550 5.7.350 Remote server returned message detected as spam
Mail sent from a Microsoft 365 mailbox was handed to the next server, and that server refused it as spam; Exchange Online passes the verdict back to the sender with this code. Very often the "remote server" is another Microsoft 365 tenant or the sender's own on-premises filter, so the mail never left Microsoft's network.
What the server replies
550 5.7.350 Remote server returned message detected as spam -> 550 5.7.350 Remote server returned message detected as spam
- Sent by
- Microsoft 365
- Type
- PermanentRetry fails
- About
- Content
- Enhanced code
- 5.7.350
Who sends it
Exchange Online transport, as the sending side, after a downstream server replied with a spam rejection. The NDR is addressed to the Microsoft 365 user who sent the message.
Why it happens
- The recipient tenant's anti-spam policy is set to reject rather than quarantine high-confidence spam, and the message scored high.
- The sending tenant's own outbound spam filter flagged the message.
- The content contains a URL on a blocklist, a suspicious attachment type, or phishing-like wording.
- A connector routes outbound mail through an on-premises appliance that rejected it.
How to fix it
Send a trimmed version
Remove links, attachments and signature images and resend. If the plain message arrives, add elements back one at a time to find the trigger.
Check the URLs
Links to shortened URLs, newly registered domains or file-sharing pages set off Microsoft's filters. Link to pages on an established domain.
Admin: trace the message
In the Exchange admin center run a message trace for the sender; the trace shows which server returned the rejection and whether an outbound policy or a connector was involved.
Ask the recipient admin to allow the sender
If the remote server is another tenant, their admin can add the sender to the Tenant Allow/Block List after confirming the mail is legitimate.
Check it yourself
These free tools show the records and connections behind this code for your own domain or server.
Related codes
- 550 5.7.1 Our system has detected that this message is likely unsolicited mailGmail's spam filter scored the message as spam before it reached a mailbox and rejected it at the SMTP level rather than placing it in the Spam folder.
- 554 5.7.1 Message rejected / recipient address rejected: access deniedA policy on the receiving server refused the message, and 5.7.1 is the catch-all code for "delivery not authorised".
- 554 5.7.1 [CS01] Message rejected due to local policyiCloud Mail refused the message on reputation or policy grounds.
Sources
Fewer bounces to look up.
Faivelo sends from authenticated, warmed infrastructure, turns permanent bounces into one clean event for your application and keeps the address out of future sends.
Free tier included. No card needed.
Other free tools
All tools- Email DNS checkerCheck MX, SPF, DKIM, DMARC and reverse DNS for any domain and get the exact records to add or fix.
- DMARC checkerLook up a domain's DMARC record, read every tag in plain words and see what to tighten next.
- DMARC record generatorBuild a valid DMARC record from a few choices and copy the host and value into your DNS.
- DMARC report analyzerDrop in a DMARC aggregate report and see who is sending as your domain and whether they pass.
- SMTP connection testerConnect to any SMTP server, check TLS and the login step, and see each stage with its timing.
- Email header analyzerPaste raw headers to see every hop, where the delay was, and whether SPF, DKIM and DMARC passed.
- Email address validatorCheck whether an address is well formed, whether its domain accepts mail, and whether it is disposable or a role account.