Error Messages
What a rejecting mail server is actually telling you — one page per message with its meaning, its causes and the path to a fix.
Authentication
550 5.7.1 SPF check failed
550 5.7.1 Message rejected due to SPF check failure
The receiving server checked your domain's SPF record and did not find the sending IP in it. Because your record ends in -all, that is an explicit rejection.
SPF permerror — too many DNS lookups
Received-SPF: permerror (SPF Permanent Error: Too many DNS lookups)
Your SPF record exceeds the limit of 10 DNS-querying mechanisms. The consequence is not “partially valid” but: SPF counts as unevaluable — for all your mail, including from your main server.
550 5.7.26 — DMARC policy
550-5.7.26 Unauthenticated email from example.com is not accepted due to domain's DMARC policy
DMARC passes only when SPF or DKIM passes and the domain it checked aligns with the domain in the From: header. That second condition — alignment — is almost always the reason for this message.
dkim=fail — body hash did not verify
dkim=fail (body hash did not verify) header.d=example.com
This message says something very specific: the key was found, the signature is formally fine — but the message body is no longer the same as when it was signed. Something along the way touched it.
dkim=permerror — no key for signature
dkim=permerror (no key for signature) header.d=example.com header.s=selector1
The receiver read the signature, looked for the matching public key in DNS — and found nothing. The fault is almost always in DNS, not in the mail server.
550 5.7.23 SPF validation failed
550 5.7.23 The message was rejected because of Sender Policy Framework violation
This wording comes almost exclusively from Microsoft — Exchange Online and Outlook.com. Substantively it is an SPF hard fail; the 5.7.23 number is Microsoft's own flavour of it.
550 5.7.509 does not pass DMARC
550 5.7.509 Access denied, sending domain [example.com] does not pass DMARC verification
Microsoft's phrasing for a DMARC rejection. The key word is verification: it is not SPF or DKIM alone that failed, but their alignment with the domain in the From: header.
554 5.7.5 Permanent error evaluating DMARC
554 5.7.5 Permanent error evaluating DMARC policy
This message does not mean your policy struck. It means the receiving server found your DMARC record but could not evaluate it. The record itself is broken.
550 5.7.60 send as denied
550 5.7.60 SMTP; Client does not have permissions to send as this sender
The server logged you in successfully and still rejects: the account you identified with is not allowed to use the address in the From header. That is a permissions question, not an authentication question.
spf=temperror
Received-SPF: temperror (example.com: DNS timeout while looking up SPF record)
Per RFC 7208 temperror means the check was not performable, not negative. Somewhere in the resolution chain DNS gave no usable answer — a different problem from a malformed record.
Transport Security
STARTTLS handshake failed
Cannot start TLS: handshake failure
STARTTLS upgrades an existing plaintext connection on port 25 to an encrypted one. If that transition fails, delivery aborts — even though the server is reachable and DNS resolves correctly.
certificate verification failed
Server certificate not verified
In SMTP a failed certificate check is often inconsequential — most servers still encrypt opportunistically. The moment MTA-STS or DANE is involved, however, it turns into a hard rejection.
530 5.7.0 must issue a STARTTLS command first
530 5.7.0 Must issue a STARTTLS command first
The server cuts the dialogue short before it takes credentials or a sender: no encryption has been negotiated on this connection, and without it nothing proceeds here.
454 4.7.0 TLS not available
454 4.7.0 TLS not available due to temporary reason
The server advertised STARTTLS among its capabilities and then refused the negotiation. This is not a mismatch between two sides but a local problem on the answering server.
Reputation & Blacklists
554 5.7.1 — Client host blocked
554 5.7.1 Service unavailable; Client host [203.0.113.5] blocked using zen.spamhaus.org
The message usually names the list that triggered it. That is the most valuable piece of information in it — because lists differ enormously in how much they matter.
421 4.7.0 Try again later
421 4.7.0 Try again later, closing connection (MAIL) [ip] - gsmtp
The first digit decides: 4xx is temporary, the message is not lost. Your server will try again. A persistent 421 is still a warning sign — it is practically always about reputation.
550 5.7.606 banned sending IP
550 5.7.606 Access denied, banned sending IP [203.0.113.5]
Codes 5.7.606 through 5.7.614 come from Microsoft's own block list. It is not publicly queryable — so an IP can be blocked here while every public DNSBL reports it clean.
450 4.2.0 Greylisted
450 4.2.0 <user@example.com>: Recipient address rejected: Greylisted, see http://postgrey.schweikert.ch/help/example.com.html
Greylisting refuses every unknown sender once and lets them through on the second attempt. A real mail server retries automatically, many spam tools do not. A single delay is therefore entirely normal.
550 5.7.708 traffic not accepted
550 5.7.708 Access denied, traffic not accepted from this IP. For more information please go to https://go.microsoft.com/fwlink/?LinkId=526653
Microsoft accepts no mail at all from this address. Unlike a listing, this is rarely about your sending behaviour and usually about the address range you sit in.
Content & Attachments
550 5.7.350 detected as spam
550 5.7.350 Remote server returned message detected as spam
Unlike a blacklist block, this rejection is about the specific message. Sending IP and authentication may be flawless — what was objected to is the content itself.
552 5.3.4 message size exceeds limit
552 5.3.4 Message size exceeds fixed maximum message size (in reply to end of DATA command)
The message is bigger than the file size of the attachments suggests. Attachments are re-encoded for transport and grow by roughly a third in the process — the cause of most surprise about this error.
552 5.7.0 blocked attachment
552 5.7.0 This message was blocked because its content presents a potential security issue.
This block targets an attachment, not the message body and not your reputation. It applies regardless of whether anything malicious was found — the file type alone is enough.
DNS & Infrastructure
550 5.7.25 — reverse DNS missing
550 5.7.25 The IP address sending this message does not have a PTR record setup
This rejection almost exclusively hits self-hosted mail servers. The receiver looks the sending IP up in reverse and finds no name — or one that does not confirm going forward.
450 4.7.1 cannot find your hostname
450 4.7.1 Client host rejected: cannot find your hostname, [203.0.113.5]
The classic Postfix restriction reject_unknown_client_hostname. Unlike 550 5.7.25 this code is temporary — the far side keeps retrying and the mail sits in the queue instead of bouncing immediately.
554 5.7.1 Relay access denied
554 5.7.1 <user@example.com>: Relay access denied
A mail server accepts messages in only two cases: for its own recipients, or from authenticated senders. This message means neither applies — and usually that is not a fault but correct behaviour.
550 5.1.1 user unknown
550 5.1.1 <info@example.com>: Recipient address rejected: User unknown in virtual mailbox table
This rejection is a statement about the recipient side, not about your reputation. The accepting server is saying: no mailbox is set up here for this address.
550 5.4.1 access denied
550 5.4.1 Recipient address rejected: Access denied. AS(201806281) [DB5EUR01FT038.eop-EUR01.prod.protection.outlook.com]
This message almost always comes from Exchange Online and is deliberately uninformative: it does not reveal whether the mailbox exists. That is what makes the diagnosis unusual — you have to narrow it down from outside.
535 5.7.8 authentication failed
535 5.7.8 Error: authentication failed: authentication failure
This message appears at submission, not at delivery — your program logs in to an outgoing server and is turned away. In most cases the password is correct and still wrong.
Message not listed?
The fastest route to the cause runs through the message itself: send or forward the affected email to hello@analyzemy.email. The report shows SPF, DKIM, DMARC, blacklists and the TLS path for that exact message.
Analyze your email now