logo

Email error 550 5.4.1: Recipient address rejected: access denied

The server refused the recipient before accepting the message. It is common with Microsoft 365 and other systems that check the address against a directory at the edge of the network.

Permanent failure (hard bounce)

What it means

The server refused the recipient before accepting the message. It is common with Microsoft 365 and other systems that check the address against a directory at the edge of the network.

Common causes

  • The recipient address does not exist in that organisation.
  • The organisation blocks outside senders for this mailbox or group.
  • The address was deleted but the old address is still on your list.
  • A directory-based filter treats unknown addresses as an attack.

How to fix it

  1. Treat the address as invalid unless you can confirm it with the person.
  2. Ask for a current address through another channel.
  3. Remove it from the list so it does not bounce again.
  4. Verify the list so addresses like this are caught before sending.

How to prevent it

Remove the address from your list and verify the rest before the next campaign.

Most bounces come from addresses that were never checked. Verify each address before you send: syntax, domain, mailbox and risk are checked without sending a message. Test a single address with the free email checker or upload a whole list for bulk verification.

Verify an email address free · Clean a whole list · MX lookup · SPF, DKIM and DMARC checker

Frequently asked questions

Is 5.4.1 the same as user unknown?

In practice yes: the system will not deliver to that address. The wording differs by provider.

Will retrying help?

No. It is a permanent rejection.

Other error codes

All email error codes