AUTHENTICATION

Authentication

550 5.7.1

550 5.7.1 SPF check failed

550 5.7.1 Message rejected due to SPF check failure

The receiving server checked your domain's SPF record and did not find the sending IP in it. Because your record ends in -all, that is an explicit rejection.

permerror

SPF permerror — too many DNS lookups

Received-SPF: permerror (SPF Permanent Error: Too many DNS lookups)

Your SPF record exceeds the limit of 10 DNS-querying mechanisms. The consequence is not “partially valid” but: SPF counts as unevaluable — for all your mail, including from your main server.

550 5.7.26

550 5.7.26 — DMARC policy

550-5.7.26 Unauthenticated email from example.com is not accepted due to domain's DMARC policy

DMARC passes only when SPF or DKIM passes and the domain it checked aligns with the domain in the From: header. That second condition — alignment — is almost always the reason for this message.

body hash

dkim=fail — body hash did not verify

dkim=fail (body hash did not verify) header.d=example.com

This message says something very specific: the key was found, the signature is formally fine — but the message body is no longer the same as when it was signed. Something along the way touched it.

no key

dkim=permerror — no key for signature

dkim=permerror (no key for signature) header.d=example.com header.s=selector1

The receiver read the signature, looked for the matching public key in DNS — and found nothing. The fault is almost always in DNS, not in the mail server.

550 5.7.23

550 5.7.23 SPF validation failed

550 5.7.23 The message was rejected because of Sender Policy Framework violation

This wording comes almost exclusively from Microsoft — Exchange Online and Outlook.com. Substantively it is an SPF hard fail; the 5.7.23 number is Microsoft's own flavour of it.

550 5.7.509

550 5.7.509 does not pass DMARC

550 5.7.509 Access denied, sending domain [example.com] does not pass DMARC verification

Microsoft's phrasing for a DMARC rejection. The key word is verification: it is not SPF or DKIM alone that failed, but their alignment with the domain in the From: header.

554 5.7.5

554 5.7.5 Permanent error evaluating DMARC

554 5.7.5 Permanent error evaluating DMARC policy

This message does not mean your policy struck. It means the receiving server found your DMARC record but could not evaluate it. The record itself is broken.

550 5.7.60

550 5.7.60 send as denied

550 5.7.60 SMTP; Client does not have permissions to send as this sender

The server logged you in successfully and still rejects: the account you identified with is not allowed to use the address in the From header. That is a permissions question, not an authentication question.

temperror

spf=temperror

Received-SPF: temperror (example.com: DNS timeout while looking up SPF record)

Per RFC 7208 temperror means the check was not performable, not negative. Somewhere in the resolution chain DNS gave no usable answer — a different problem from a malformed record.

TRANSPORT

Transport Security

STARTTLS

STARTTLS handshake failed

Cannot start TLS: handshake failure

STARTTLS upgrades an existing plaintext connection on port 25 to an encrypted one. If that transition fails, delivery aborts — even though the server is reachable and DNS resolves correctly.

certificate

certificate verification failed

Server certificate not verified

In SMTP a failed certificate check is often inconsequential — most servers still encrypt opportunistically. The moment MTA-STS or DANE is involved, however, it turns into a hard rejection.

530 5.7.0

530 5.7.0 must issue a STARTTLS command first

530 5.7.0 Must issue a STARTTLS command first

The server cuts the dialogue short before it takes credentials or a sender: no encryption has been negotiated on this connection, and without it nothing proceeds here.

454 4.7.0

454 4.7.0 TLS not available

454 4.7.0 TLS not available due to temporary reason

The server advertised STARTTLS among its capabilities and then refused the negotiation. This is not a mismatch between two sides but a local problem on the answering server.

REPUTATION

Reputation & Blacklists

554 5.7.1

554 5.7.1 — Client host blocked

554 5.7.1 Service unavailable; Client host [203.0.113.5] blocked using zen.spamhaus.org

The message usually names the list that triggered it. That is the most valuable piece of information in it — because lists differ enormously in how much they matter.

421 4.7.0

421 4.7.0 Try again later

421 4.7.0 Try again later, closing connection (MAIL) [ip] - gsmtp

The first digit decides: 4xx is temporary, the message is not lost. Your server will try again. A persistent 421 is still a warning sign — it is practically always about reputation.

550 5.7.606

550 5.7.606 banned sending IP

550 5.7.606 Access denied, banned sending IP [203.0.113.5]

Codes 5.7.606 through 5.7.614 come from Microsoft's own block list. It is not publicly queryable — so an IP can be blocked here while every public DNSBL reports it clean.

450 4.2.0

450 4.2.0 Greylisted

450 4.2.0 <user@example.com>: Recipient address rejected: Greylisted, see http://postgrey.schweikert.ch/help/example.com.html

Greylisting refuses every unknown sender once and lets them through on the second attempt. A real mail server retries automatically, many spam tools do not. A single delay is therefore entirely normal.

550 5.7.708

550 5.7.708 traffic not accepted

550 5.7.708 Access denied, traffic not accepted from this IP. For more information please go to https://go.microsoft.com/fwlink/?LinkId=526653

Microsoft accepts no mail at all from this address. Unlike a listing, this is rarely about your sending behaviour and usually about the address range you sit in.

CONTENT

Content & Attachments

550 5.7.350

550 5.7.350 detected as spam

550 5.7.350 Remote server returned message detected as spam

Unlike a blacklist block, this rejection is about the specific message. Sending IP and authentication may be flawless — what was objected to is the content itself.

552 5.3.4

552 5.3.4 message size exceeds limit

552 5.3.4 Message size exceeds fixed maximum message size (in reply to end of DATA command)

The message is bigger than the file size of the attachments suggests. Attachments are re-encoded for transport and grow by roughly a third in the process — the cause of most surprise about this error.

552 5.7.0

552 5.7.0 blocked attachment

552 5.7.0 This message was blocked because its content presents a potential security issue.

This block targets an attachment, not the message body and not your reputation. It applies regardless of whether anything malicious was found — the file type alone is enough.

INFRASTRUCTURE

DNS & Infrastructure

550 5.7.25

550 5.7.25 — reverse DNS missing

550 5.7.25 The IP address sending this message does not have a PTR record setup

This rejection almost exclusively hits self-hosted mail servers. The receiver looks the sending IP up in reverse and finds no name — or one that does not confirm going forward.

450 4.7.1

450 4.7.1 cannot find your hostname

450 4.7.1 Client host rejected: cannot find your hostname, [203.0.113.5]

The classic Postfix restriction reject_unknown_client_hostname. Unlike 550 5.7.25 this code is temporary — the far side keeps retrying and the mail sits in the queue instead of bouncing immediately.

554 5.7.1

554 5.7.1 Relay access denied

554 5.7.1 <user@example.com>: Relay access denied

A mail server accepts messages in only two cases: for its own recipients, or from authenticated senders. This message means neither applies — and usually that is not a fault but correct behaviour.

550 5.1.1

550 5.1.1 user unknown

550 5.1.1 <info@example.com>: Recipient address rejected: User unknown in virtual mailbox table

This rejection is a statement about the recipient side, not about your reputation. The accepting server is saying: no mailbox is set up here for this address.

550 5.4.1

550 5.4.1 access denied

550 5.4.1 Recipient address rejected: Access denied. AS(201806281) [DB5EUR01FT038.eop-EUR01.prod.protection.outlook.com]

This message almost always comes from Exchange Online and is deliberately uninformative: it does not reveal whether the mailbox exists. That is what makes the diagnosis unusual — you have to narrow it down from outside.

535 5.7.8

535 5.7.8 authentication failed

535 5.7.8 Error: authentication failed: authentication failure

This message appears at submission, not at delivery — your program logs in to an outgoing server and is turned away. In most cases the password is correct and still wrong.

Message not listed?

The fastest route to the cause runs through the message itself: send or forward the affected email to hello@analyzemy.email. The report shows SPF, DKIM, DMARC, blacklists and the TLS path for that exact message.

Analyze your email now