550 5.7.509 Access denied, sending domain does not pass DMARC verification
Your domain publishes a DMARC policy of reject, the message failed DMARC, and Microsoft did what the policy asked. Neither SPF nor DKIM produced a pass aligned with the From domain. The policy is yours, so this is often self-inflicted: the domain owner tightened DMARC before every sending service was authenticated.
What the server replies
550 5.7.509 Access denied, sending domain example.com does not pass DMARC verification and has a DMARC policy of reject. [AM5EUR03FT009.eop-EUR03.prod.protection.outlook.com]
- Sent by
- Microsoft 365
- Type
- PermanentRetry fails
- About
- Authentication
- Enhanced code
- 5.7.509
Who sends it
Exchange Online Protection after DATA, for any message from a domain with p=reject that fails alignment. Microsoft began honouring p=reject fully in 2023; before that, failing mail was quarantined.
Why it happens
- A service sends with your domain in From but signs DKIM with its own domain and uses its own bounce domain for SPF, so nothing aligns.
- DMARC was moved to p=reject while a legitimate sender was still unauthenticated.
- The message was forwarded or passed through a mailing list that modified it and broke the DKIM signature.
- The DKIM key for the sending service was removed or rotated and the new one was never published.
How to fix it
Read your DMARC aggregate reports
The rua reports list every source sending as your domain and whether each one aligns. The failing source in the bounce will be there with its IP.
Authenticate the source
Set up DKIM signing with your domain at the service that sent the message (custom DKIM or a CNAME to their key), and add its SPF include or a custom bounce domain so the envelope sender aligns.
Step the policy back if you must
If you cannot fix the sender immediately and the mail matters, move to p=quarantine, or p=none with reports, until it is authenticated. Then return to reject.
Use strict alignment carefully
adkim=s and aspf=s require exact domain matches. Most organisations should leave alignment relaxed so subdomains align.
Check it yourself
These free tools show the records and connections behind this code for your own domain or server.
- DMARC checkerLook up a domain's DMARC record, read every tag in plain words and see what to tighten next.
- DMARC report analyzerDrop in a DMARC aggregate report and see who is sending as your domain and whether they pass.
- Email header analyzerPaste raw headers to see every hop, where the delay was, and whether SPF, DKIM and DMARC passed.
Related codes
- 554 5.7.9 Message not accepted for policy reasonsYahoo rejected the message because it failed DMARC and the sending domain's policy says to reject, or because the message failed Yahoo's own authentication requirements for bulk mail.
- 550 5.7.26 This mail has been blocked because the sender is unauthenticatedGmail refused the message because neither SPF nor DKIM passed for the sending domain.
- 550 5.7.23 The message was rejected because of Sender Policy Framework violationThe recipient's Microsoft 365 tenant rejects mail that fails SPF, and yours did.
Sources
Fewer bounces to look up.
Faivelo sends from authenticated, warmed infrastructure, turns permanent bounces into one clean event for your application and keeps the address out of future sends.
Free tier included. No card needed.
Questions people ask
Other free tools
All tools- Email DNS checkerCheck MX, SPF, DKIM, DMARC and reverse DNS for any domain and get the exact records to add or fix.
- DMARC checkerLook up a domain's DMARC record, read every tag in plain words and see what to tighten next.
- DMARC record generatorBuild a valid DMARC record from a few choices and copy the host and value into your DNS.
- DMARC report analyzerDrop in a DMARC aggregate report and see who is sending as your domain and whether they pass.
- SMTP connection testerConnect to any SMTP server, check TLS and the login step, and see each stage with its timing.
- Email header analyzerPaste raw headers to see every hop, where the delay was, and whether SPF, DKIM and DMARC passed.
- Email address validatorCheck whether an address is well formed, whether its domain accepts mail, and whether it is disposable or a role account.