550 5.4.1 Recipient address rejected: Access denied
Exchange Online looked the recipient up in the tenant's directory and did not find it, so it refused the address at RCPT TO. This is Directory-Based Edge Blocking (DBEB). The recipient domain is real and hosted at Microsoft; the mailbox is not. For you it behaves like "user unknown"; for the tenant's admin it can also be a sync problem.
What the server replies
550 5.4.1 Recipient address rejected: Access denied. AS(201806281) [DB5EUR01FT043.eop-EUR01.prod.protection.outlook.com]
- Sent by
- Microsoft 365
- Type
- PermanentRetry fails
- About
- Recipient problems
- Enhanced code
- 5.4.1
Who sends it
Exchange Online Protection edge servers (eop-*.prod.protection.outlook.com) at RCPT TO, for any address in a Microsoft 365 domain that is not an active mailbox, group, contact or alias.
Why it happens
- The address does not exist or was deleted.
- The user was created on-premises and Entra Connect has not synced the mailbox to the cloud yet.
- The domain is set to Authoritative in Microsoft 365 but some addresses live on another system; it should be Internal Relay.
- A typo in the address, including a wrong domain that happens to belong to another Microsoft tenant.
How to fix it
Confirm the address with the recipient
For an outside sender this is the whole fix. If the recipient says the address is right, the problem is in their tenant and the next steps are for their admin.
Admin: check the recipient exists in Exchange Online
Search the address in the Exchange admin center. If it is missing, force a directory sync or create the mail user. Shared mailboxes with no licence still need to exist as recipients.
Admin: check the domain type
If some addresses in the domain are hosted elsewhere, set the accepted domain to Internal Relay so EOP forwards unknown recipients instead of rejecting them.
Suppress after confirming
Senders should treat a confirmed 5.4.1 like any hard bounce and stop sending to it.
Check it yourself
These free tools show the records and connections behind this code for your own domain or server.
Related codes
- 550 5.1.10 RESOLVER.ADR.RecipientNotFound; Recipient not found by SMTP address lookupExchange tried to resolve the recipient address against its directory and found nothing.
- 550 5.1.1 The email account that you tried to reach does not existThere is no mailbox at that address on Gmail or on the Workspace domain.
- 550 5.1.1 User unknown / recipient address rejectedThe most common bounce there is: the mailbox does not exist.
- 550 5.4.310 DNS domain does not existA Microsoft 365 user tried to send to a domain and Exchange Online could not find it in DNS: no MX record, no A record, nothing.
Sources
Fewer bounces to look up.
Faivelo sends from authenticated, warmed infrastructure, turns permanent bounces into one clean event for your application and keeps the address out of future sends.
Free tier included. No card needed.
Questions people ask
Other free tools
All tools- Email DNS checkerCheck MX, SPF, DKIM, DMARC and reverse DNS for any domain and get the exact records to add or fix.
- DMARC checkerLook up a domain's DMARC record, read every tag in plain words and see what to tighten next.
- DMARC record generatorBuild a valid DMARC record from a few choices and copy the host and value into your DNS.
- DMARC report analyzerDrop in a DMARC aggregate report and see who is sending as your domain and whether they pass.
- SMTP connection testerConnect to any SMTP server, check TLS and the login step, and see each stage with its timing.
- Email header analyzerPaste raw headers to see every hop, where the delay was, and whether SPF, DKIM and DMARC passed.
- Email address validatorCheck whether an address is well formed, whether its domain accepts mail, and whether it is disposable or a role account.