550 5.7.509 Access denied, sending domain does not pass DMARC verification

Your domain publishes a DMARC policy of reject, the message failed DMARC, and Microsoft did what the policy asked. Neither SPF nor DKIM produced a pass aligned with the From domain. The policy is yours, so this is often self-inflicted: the domain owner tightened DMARC before every sending service was authenticated.

What the server replies

550 5.7.509 Access denied, sending domain example.com does not pass DMARC verification and has a DMARC policy of reject. [AM5EUR03FT009.eop-EUR03.prod.protection.outlook.com]

Sent by
Microsoft 365
Type
PermanentRetry fails
About
Authentication
Enhanced code
5.7.509

Who sends it

Exchange Online Protection after DATA, for any message from a domain with p=reject that fails alignment. Microsoft began honouring p=reject fully in 2023; before that, failing mail was quarantined.

Why it happens

  • A service sends with your domain in From but signs DKIM with its own domain and uses its own bounce domain for SPF, so nothing aligns.
  • DMARC was moved to p=reject while a legitimate sender was still unauthenticated.
  • The message was forwarded or passed through a mailing list that modified it and broke the DKIM signature.
  • The DKIM key for the sending service was removed or rotated and the new one was never published.

How to fix it

  1. Read your DMARC aggregate reports

    The rua reports list every source sending as your domain and whether each one aligns. The failing source in the bounce will be there with its IP.

  2. Authenticate the source

    Set up DKIM signing with your domain at the service that sent the message (custom DKIM or a CNAME to their key), and add its SPF include or a custom bounce domain so the envelope sender aligns.

  3. Step the policy back if you must

    If you cannot fix the sender immediately and the mail matters, move to p=quarantine, or p=none with reports, until it is authenticated. Then return to reject.

  4. Use strict alignment carefully

    adkim=s and aspf=s require exact domain matches. Most organisations should leave alignment relaxed so subdomains align.

Check it yourself

These free tools show the records and connections behind this code for your own domain or server.

Related codes

Sources

Fewer bounces to look up.

Faivelo sends from authenticated, warmed infrastructure, turns permanent bounces into one clean event for your application and keeps the address out of future sends.

Send with Faivelo

Free tier included. No card needed.

Questions people ask