554 5.4.14 Hop count exceeded, possible mail loop
The message passed through more servers than Exchange allows and was discarded as a loop. Every Received header counts as a hop, and when a domain is set up so that Microsoft forwards to a server that forwards back to Microsoft, the same message circles until the limit (30 hops in Exchange Online) is reached.
What the server replies
554 5.4.14 Hop count exceeded - possible mail loop ATTR34 [DB7EUR06FT029.eop-eur06.prod.protection.outlook.com]
- Sent by
- Microsoft 365
- Type
- PermanentRetry fails
- About
- Connection
- Enhanced code
- 5.4.14
Who sends it
Exchange Online transport, when a message arrives with more Received headers than the hop limit. The ATTR number identifies which routing component spotted it.
Why it happens
- The domain's MX record points to Microsoft 365 but the accepted domain in the tenant is set to Internal Relay, sending unknown recipients to an on-premises server that routes them back to the MX.
- Two mailboxes forward to each other, or a forward goes to a distribution group that contains the original mailbox.
- A hybrid connector pair where both sides think the other is authoritative for the domain.
- A third-party filtering service in front of Microsoft 365 that is also configured as the outbound smart host.
How to fix it
Read the Received headers
The NDR includes the original headers. The same two or three hostnames repeating tell you exactly which servers are bouncing the message between them.
Fix the accepted domain
If the mailbox lives in Microsoft 365, the accepted domain should be Authoritative. Internal Relay is only for domains that are split between systems.
Break the forwarding chain
Remove the forward on one side, or exclude the original mailbox from the group it forwards to.
Check connector direction
For hybrid or filtering setups, confirm inbound and outbound connectors are not both pointing at the same external host for the same domain.
Check it yourself
These free tools show the records and connections behind this code for your own domain or server.
Related codes
- 4.4.7 Message delayed, QUEUE.Expired; message expiredExchange tried to deliver the message for as long as it is allowed to (two days by default in Exchange Online) and gave up.
- 550 5.1.10 RESOLVER.ADR.RecipientNotFound; Recipient not found by SMTP address lookupExchange tried to resolve the recipient address against its directory and found nothing.
- 550 5.4.1 Recipient address rejected: Access deniedExchange Online looked the recipient up in the tenant's directory and did not find it, so it refused the address at RCPT TO.
Sources
Fewer bounces to look up.
Faivelo sends from authenticated, warmed infrastructure, turns permanent bounces into one clean event for your application and keeps the address out of future sends.
Free tier included. No card needed.
Other free tools
All tools- Email DNS checkerCheck MX, SPF, DKIM, DMARC and reverse DNS for any domain and get the exact records to add or fix.
- DMARC checkerLook up a domain's DMARC record, read every tag in plain words and see what to tighten next.
- DMARC record generatorBuild a valid DMARC record from a few choices and copy the host and value into your DNS.
- DMARC report analyzerDrop in a DMARC aggregate report and see who is sending as your domain and whether they pass.
- SMTP connection testerConnect to any SMTP server, check TLS and the login step, and see each stage with its timing.
- Email header analyzerPaste raw headers to see every hop, where the delay was, and whether SPF, DKIM and DMARC passed.
- Email address validatorCheck whether an address is well formed, whether its domain accepts mail, and whether it is disposable or a role account.