554 5.7.1 Service unavailable; Client host blocked using zen.spamhaus.org
The receiving server checked your IP against a DNS blocklist and found it listed. This is the Postfix wording (reject_rbl_client) and it names the list, which is the useful part. Spamhaus ZEN is the most common; others include Barracuda (b.barracudacentral.org), SpamCop (bl.spamcop.net) and SORBS.
What the server replies
554 5.7.1 Service unavailable; Client host [203.0.113.10] blocked using zen.spamhaus.org; https://www.spamhaus.org/query/ip/203.0.113.10
- Sent by
- Any mail server
- Type
- PermanentRetry fails
- About
- Reputation and blocklists
- Enhanced code
- 5.7.1
Who sends it
Any server configured to query DNS blocklists, which is most self-hosted and small-provider servers. It is sent at RCPT TO or at connection, before content.
Why it happens
- Spam or malware traffic from the IP, now or recently.
- The IP is in a dynamic or residential range (Spamhaus PBL).
- A previous owner of the IP got it listed.
- A listing of the whole /24 because of a neighbour.
How to fix it
Look up the named list
The reply tells you which list. Check the IP on that list's site to see the reason and the removal process.
Fix the cause
For an active listing, find and stop the source: a compromised account, a vulnerable web form, an infected host. Listings return quickly otherwise.
Request removal
Spamhaus and SpamCop removals are self-service once the traffic has stopped. Barracuda needs a form. PBL listings cannot be removed for the range; relay through a provider instead.
Check other lists while you are there
A multi-list lookup shows whether you are on lists you have not been bounced by yet.
Check it yourself
These free tools show the records and connections behind this code for your own domain or server.
Related codes
- 550 5.7.1 Service unavailable, Client host blocked using Spamhaus (S3140, S3150)Microsoft refused the connection because the sending IP is on a blocklist.
- 553 5.7.1 [BL21] Connections will not be accepted from IP because the IP is in Spamhaus's listYahoo refused the connection because the sending IP is on a Spamhaus list.
- 550 5.7.606 Access denied, banned sending IPThe sending IP is on Microsoft's blocklist for Microsoft 365 recipients.
- 554 5.7.1 Message rejected / recipient address rejected: access deniedA policy on the receiving server refused the message, and 5.7.1 is the catch-all code for "delivery not authorised".
Sources
Fewer bounces to look up.
Faivelo sends from authenticated, warmed infrastructure, turns permanent bounces into one clean event for your application and keeps the address out of future sends.
Free tier included. No card needed.
Other free tools
All tools- Email DNS checkerCheck MX, SPF, DKIM, DMARC and reverse DNS for any domain and get the exact records to add or fix.
- DMARC checkerLook up a domain's DMARC record, read every tag in plain words and see what to tighten next.
- DMARC record generatorBuild a valid DMARC record from a few choices and copy the host and value into your DNS.
- DMARC report analyzerDrop in a DMARC aggregate report and see who is sending as your domain and whether they pass.
- SMTP connection testerConnect to any SMTP server, check TLS and the login step, and see each stage with its timing.
- Email header analyzerPaste raw headers to see every hop, where the delay was, and whether SPF, DKIM and DMARC passed.
- Email address validatorCheck whether an address is well formed, whether its domain accepts mail, and whether it is disposable or a role account.