554 5.7.1 Message rejected / recipient address rejected: access denied
A policy on the receiving server refused the message, and 5.7.1 is the catch-all code for "delivery not authorised". The text after it is what matters: access denied, blocked, not permitted, policy rejection. Without more words it means the server has a rule, local to it, that your message tripped.
What the server replies
554 5.7.1 <tom.becker@example.com>: Recipient address rejected: Access denied
- Sent by
- Any mail server
- Type
- PermanentRetry fails
- About
- Receiver policy
- Enhanced code
- 5.7.1
Who sends it
Every MTA uses 5.7.1 for local policy. Postfix emits it for access-map rejections and for RBL hits; Exchange for transport rules and recipient restrictions ("Recipient not authorized, your IP has been found on a block list"); Gmail and Yahoo for content and reputation blocks; cPanel hosts for "message rejected due to local policy".
Why it happens
- The sender address, domain or IP is on the recipient server's local block list.
- A transport rule in the recipient organisation blocks the content, attachment type or sender.
- A distribution list or shared mailbox only accepts messages from authenticated internal users.
- The sending IP is on a public blocklist consulted by the server (see the blocklist variant).
How to fix it
Read the whole reply
Every server adds words after 5.7.1. "Blocklist" points you to the blocklist page; "Recipient not authorized" means the address only accepts certain senders; "local policy" means a rule you cannot see.
Ask the recipient
For a one-off, the recipient's administrator can look up the message in their logs or message trace and tell you which rule rejected it. They can also allow-list you.
Check your own hygiene
Run your domain through a DNS checker. Senders that pass SPF, DKIM and DMARC with a proper PTR record trip far fewer local policies.
Check it yourself
These free tools show the records and connections behind this code for your own domain or server.
Related codes
- 554 5.7.1 Service unavailable; Client host blocked using zen.spamhaus.orgThe receiving server checked your IP against a DNS blocklist and found it listed.
- 550 5.7.1 Our system has detected that this message is likely unsolicited mailGmail's spam filter scored the message as spam before it reached a mailbox and rejected it at the SMTP level rather than placing it in the Spam folder.
- 554 5.7.1 [CS01] Message rejected due to local policyiCloud Mail refused the message on reputation or policy grounds.
- 550 5.7.1 Relay access denied / relaying deniedYou asked a mail server to deliver to a domain it does not host, and it refused because you are not an authorised client.
Sources
Fewer bounces to look up.
Faivelo sends from authenticated, warmed infrastructure, turns permanent bounces into one clean event for your application and keeps the address out of future sends.
Free tier included. No card needed.
Other free tools
All tools- Email DNS checkerCheck MX, SPF, DKIM, DMARC and reverse DNS for any domain and get the exact records to add or fix.
- DMARC checkerLook up a domain's DMARC record, read every tag in plain words and see what to tighten next.
- DMARC record generatorBuild a valid DMARC record from a few choices and copy the host and value into your DNS.
- DMARC report analyzerDrop in a DMARC aggregate report and see who is sending as your domain and whether they pass.
- SMTP connection testerConnect to any SMTP server, check TLS and the login step, and see each stage with its timing.
- Email header analyzerPaste raw headers to see every hop, where the delay was, and whether SPF, DKIM and DMARC passed.
- Email address validatorCheck whether an address is well formed, whether its domain accepts mail, and whether it is disposable or a role account.