550 5.7.1 Relay access denied / relaying denied
You asked a mail server to deliver to a domain it does not host, and it refused because you are not an authorised client. Servers only relay for their own users; everyone else gets this. It almost always means the client is talking to the wrong server, or is not logged in.
What the server replies
554 5.7.1 <julia.stein@othercompany.com>: Relay access denied
- Sent by
- Any mail server
- Type
- PermanentRetry fails
- About
- Relaying
- Enhanced code
- 5.7.1
Who sends it
Postfix returns "Relay access denied" (with 554 by default, 550 if configured); Exim "relay not permitted"; Exchange "550 5.7.1 Unable to relay" or "Client does not have permissions to send as this sender"; Sendmail "Relaying denied". It happens at RCPT TO.
Why it happens
- An application points its SMTP settings at the inbound MX server of its own domain instead of the submission server (port 587 with authentication).
- The client connected on port 25 without authenticating; most servers only relay for authenticated sessions on 587 or 465.
- The username and password were left out or the client fell back to no authentication after a TLS problem.
- A device on the network (printer, scanner) relays through a server that no longer has its IP in the allowed list.
How to fix it
Use the submission port and log in
Configure the client with the provider's submission host on port 587 (STARTTLS) or 465 (TLS) and a username and password. Relaying for authenticated users is what those ports are for.
Check which server you are talking to
An SMTP test against the configured host shows its EHLO capabilities; if AUTH is not offered, it is an inbound-only server and will never relay for you.
Admin: allow the client
If a device cannot authenticate, add its IP to mynetworks (Postfix) or create a receive connector for it (Exchange). Keep that list short.
Check it yourself
These free tools show the records and connections behind this code for your own domain or server.
Related codes
- 530 5.7.0 Authentication required / Must issue a STARTTLS command firstThe server will not go any further until the client does something it has not done yet.
- 535 5.7.8 Authentication credentials invalid / Username and Password not acceptedThe server rejected the login.
- 554 5.7.1 Message rejected / recipient address rejected: access deniedA policy on the receiving server refused the message, and 5.7.1 is the catch-all code for "delivery not authorised".
Sources
Fewer bounces to look up.
Faivelo sends from authenticated, warmed infrastructure, turns permanent bounces into one clean event for your application and keeps the address out of future sends.
Free tier included. No card needed.
Other free tools
All tools- Email DNS checkerCheck MX, SPF, DKIM, DMARC and reverse DNS for any domain and get the exact records to add or fix.
- DMARC checkerLook up a domain's DMARC record, read every tag in plain words and see what to tighten next.
- DMARC record generatorBuild a valid DMARC record from a few choices and copy the host and value into your DNS.
- DMARC report analyzerDrop in a DMARC aggregate report and see who is sending as your domain and whether they pass.
- SMTP connection testerConnect to any SMTP server, check TLS and the login step, and see each stage with its timing.
- Email header analyzerPaste raw headers to see every hop, where the delay was, and whether SPF, DKIM and DMARC passed.
- Email address validatorCheck whether an address is well formed, whether its domain accepts mail, and whether it is disposable or a role account.