550 5.4.1 Recipient address rejected: Access denied

Exchange Online looked the recipient up in the tenant's directory and did not find it, so it refused the address at RCPT TO. This is Directory-Based Edge Blocking (DBEB). The recipient domain is real and hosted at Microsoft; the mailbox is not. For you it behaves like "user unknown"; for the tenant's admin it can also be a sync problem.

What the server replies

550 5.4.1 Recipient address rejected: Access denied. AS(201806281) [DB5EUR01FT043.eop-EUR01.prod.protection.outlook.com]

Sent by
Microsoft 365
Type
PermanentRetry fails
About
Recipient problems
Enhanced code
5.4.1

Who sends it

Exchange Online Protection edge servers (eop-*.prod.protection.outlook.com) at RCPT TO, for any address in a Microsoft 365 domain that is not an active mailbox, group, contact or alias.

Why it happens

  • The address does not exist or was deleted.
  • The user was created on-premises and Entra Connect has not synced the mailbox to the cloud yet.
  • The domain is set to Authoritative in Microsoft 365 but some addresses live on another system; it should be Internal Relay.
  • A typo in the address, including a wrong domain that happens to belong to another Microsoft tenant.

How to fix it

  1. Confirm the address with the recipient

    For an outside sender this is the whole fix. If the recipient says the address is right, the problem is in their tenant and the next steps are for their admin.

  2. Admin: check the recipient exists in Exchange Online

    Search the address in the Exchange admin center. If it is missing, force a directory sync or create the mail user. Shared mailboxes with no licence still need to exist as recipients.

  3. Admin: check the domain type

    If some addresses in the domain are hosted elsewhere, set the accepted domain to Internal Relay so EOP forwards unknown recipients instead of rejecting them.

  4. Suppress after confirming

    Senders should treat a confirmed 5.4.1 like any hard bounce and stop sending to it.

Check it yourself

These free tools show the records and connections behind this code for your own domain or server.

Related codes

Sources

Fewer bounces to look up.

Faivelo sends from authenticated, warmed infrastructure, turns permanent bounces into one clean event for your application and keeps the address out of future sends.

Send with Faivelo

Free tier included. No card needed.

Questions people ask