550 5.4.1: Recipient Address Rejected
Got "550 5.4.1 Recipient Address Rejected"? Microsoft documents this as an invalid recipient, but it also shows up on IP reputation blocks. One test tells you which.
Published · Last verified · Maintained by TamingDNS
550
5.4.1
Recipient Address Rejected
Very Common
🔢 Enhanced Status Code Breakdown: 5.4.1
| Component | Value | Meaning |
|---|---|---|
| Class | 5 | Permanent failure (Hard bounce) |
| Subject | 4 | Network and routing |
| Detail | 1 | Recipient Address Rejected |
Per RFC 3463 Enhanced Mail System Status Codes. Class (X) = severity, Subject (Y) = category, Detail (Z) = specific condition.
💬 What This Error Means
This code decides nothing on its own. Microsoft documents it as directory-based edge blocking rejecting a recipient address that does not exist in the tenant. Senders also hit it with every authentication check green, where the address is fine and the sending IP is the problem. One test separates the two: send to a second, definitely-valid address at the same organisation. If everyone there bounces, it is your IP or domain. If only one address bounces, it is that address.
Common Causes
- The recipient address does not exist in the tenant, which is what Microsoft documents this code for
- The recipient domain is out of sync in Exchange Online, so valid addresses are refused
- Reported but undocumented: the receiving filters refusing your sending IP or domain, with SPF, DKIM and DMARC all passing
How to Fix This
- Send to a second address you know is valid at the same organisation. Every recipient bouncing points at your IP or domain; one address bouncing points at the address
- Check the spelling of the recipient address, and ask their admin to confirm the mailbox exists
- If the whole tenant bounces, check your sending IP with our Blacklist Checker, confirm SPF and DKIM pass, then use the Microsoft delist portal
📚 Official Documentation
Microsoft attributes 550 5.4.1 "Recipient address rejected: Access denied" to directory-based edge blocking rejecting an invalid recipient, and its published fixes are all recipient-side. Senders widely report the same code as an IP reputation block, but Microsoft documents no reputation path for it. Test a second valid recipient before assuming either.
📖 Microsoft 365 / Outlook documentation → Browse all Microsoft 365 / Outlook error codes →📋 Real-World Example Messages
These are real bounce message formats you might receive. Paste yours into the Bounce Decoder for instant analysis.
550 5.4.1 Recipient address rejected: Access denied [AM0P190CA0026.EURP190.PROD.OUTLOOK.COM] 550 5.4.1 [x.x.x.x]: Client host rejected: cannot find your hostname
🔗 Related Error Codes
🔧 Related Diagnostic Tools
These tools can help you diagnose and fix this type of bounce:
Got a bounce message to decode?
Paste your full NDR email, SMTP error line, or mail log fragment to get an instant plain-English diagnosis.
Open the Bounce Decoder →