BETA

Proofpoint Email Gateway SMTP Error Code Directory

pphosted.com rejection patterns, spam policy blocks, and reputation filters — decoded

🔧 Related Tools

ANALYSIS TOOLS
DIAGNOSTIC TOOLS
BUILDER TOOLS

Proofpoint Email Gateway SMTP Error Code Directory

Proofpoint is one of the most widely deployed enterprise email security gateways. When a company puts Proofpoint in front of their mailboxes, their MX records resolve to pphosted.com servers. Proofpoint uses standard SMTP codes, but applies its own layered spam, content, and reputation checks on top — and it often cites third-party reputation services like Spamhaus or Cloudmark directly in the bounce text.

Gateway
Proofpoint Email Protection
MX Hostname Pattern
*.pphosted.com
NDR From Address
[email protected]

How to Identify a Proofpoint Bounce

If the Remote-MTA or Reporting-MTA in your bounce contains pphosted.com, the rejection came from a Proofpoint gateway. Proofpoint uses standard SMTP codes (550, 421, etc.) with descriptive human-readable text. The diagnostic often references a third-party reputation service (like Spamhaus or Cloudmark) or a Proofpoint-internal policy rule.

Remote-MTA: dns; mx1-us1.ppe-hosted.com
Diagnostic-Code: smtp; 550 5.7.1 Service unavailable; Client host [198.51.100.1]
  blocked using Cloudmark Sender Intelligence; To request removal from this list
  please forward this message to: [email protected]

The pphosted.com or ppe-hosted.com MX hostname is the key Proofpoint identifier. Note that Proofpoint often cites the underlying reputation service (Cloudmark, Spamhaus) in the rejection text — follow that service's delist process, not Proofpoint's.

Proofpoint Error Codes

The most common SMTP errors returned by Proofpoint Email Protection gateways.

🔴 550 5.7.10 CRITICAL
Message Blocked — Spam/Policy (Proofpoint)
Proofpoint's spam engine has classified your message as unwanted. This code is commonly returned by Proofpoint's gateway when the sending IP, domain, or message content scores above the configured spam threshold.
550 5.7.10 Message rejected because sending domain is listed in Cloudmark
🔴 550 5.7.1 CRITICAL
Message Rejected by Policy
A Proofpoint inbound policy rule has rejected your message. This can be triggered by IP reputation, DMARC failure, content filtering, or organisation-specific allow/block list rules configured by the recipient's admin.
550 5.7.1 Service unavailable; Client host [198.51.100.1] blocked using Spamhaus; https://www.spamhaus.org/query/ip/198.51.100.1
🔴 550 5.7.26 CRITICAL
DMARC Policy Violation
The recipient organisation's Proofpoint gateway is enforcing DMARC. Your message failed alignment — neither SPF nor DKIM matched your From domain. Fix your authentication records.
550 5.7.26 This message fails DMARC evaluation and the sending domain has a DMARC reject policy.
🟡 421 4.7.0 CRITICAL
Rate Limited — Throttling
Proofpoint is temporarily throttling your sending IP. This occurs when you exceed the per-IP or per-domain message rate limit. Back off and retry with exponential delay.
421 4.7.0 Too many concurrent connections from your IP address, please try again later.
🔴 550 5.1.1 CRITICAL
Recipient Does Not Exist
Proofpoint's LDAP or directory verification confirmed the recipient address does not exist in the organisation's mail system. Remove from your list immediately.
550 5.1.1 <[email protected]>: Recipient address rejected: User unknown in virtual mailbox table

Proofpoint Uses Layered Reputation Sources

Proofpoint aggregates multiple third-party and proprietary reputation sources. When your IP or domain is blocked, the diagnostic text usually tells you which reputation service triggered the block:

Cloudmark / Cloudmark CSI
Cloudmark Sender Intelligence. Delist via [email protected] or the Cloudmark Sender Intelligence portal.
Spamhaus
One of the largest IP and domain blocklists. Check and delist via spamhaus.org/lookup.
Proofpoint Nexus
Proofpoint's own IP and domain reputation database. Sender review requests go via Proofpoint Support.

Frequently Asked Questions

Common questions about Proofpoint gateway SMTP errors.

Look up the MX records for the recipient domain. If they resolve to hostnames ending in pphosted.com or ppe-hosted.com, Proofpoint is in front of their inbox. You can do this quickly with our MX Inspector. Knowing the recipient is behind Proofpoint tells you a lot about what to expect and which delist processes to use.

Proofpoint does not just use its own filters — it queries several third-party reputation services as part of its connection checks. When one of those lists flags your IP or domain, Proofpoint includes the service's name (and sometimes a delist link) right in the rejection message. This is actually helpful: it tells you exactly where to go. Delist from the cited service — Spamhaus, Cloudmark, or whichever is named — and Proofpoint will stop blocking you automatically. You do not need to contact Proofpoint.

Proofpoint does not have a public sender portal the way Google or Microsoft do. If the bounce message names Spamhaus, Cloudmark, or another third-party service, contact them — not Proofpoint. If the rejection text references Proofpoint's own Nexus reputation system, you can submit a sender review request through the Proofpoint support portal, but be prepared for a longer process than third-party delist requests.

Yes, and this is an important distinction. Proofpoint is not the mailbox — it is a filter that sits in front of the mailbox (usually Microsoft 365, Google Workspace, or an Exchange server). It applies its own checks before the message ever reaches Microsoft or Google's systems. This is why you can pass all of Microsoft's authentication checks and still get bounced: the company has stricter custom rules in their Proofpoint configuration that Microsoft's own systems know nothing about.

🔍

Got a Proofpoint bounce to decode?

Paste your full NDR email or SMTP error line for an instant plain-English diagnosis.

Open the Bounce Decoder →