550 5.7.23 The message was rejected because of Sender Policy Framework violation
The recipient's Microsoft 365 tenant rejects mail that fails SPF, and yours did. Microsoft does not reject on SPF failure by default; this reply means the tenant has a mail flow rule or a strict anti-spoofing policy that turns an SPF fail into a hard bounce. The sending IP was not in the SPF record of the domain in MAIL FROM.
What the server replies
550 5.7.23 The message was rejected because of Sender Policy Framework violation -> 550 5.7.23 SPF validation failed
- Sent by
- Microsoft 365
- Type
- PermanentRetry fails
- About
- Authentication
- Enhanced code
- 5.7.23
Who sends it
Exchange Online Protection, after DATA, for tenants whose admin configured a rule on the SPF result. Enhanced code 5.7.23 is defined as "SPF validation failed" in RFC 7372.
Why it happens
- A new sending service was added without updating the SPF record.
- The envelope sender (Return-Path) domain is different from the From domain and has no SPF of its own.
- The SPF record exceeds ten DNS lookups, which evaluates as a permanent error and is treated as fail by strict tenants.
- The message was forwarded by an intermediate server that is not in your SPF.
How to fix it
Identify the envelope sender
SPF checks the domain in MAIL FROM, which is often a bounce address like bounces.example.com set by your sending platform. That domain, not the From header's, needs the SPF record.
Add the sending source
Append the provider's include or the server's ip4 to that domain's SPF TXT record and keep the total lookups under ten.
Sign with DKIM as well
A tenant that rejects on SPF alone is rare; most check DMARC, which also passes on an aligned DKIM signature. Signing protects you when forwarding breaks SPF.
Ask the recipient about forwarding
If they forward from another address into Microsoft 365, the forwarder's IP fails SPF and only SRS or DKIM can save it.
Check it yourself
These free tools show the records and connections behind this code for your own domain or server.
- Email DNS checkerCheck MX, SPF, DKIM, DMARC and reverse DNS for any domain and get the exact records to add or fix.
- Email header analyzerPaste raw headers to see every hop, where the delay was, and whether SPF, DKIM and DMARC passed.
- DMARC checkerLook up a domain's DMARC record, read every tag in plain words and see what to tighten next.
Related codes
- 550 5.7.509 Access denied, sending domain does not pass DMARC verificationYour domain publishes a DMARC policy of reject, the message failed DMARC, and Microsoft did what the policy asked.
- 550 5.7.26 This mail has been blocked because the sender is unauthenticatedGmail refused the message because neither SPF nor DKIM passed for the sending domain.
- 554 5.7.9 Message not accepted for policy reasonsYahoo rejected the message because it failed DMARC and the sending domain's policy says to reject, or because the message failed Yahoo's own authentication requirements for bulk mail.
Sources
Fewer bounces to look up.
Faivelo sends from authenticated, warmed infrastructure, turns permanent bounces into one clean event for your application and keeps the address out of future sends.
Free tier included. No card needed.
Questions people ask
Other free tools
All tools- Email DNS checkerCheck MX, SPF, DKIM, DMARC and reverse DNS for any domain and get the exact records to add or fix.
- DMARC checkerLook up a domain's DMARC record, read every tag in plain words and see what to tighten next.
- DMARC record generatorBuild a valid DMARC record from a few choices and copy the host and value into your DNS.
- DMARC report analyzerDrop in a DMARC aggregate report and see who is sending as your domain and whether they pass.
- SMTP connection testerConnect to any SMTP server, check TLS and the login step, and see each stage with its timing.
- Email header analyzerPaste raw headers to see every hop, where the delay was, and whether SPF, DKIM and DMARC passed.
- Email address validatorCheck whether an address is well formed, whether its domain accepts mail, and whether it is disposable or a role account.