text, first match wins, in this order: temporary system problem; invalid or inactive recipient (does not exist, not found, invalid, inactive or disabled); recipient accepts only internal or listed senders; sender TLS, login or relay credentials; unusual sending rate; sender authentication; banned sender or low reputation; sending software or protocol; recipient domain or server problem; sender account or route; recipient receiving too fast; sending volume or rate; mailbox full; content, format or reputation; then temporary or permanent other. The 'what to do' line follows the kind. The counts in the figure are Google's documented responses per class, not how often each occurs in real sending. The 'what to do' guidance is ReplyLead's own practice for cold outreach. ReplyLead runs cold email and LinkedIn outbound.

Common questions

What does 550 5.1.1 mean?

It is a permanent failure: the address does not exist. Google's text is "The email account that you tried to reach does not exist. Please double-check the recipient's email address for typos or unnecessary spaces." and Microsoft titles 5.1.1 "Bad destination mailbox address". In cold outreach, suppress the address permanently and check the list source that produced it.

What does 550 5.7.1 mean?

It is a permanent security or policy rejection, and Google lists 20 different texts for it, from "The user or domain that you are sending to (or from) has a policy that prohibits the email that you sent. Contact your domain administrator for assistance." to reputation, relay and header-compliance blocks. The address may be valid: fix authentication, volume and reputation, or read the text for the specific rule, before deleting the lead.

What does 421 4.7.0 mean?

It is a temporary security or policy deferral; Google lists 8 texts for 421 4.7.0 (and 2 more under 454 4.7.0), including "This message is suspicious due to the very low reputation of the sending IP address. To protect our users from spam, email sent from your IP address has been temporarily rate limited." Slow down, check authentication and TLS, and let the retry run; a deferral that persists usually points at reputation, authentication or TLS, not a bad address.

What does 550 5.4.1 mean?

Microsoft lists two meanings for 5.4.1 in Exchange Online: "Relay Access Denied" and "Recipient address rejected: Access denied". For the second, Microsoft's cause is "The recipient's address doesn't exist" and it links to Directory Based Edge Blocking, so suppress that address; the first is a routing problem with the recipient's domain, so check the domain and its MX records before deleting anything.

What does 550 5.7.26 mean?

Gmail rejected the message because it failed authentication; one of Google's texts is "This email has been blocked because the sender is unauthenticated. Gmail requires all senders to authenticate with either SPF or DKIM. Authentication results: DKIM = did not pass SPF [[domain-name]] with ip: [[ip-address]] = did not pass." Fix SPF, DKIM and DMARC alignment for the sending domain before sending again.

What is the difference between 4xx and 5xx SMTP errors?

Under RFC 5321 a 4xx reply is a transient negative completion - try again later - and a 5xx reply is permanent. RFC 3463 carries the same split in the enhanced code: 4.X.X is a persistent transient failure, 5.X.X a permanent failure. In cold outreach, let 4xx retry and treat 5xx as final unless the text names a policy you can fix.

Sources and check dates

ReplyLead pages that use these codes:

  1. Hard bounce vs soft bounce: the bounce classifier and bounce rates by recipient mail environment.
  2. Why verified lists still bounce: gateway rejections behind valid addresses.
  3. Email header analyzer: reading the headers of a message that bounced.
  4. Deliverability checker: SPF, DKIM and DMARC checks for your sending domain.

Outside primary sources, each read on the date shown:

  1. Google Workspace: Gmail SMTP errors and codes: the 121 Gmail and Google Workspace responses listed here, with Google's own error text. checked 24 September 2026.
  2. Microsoft Learn: Email nondelivery reports (NDRs) and SMTP errors in Exchange Online: the 92 Microsoft 365 delivery status codes, their descriptions and possible causes. checked 24 September 2026.
  3. RFC 5321, Simple Mail Transfer Protocol (IETF): basic reply codes: 4yz transient negative completion, 5yz permanent negative completion. checked 24 September 2026.
  4. RFC 3463, Enhanced Mail System Status Codes (IETF): the class.subject.detail format, 4.X.X persistent transient and 5.X.X permanent failure, and the eight subject classes. checked 24 September 2026.
  5. IANA: Simple Mail Transfer Protocol (SMTP) Enhanced Status Codes registry: the registered enhanced status codes and their meanings. checked 24 September 2026.
  6. RFC 3464, An Extensible Message Format for Delivery Status Notifications (IETF): the non-delivery report format these codes arrive in. checked 24 September 2026.

Bounces under control are part of every programme we run: how ReplyLead runs outbound.