550 5.7.708 Service unavailable, access denied, traffic not accepted from this IP
Microsoft is declining all traffic from the sending IP, a softer cousin of the 5.7.606 ban. It happens typically because it has no sending history with Microsoft at all or because its behaviour looks like a new spam source. Unlike a ban, it often lifts after a quiet period and a delist request is usually accepted on the first try.
What the server replies
550 5.7.708 Service unavailable. Access denied, traffic not accepted from this IP. For more information please go to http://go.microsoft.com/fwlink/?LinkId=526653 AS(1430) [BN8NAM12FT024.eop-nam12.prod.protection.outlook.com]
- Sent by
- Microsoft 365
- Type
- PermanentRetry fails
- About
- Reputation and blocklists
- Enhanced code
- 5.7.708
Who sends it
Exchange Online Protection, at connection, for IPs it does not trust yet. Brand-new mail servers and freshly provisioned cloud instances see it on their first sends to Microsoft 365 domains.
Why it happens
- A new IP with no reputation sent a burst of mail to Microsoft 365 recipients.
- The IP is in a cloud provider range that Microsoft rate-limits by default.
- Missing PTR record, so Microsoft has nothing to anchor the IP's identity to.
- A smaller-scale version of the abuse that leads to 5.7.606.
How to fix it
Pause sends to Microsoft domains for a few hours
Keep the queue but reduce the retry rate. Much of the time the block clears on its own once the burst has passed.
Delist through the portal
If it persists beyond a day, submit the IP at sender.office.com. 5.7.708 removals are usually automatic.
Warm the IP
Begin with a few dozen messages a day to Microsoft recipients who know you, and increase over two weeks. Microsoft builds trust from the number of recipients who do not report you.
Fix reverse DNS and authentication
Set the PTR record to your mail hostname, publish SPF, sign with DKIM, and publish DMARC. Each one raises the starting trust of a new IP.
Check it yourself
These free tools show the records and connections behind this code for your own domain or server.
Related codes
- 550 5.7.606 Access denied, banned sending IPThe sending IP is on Microsoft's blocklist for Microsoft 365 recipients.
- 550 5.7.1 Service unavailable, Client host blocked using Spamhaus (S3140, S3150)Microsoft refused the connection because the sending IP is on a blocklist.
- 451 4.7.500 Server busy, please try again laterMicrosoft is throttling your IP.
- 550 5.7.25 The IP address sending this message does not have a PTR record setupGmail looked up the reverse DNS of the connecting IP and either found nothing or found a hostname that does not resolve back to that IP.
Sources
Fewer bounces to look up.
Faivelo sends from authenticated, warmed infrastructure, turns permanent bounces into one clean event for your application and keeps the address out of future sends.
Free tier included. No card needed.
Other free tools
All tools- Email DNS checkerCheck MX, SPF, DKIM, DMARC and reverse DNS for any domain and get the exact records to add or fix.
- DMARC checkerLook up a domain's DMARC record, read every tag in plain words and see what to tighten next.
- DMARC record generatorBuild a valid DMARC record from a few choices and copy the host and value into your DNS.
- DMARC report analyzerDrop in a DMARC aggregate report and see who is sending as your domain and whether they pass.
- SMTP connection testerConnect to any SMTP server, check TLS and the login step, and see each stage with its timing.
- Email header analyzerPaste raw headers to see every hop, where the delay was, and whether SPF, DKIM and DMARC passed.
- Email address validatorCheck whether an address is well formed, whether its domain accepts mail, and whether it is disposable or a role account.