550 5.7.1 Relay access denied / relaying denied

You asked a mail server to deliver to a domain it does not host, and it refused because you are not an authorised client. Servers only relay for their own users; everyone else gets this. It almost always means the client is talking to the wrong server, or is not logged in.

What the server replies

554 5.7.1 <julia.stein@othercompany.com>: Relay access denied

Sent by
Any mail server
Type
PermanentRetry fails
About
Relaying
Enhanced code
5.7.1

Who sends it

Postfix returns "Relay access denied" (with 554 by default, 550 if configured); Exim "relay not permitted"; Exchange "550 5.7.1 Unable to relay" or "Client does not have permissions to send as this sender"; Sendmail "Relaying denied". It happens at RCPT TO.

Why it happens

  • An application points its SMTP settings at the inbound MX server of its own domain instead of the submission server (port 587 with authentication).
  • The client connected on port 25 without authenticating; most servers only relay for authenticated sessions on 587 or 465.
  • The username and password were left out or the client fell back to no authentication after a TLS problem.
  • A device on the network (printer, scanner) relays through a server that no longer has its IP in the allowed list.

How to fix it

  1. Use the submission port and log in

    Configure the client with the provider's submission host on port 587 (STARTTLS) or 465 (TLS) and a username and password. Relaying for authenticated users is what those ports are for.

  2. Check which server you are talking to

    An SMTP test against the configured host shows its EHLO capabilities; if AUTH is not offered, it is an inbound-only server and will never relay for you.

  3. Admin: allow the client

    If a device cannot authenticate, add its IP to mynetworks (Postfix) or create a receive connector for it (Exchange). Keep that list short.

Check it yourself

These free tools show the records and connections behind this code for your own domain or server.

Related codes

Sources

Fewer bounces to look up.

Faivelo sends from authenticated, warmed infrastructure, turns permanent bounces into one clean event for your application and keeps the address out of future sends.

Send with Faivelo

Free tier included. No card needed.