554 5.7.9 Message not accepted for policy reasons
Yahoo rejected the message because it failed DMARC and the sending domain's policy says to reject, or because the message failed Yahoo's own authentication requirements for bulk mail. Yahoo was the first large mailbox provider to enforce p=reject, back in 2014, and it does so without exception.
What the server replies
554 5.7.9 Message not accepted for policy reasons. See https://senders.yahooinc.com/error-codes
- Sent by
- Yahoo and AOL
- Type
- PermanentRetry fails
- About
- Authentication
- Enhanced code
- 5.7.9
Who sends it
Yahoo and AOL inbound servers after DATA, once SPF, DKIM and DMARC have been evaluated. The 5.7.9 enhanced code is defined for "DKIM signature not acceptable" and Yahoo uses it for DMARC enforcement generally.
Why it happens
- The From domain has p=reject and the message was neither SPF-aligned nor DKIM-aligned.
- Mail sent "on behalf of" a Yahoo or AOL address from a third-party service; yahoo.com itself is p=reject, so only Yahoo's own servers can send as it.
- A mailing list that keeps the original From address but modifies the body, breaking the DKIM signature.
- The DKIM key in DNS was rotated or removed and messages are signed with the old one.
How to fix it
Check the From domain's DMARC
Look up _dmarc.<from domain>. If the policy is reject, every source sending as that domain must pass aligned SPF or DKIM.
Sign with the From domain
Enable DKIM at the service that sent the message using a key published under your domain, so header.d matches the From domain.
Never send from yahoo.com or aol.com addresses through other servers
If customers sign up with Yahoo addresses and you send on their behalf, use your own domain in From and put their address in Reply-To.
For mailing lists, rewrite From
List software should rewrite the From header to the list's domain when the original domain publishes p=reject, which is what Mailman and Google Groups do by default.
Check it yourself
These free tools show the records and connections behind this code for your own domain or server.
- DMARC checkerLook up a domain's DMARC record, read every tag in plain words and see what to tighten next.
- Email header analyzerPaste raw headers to see every hop, where the delay was, and whether SPF, DKIM and DMARC passed.
- DMARC report analyzerDrop in a DMARC aggregate report and see who is sending as your domain and whether they pass.
Related codes
- 550 5.7.509 Access denied, sending domain does not pass DMARC verificationYour domain publishes a DMARC policy of reject, the message failed DMARC, and Microsoft did what the policy asked.
- 550 5.7.26 This mail has been blocked because the sender is unauthenticatedGmail refused the message because neither SPF nor DKIM passed for the sending domain.
- 553 5.7.1 [BL21] Connections will not be accepted from IP because the IP is in Spamhaus's listYahoo refused the connection because the sending IP is on a Spamhaus list.
Sources
Fewer bounces to look up.
Faivelo sends from authenticated, warmed infrastructure, turns permanent bounces into one clean event for your application and keeps the address out of future sends.
Free tier included. No card needed.
Other free tools
All tools- Email DNS checkerCheck MX, SPF, DKIM, DMARC and reverse DNS for any domain and get the exact records to add or fix.
- DMARC checkerLook up a domain's DMARC record, read every tag in plain words and see what to tighten next.
- DMARC record generatorBuild a valid DMARC record from a few choices and copy the host and value into your DNS.
- DMARC report analyzerDrop in a DMARC aggregate report and see who is sending as your domain and whether they pass.
- SMTP connection testerConnect to any SMTP server, check TLS and the login step, and see each stage with its timing.
- Email header analyzerPaste raw headers to see every hop, where the delay was, and whether SPF, DKIM and DMARC passed.
- Email address validatorCheck whether an address is well formed, whether its domain accepts mail, and whether it is disposable or a role account.