SMTP error codes and what to do about them
Paste the line from a bounce, or type the code, to find out what the receiving server is telling you, which provider says it that way, and the exact fix. One page per code.
48 codes across six providers, each with its own page.
Gmail and Google Workspace
- 550 5.7.26 This mail has been blocked because the sender is unauthenticatedPermanentGmail refused the message because neither SPF nor DKIM passed for the sending domain.
- 550 5.7.1 Our system has detected that this message is likely unsolicited mailPermanentGmail's spam filter scored the message as spam before it reached a mailbox and rejected it at the SMTP level rather than placing it in the Spam folder.
- 421 4.7.0 Our system has detected an unusual rate of unsolicited mail originating from your IP addressTemporaryGmail is throttling the sending IP.
- 421 4.7.28 Our system has detected an unusual rate of unsolicited mail originating from your DKIM domainTemporaryLike 421 4.7.0 but keyed to the domain rather than the IP: Gmail is deferring mail signed by, or claiming, your domain regardless of which server sends it.
- 550 5.1.1 The email account that you tried to reach does not existPermanentThere is no mailbox at that address on Gmail or on the Workspace domain.
- 552 5.2.2 The email account that you tried to reach is over quotaPermanentThe recipient's Google storage is full, so Gmail cannot accept new mail for them.
- 550 5.4.5 Daily sending quota exceededPermanentThis one comes back when you send through Gmail, not to it.
- 554 5.7.0 Too many unauthenticated messagesPermanentGmail has stopped accepting mail from a sender that keeps arriving without working SPF or DKIM.
- 450 4.2.1 The user you are trying to contact is receiving mail at a rate that prevents additional messages from being deliveredTemporaryThe limit here belongs to the recipient, not to you.
- 550 5.7.25 The IP address sending this message does not have a PTR record setupPermanentGmail looked up the reverse DNS of the connecting IP and either found nothing or found a hostname that does not resolve back to that IP.
Microsoft 365 and Outlook.com
- 550 5.7.1 Service unavailable, Client host blocked using Spamhaus (S3140, S3150)PermanentMicrosoft refused the connection because the sending IP is on a blocklist.
- 550 5.4.1 Recipient address rejected: Access deniedPermanentExchange Online looked the recipient up in the tenant's directory and did not find it, so it refused the address at RCPT TO.
- 550 5.7.606 Access denied, banned sending IPPermanentThe sending IP is on Microsoft's blocklist for Microsoft 365 recipients.
- 550 5.7.708 Service unavailable, access denied, traffic not accepted from this IPPermanentMicrosoft is declining all traffic from the sending IP, a softer cousin of the 5.7.606 ban.
- 451 4.7.500 Server busy, please try again laterTemporaryMicrosoft is throttling your IP.
- 554 5.2.0 STOREDRV.Deliver; delivery result bannerPermanentThe message was accepted by Exchange Online and then failed while being written into the recipient's mailbox.
- 550 5.7.23 The message was rejected because of Sender Policy Framework violationPermanentThe recipient's Microsoft 365 tenant rejects mail that fails SPF, and yours did.
- 550 5.7.509 Access denied, sending domain does not pass DMARC verificationPermanentYour domain publishes a DMARC policy of reject, the message failed DMARC, and Microsoft did what the policy asked.
- 550 5.4.310 DNS domain does not existPermanentA Microsoft 365 user tried to send to a domain and Exchange Online could not find it in DNS: no MX record, no A record, nothing.
- 550 5.7.350 Remote server returned message detected as spamPermanentMail sent from a Microsoft 365 mailbox was handed to the next server, and that server refused it as spam; Exchange Online passes the verdict back to the sender with this code.
- 550 5.1.10 RESOLVER.ADR.RecipientNotFound; Recipient not found by SMTP address lookupPermanentExchange tried to resolve the recipient address against its directory and found nothing.
- 4.4.7 Message delayed, QUEUE.Expired; message expiredPermanentExchange tried to deliver the message for as long as it is allowed to (two days by default in Exchange Online) and gave up.
- 554 5.4.14 Hop count exceeded, possible mail loopPermanentThe message passed through more servers than Exchange allows and was discarded as a loop.
Yahoo and AOL
- 421 4.7.0 [TSS04] Messages from IP temporarily deferred due to unexpected volume or user complaintsTemporaryYahoo is slowing your IP down.
- 554 5.7.9 Message not accepted for policy reasonsPermanentYahoo rejected the message because it failed DMARC and the sending domain's policy says to reject, or because the message failed Yahoo's own authentication requirements for bulk mail.
- 553 5.7.1 [BL21] Connections will not be accepted from IP because the IP is in Spamhaus's listPermanentYahoo refused the connection because the sending IP is on a Spamhaus list.
- 553 5.7.2 [TSS09] All messages from IP will be permanently deferredPermanentThis is the step after TSS04.
- 554 delivery error: dd This user doesn't have a yahoo.com accountPermanentThe recipient address does not exist at Yahoo.
Apple iCloud Mail
Amazon SES
- 554 Message rejected: Email address is not verifiedPermanentAmazon SES refused to send because the From address, or its domain, has not been verified in the SES console for the region you are using.
- 454 Throttling failure: Maximum sending rate exceededTemporaryYour application is submitting to SES faster than the account's per-second sending rate, or has used its 24-hour quota (the wording is then "Daily message quota exceeded").
Any mail server
- 421 Service not available, closing transmission channelTemporaryThe server is ending the session and wants you to come back later.
- 450 4.1.1 Recipient address rejected: unverified address / mailbox unavailableTemporaryThe server could not confirm the recipient exists right now and is asking you to try again.
- 451 4.3.0 Temporary system problem / temporary lookup failureTemporarySomething inside the receiving server failed while it was handling your message and it is asking you to retry.
- 451 4.7.1 Greylisted, please try again laterTemporaryThe receiving server has never seen this combination of sending IP, sender address and recipient before, so it refuses the first attempt and remembers the triple.
- 452 4.2.2 Mailbox full / over quotaTemporaryThe recipient's mailbox has no room for the message.
- 452 4.5.3 Too many recipientsTemporaryYou tried to address one message to more recipients than the server accepts in a single transaction.
- 550 5.1.1 User unknown / recipient address rejectedPermanentThe most common bounce there is: the mailbox does not exist.
- 550 5.1.2 Host unknown / bad destination system addressPermanentThe domain part of the recipient address is the problem: it does not resolve, so no server can be found to deliver to.
- 550 5.7.1 Relay access denied / relaying deniedPermanentYou asked a mail server to deliver to a domain it does not host, and it refused because you are not an authorised client.
- 552 5.3.4 Message size exceeds fixed maximum message sizePermanentThe message is larger than the receiving server allows.
- 553 5.1.8 Sender address rejected: Domain not foundPermanentThe receiving server looked up the domain in your envelope sender address and found nothing, so it refuses to accept mail it could never bounce back to you.
- 554 5.7.1 Message rejected / recipient address rejected: access deniedPermanentA policy on the receiving server refused the message, and 5.7.1 is the catch-all code for "delivery not authorised".
- 554 5.7.1 Service unavailable; Client host blocked using zen.spamhaus.orgPermanentThe receiving server checked your IP against a DNS blocklist and found it listed.
- 530 5.7.0 Authentication required / Must issue a STARTTLS command firstPermanentThe server will not go any further until the client does something it has not done yet.
- 535 5.7.8 Authentication credentials invalid / Username and Password not acceptedPermanentThe server rejected the login.
- 501 5.5.4 Invalid HELO/EHLO argument / syntax error in parametersPermanentThe server did not like the arguments your client sent with a command, most often the hostname in HELO or EHLO.
- 553 5.1.3 Bad recipient address syntaxPermanentThe recipient address is not a valid email address as far as the server can tell: a missing @, two @ signs, spaces, quotes in the wrong place, a trailing dot, or characters outside what the server permits.
How to read an SMTP error code
Every bounce starts with three digits, and the first one tells you most of what you need. A 4 means the server wants you to try again later: the message is still in your queue and will usually deliver on its own. A 5 means the server has made up its mind and retrying the same message will fail the same way. The second digit narrows it to syntax (0), information (1), connection (2) or mail system (5), but in practice the words after the code carry more.
Most servers add a second, dotted number called the enhanced status code, such as 5.7.26. Its first digit repeats the verdict (4 temporary, 5 permanent) and its second digit names the part of the system that objected. That second digit is the quickest way to sort a pile of bounces into "fix the list", "fix my server" and "wait".
What the enhanced status classes mean
| Class | Concerns | Typical fix lives in |
|---|---|---|
| x.1.x | Addresses: the recipient or sender mailbox, domain or syntax | Your list, or the recipient's directory |
| x.2.x | The mailbox itself: full, disabled, receiving too fast | The recipient |
| x.3.x | The receiving mail system: disk, database, overload | The receiving server's admin |
| x.4.x | Network and routing: DNS, timeouts, loops, unreachable hosts | DNS records on either side |
| x.5.x | Protocol: bad commands, wrong arguments, unsupported extensions | Your mail client or library |
| x.7.x | Policy and security: authentication, blocklists, spam verdicts, relaying | SPF, DKIM, DMARC, reputation |
The third digit is the specific condition, and providers extend the list with their own numbers, which is why Microsoft has a 5.7.606 and Gmail a 5.7.26. When the text after the code includes a short tag in brackets such as [TSS04] or (S3150), that tag is the provider's own reason code and is worth searching for on its own.
Bounces handled before you see them.
Faivelo sends transactional email through authenticated, reputation-managed infrastructure, retries temporary failures on a sane schedule and suppresses addresses that hard-bounce, so your application gets a clean event instead of a cryptic reply line.
Free tier included. No card needed.
Questions people ask
Other free tools
All tools- Email DNS checkerCheck MX, SPF, DKIM, DMARC and reverse DNS for any domain and get the exact records to add or fix.
- DMARC checkerLook up a domain's DMARC record, read every tag in plain words and see what to tighten next.
- DMARC record generatorBuild a valid DMARC record from a few choices and copy the host and value into your DNS.
- DMARC report analyzerDrop in a DMARC aggregate report and see who is sending as your domain and whether they pass.
- SMTP connection testerConnect to any SMTP server, check TLS and the login step, and see each stage with its timing.
- Email header analyzerPaste raw headers to see every hop, where the delay was, and whether SPF, DKIM and DMARC passed.
- Email address validatorCheck whether an address is well formed, whether its domain accepts mail, and whether it is disposable or a role account.