554 5.7.1 Message rejected / recipient address rejected: access denied

A policy on the receiving server refused the message, and 5.7.1 is the catch-all code for "delivery not authorised". The text after it is what matters: access denied, blocked, not permitted, policy rejection. Without more words it means the server has a rule, local to it, that your message tripped.

What the server replies

554 5.7.1 <tom.becker@example.com>: Recipient address rejected: Access denied

Sent by
Any mail server
Type
PermanentRetry fails
About
Receiver policy
Enhanced code
5.7.1

Who sends it

Every MTA uses 5.7.1 for local policy. Postfix emits it for access-map rejections and for RBL hits; Exchange for transport rules and recipient restrictions ("Recipient not authorized, your IP has been found on a block list"); Gmail and Yahoo for content and reputation blocks; cPanel hosts for "message rejected due to local policy".

Why it happens

  • The sender address, domain or IP is on the recipient server's local block list.
  • A transport rule in the recipient organisation blocks the content, attachment type or sender.
  • A distribution list or shared mailbox only accepts messages from authenticated internal users.
  • The sending IP is on a public blocklist consulted by the server (see the blocklist variant).

How to fix it

  1. Read the whole reply

    Every server adds words after 5.7.1. "Blocklist" points you to the blocklist page; "Recipient not authorized" means the address only accepts certain senders; "local policy" means a rule you cannot see.

  2. Ask the recipient

    For a one-off, the recipient's administrator can look up the message in their logs or message trace and tell you which rule rejected it. They can also allow-list you.

  3. Check your own hygiene

    Run your domain through a DNS checker. Senders that pass SPF, DKIM and DMARC with a proper PTR record trip far fewer local policies.

Check it yourself

These free tools show the records and connections behind this code for your own domain or server.

Related codes

Sources

Fewer bounces to look up.

Faivelo sends from authenticated, warmed infrastructure, turns permanent bounces into one clean event for your application and keeps the address out of future sends.

Send with Faivelo

Free tier included. No card needed.