550 5.7.606 Access denied, banned sending IP
The sending IP is on Microsoft's blocklist for Microsoft 365 recipients. It is the Exchange Online Protection counterpart of Outlook.com's S3140. The message is refused for every tenant until the IP is delisted, and the reply tells you where to apply.
What the server replies
550 5.7.606 Access denied, banned sending IP [203.0.113.10]. To request removal from this list please visit https://sender.office.com/ and follow the directions. For more information please go to http://go.microsoft.com/fwlink/?LinkID=526655 AS(1410) [SN1NAM02FT012.eop-nam02.prod.protection.outlook.com]
- Sent by
- Microsoft 365
- Type
- PermanentRetry fails
- About
- Reputation and blocklists
- Enhanced code
- 5.7.606
Who sends it
Exchange Online Protection at connection or MAIL FROM, for mail from an IP Microsoft has banned. It affects mail to any Microsoft 365 hosted domain, not only outlook.com addresses.
Why it happens
- Spam or phishing was sent from the IP, often by a compromised account or a web form abused as a relay.
- The IP is new to sending and jumped straight to volume, which Microsoft reads as a spam run.
- Reputation inherited from a previous tenant of the IP.
- Repeated delivery attempts to addresses that do not exist in Microsoft tenants.
How to fix it
Find and stop the abuse
Check the outbound queue and logs for the hours before the first bounce. Look for a single account or script with unusual volume, and disable it.
Submit the delist request
Use the sender support portal at sender.office.com with the exact IP. Automated removals are usually processed within a day; if the form says the IP is not eligible, Microsoft still sees abuse from it.
Prepare the IP for the retry
Confirm the PTR record, SPF and DKIM before mail resumes. A delisted IP with no authentication is relisted faster than it was removed.
Enrol in SNDS
Microsoft's Smart Network Data Services shows complaint rates and trap hits per IP so the next problem is visible before it becomes a ban.
Check it yourself
These free tools show the records and connections behind this code for your own domain or server.
Related codes
- 550 5.7.1 Service unavailable, Client host blocked using Spamhaus (S3140, S3150)Microsoft refused the connection because the sending IP is on a blocklist.
- 550 5.7.708 Service unavailable, access denied, traffic not accepted from this IPMicrosoft is declining all traffic from the sending IP, a softer cousin of the 5.7.606 ban.
- 554 5.7.1 Service unavailable; Client host blocked using zen.spamhaus.orgThe receiving server checked your IP against a DNS blocklist and found it listed.
Sources
Fewer bounces to look up.
Faivelo sends from authenticated, warmed infrastructure, turns permanent bounces into one clean event for your application and keeps the address out of future sends.
Free tier included. No card needed.
Questions people ask
Other free tools
All tools- Email DNS checkerCheck MX, SPF, DKIM, DMARC and reverse DNS for any domain and get the exact records to add or fix.
- DMARC checkerLook up a domain's DMARC record, read every tag in plain words and see what to tighten next.
- DMARC record generatorBuild a valid DMARC record from a few choices and copy the host and value into your DNS.
- DMARC report analyzerDrop in a DMARC aggregate report and see who is sending as your domain and whether they pass.
- SMTP connection testerConnect to any SMTP server, check TLS and the login step, and see each stage with its timing.
- Email header analyzerPaste raw headers to see every hop, where the delay was, and whether SPF, DKIM and DMARC passed.
- Email address validatorCheck whether an address is well formed, whether its domain accepts mail, and whether it is disposable or a role account.