How the message looks
550 5.7.23 The message was rejected because of Sender Policy Framework violation 550 5.7.23 <user@example.com>: Recipient address rejected: Message rejected due to: SPF fail Remote Server returned '550 5.7.23 The message was rejected because of Sender Policy Framework violation'

What the code means

Enhanced status code 5.7.23 is reserved in RFC 7372 for exactly this: the message failed the SPF check. Other receivers usually report the same thing as 550 5.7.1. The distinction is worth keeping — someone searching for this number is normally looking at Microsoft-specific behaviour.

As always with SPF, the IP of the delivering connection is checked against the record of the domain in the envelope from. The visible From: header plays no part.

The forwarding special case

If the message only appears for some recipients, forwarding is often behind it. When a mailbox forwards your mail to a Microsoft address, the delivering IP is the forwarding server's — and that one is naturally absent from your SPF record. SPF does not survive classic forwarding.

DKIM exists precisely for this: the signature stays intact through a forward, and DMARC already passes when one of the two methods passes in alignment. A domain with SPF but no DKIM loses its authentication on every forward.

How to proceed

  1. Determine the envelope from. In the bounce it appears in the Return-Path. That domain is what counts, not the one in From:.
  2. Check the record against the real IP. Is the sending address genuinely in there — including as IPv6?
  3. Verify the lookup limit. A record above ten DNS lookups returns permerror, and Microsoft treats that as a failure.
  4. Set up DKIM if it is missing. It is the only way to survive forwarding.

The note “part of their network is on our block list” that Microsoft sometimes appends is misleading: it also shows up when the SPF record simply does not match.

Find the cause in the actual message

Send or forward the affected email to hello@analyzemy.email. For that exact message the report shows which IP sent it, how SPF, DKIM and DMARC turned out, and where the chain breaks.

Analyze your email now

Last updated: · All error messages