Email & Hosting Company-wide impact Partly DIY

Email Bounced with 550 5.7.1? 6 Steps to Fix It, from Real Cases

Your company email bounces back with 550 5.7.1 or blocked. That means the receiving server doesn't trust the sender. This guide walks through finding and fixing the cause, in the same order the Hinet team uses with real clients.

Quick answer

A 550 5.7.1 bounce means the receiving server rejected your email for trust reasons. The two main causes are (1) your mail server's IP is on a blacklist — usually because a compromised account sent spam — and (2) your domain's SPF, DKIM or DMARC records are missing or wrong. Read the bounce message, check the IP at MXToolbox, verify all three DNS records, fix the root cause first, then request delisting.

Contents
  1. What does 550 5.7.1 mean?
  2. Common bounce codes
  3. 6 steps to fix the bounce
  4. Setting up SPF, DKIM, DMARC
  5. From Hinet's real cases
  6. Preventing repeat bounces
  7. When to call an expert
  8. FAQ: 550 5.7.1 email bounces

What does a 550 5.7.1 bounce mean?

550 5.7.1 means “permanently rejected for policy or security reasons”. The receiving server got your message but refused it because it does not trust the sending IP address or domain.

A bounce message (Non-Delivery Report, or NDR) carries two codes, as defined in RFC 3463:

  • 550 — the 3-digit SMTP reply. A leading 5 means permanent failure: resending will not help until the cause is fixed. (A leading 4 is temporary and the server will retry by itself.)
  • 5.7.1 — the enhanced status code. Class .7 = Security / Policy, not a typo in the address or a full mailbox.

The text after the code matters most — for example blocked using zen.spamhaus.org, listed in ... or Sender not authorized — because it tells you exactly where to look.

Email bounce diagnosis flow Read the bounce code first: 5.1.1 means check the recipient address, 5.2.2 means the recipient mailbox is full, 5.7.x means check blacklists. If listed, find the cause and request delisting; if not listed, check SPF, DKIM, DMARC and PTR. Email bounced (NDR) Read the 5.x.x code + text 5.1.1 User unknown Check the address 5.2.2 / 552 Quota Recipient mailbox full 5.7.x Policy This guide IP blacklisted? Listed Find the cause → delist Not listed Check SPF/DKIM/DMARC
The bounce triage flow the Hinet team uses — classify by code first, then fix.

Common bounce codes and what they mean

The code alone tells you whether the problem is on the sender side, the recipient side, or just temporary.

CodeMeaningProblem sideWhat to do
550 5.7.1Rejected by policy / IP blacklistedSender (usually)Check blacklists + SPF/DKIM/DMARC
550 5.7.26Gmail: authentication failed (DMARC/SPF/DKIM)SenderFix the domain's DNS records
550 5.7.25Gmail: sending IP has no reverse DNS (PTR)Sender / IP providerAsk your VPS provider to set a PTR
550 5.1.1Recipient not foundTypo / mailbox deletedDouble-check the address
552 5.2.2Recipient mailbox fullRecipientTell the recipient / use another channel
421 4.7.0Temporarily deferred (rate limit / timeout)TemporaryLet it retry; investigate after 24 h

Microsoft 365 / Exchange Online codes are documented in Microsoft's NDR reference.

6 steps to fix a 550 5.7.1 bounce

Work top to bottom. The first steps take minutes and rule out the most causes.

  1. Read the full bounce message

    Open the NDR and find the Remote server / Reporting-MTA line, the 550 5.7.1 code and the text after it. If you see spamhaus, barracuda, spamcop or listed, your IP is blacklisted — jump to step 3.

  2. Send test emails to several destinations

    Send a test to Gmail, Outlook.com and one or two other company domains.

    • Bounces everywhere = the problem is on your side (IP / DNS / compromised account)
    • Bounces at one recipient only = that recipient's own policy — go to step 6
  3. Check your IP and domain against blacklists

    Find your mail server's IP (from the headers of a sent message, or ask your hosting provider) and check it at:

  4. Check SPF, DKIM, DMARC and PTR

    Open Command Prompt on Windows and run (replace example.co.th with your domain):

    nslookup -type=txt example.co.th           :: SPF (v=spf1 ...)
    nslookup -type=txt _dmarc.example.co.th    :: DMARC
    nslookup -type=txt default._domainkey.example.co.th   :: DKIM (your selector may differ)
    nslookup 203.0.113.25                      :: PTR of the mail server IP

    If a record is missing, or you see more than one SPF record, fix it as described in the next section.

  5. Find the root cause before asking to be delisted

    This is the step people skip most often. IPs don't get blacklisted on their own — usually an employee account was compromised and used to send spam. In your mail server's control panel, check:

    • whether the outbound queue is abnormally large
    • which account has been sending unusual volumes
    • whether there are logins from foreign IP addresses

    If you find one, reset the password and enable MFA immediately. See Email account hacked and sending spam: what to do first.

  6. Request delisting and follow up

    Once the cause is closed, submit a delisting request on the website of every list you appear on. Timing depends on each provider. If only one recipient rejects you, ask them in writing to whitelist your domain or IP.

Don't request delisting before fixing the cause — if spam is still leaving your server, the IP will be listed again within hours, and some providers delist more slowly the next time.

How should SPF, DKIM and DMARC be set up?

Your domain needs all three DNS records, because receiving servers use them to verify that the email really came from you.

Since 2024, Gmail's sender guidelines require every sender to have SPF or DKIM, and senders of more than 5,000 messages a day to have SPF, DKIM and DMARC.

RecordPurposeExample value (TXT)
SPF
@ or example.co.th
Lists which servers may send mail for the domainv=spf1 mx a include:spf.protection.outlook.com -all
DKIM
selector._domainkey
Digital signature proving the content wasn't alteredv=DKIM1; k=rsa; p=MIIBIjANBg...
Generated in your control panel / Microsoft Defender
DMARC
_dmarc
Tells receivers what to do if SPF/DKIM fail, and sends reportsv=DMARC1; p=none; rua=mailto:dmarc@example.co.th
Most common mistake: two SPF records (e.g. adding Microsoft 365's without removing the old hosting one), which makes SPF fail completely. Merge them into one record and stay within 10 DNS lookups. Start DMARC at p=none, review reports for 2–4 weeks, then move to quarantine or reject.
First-hand experience

What the Hinet team sees managing email for SMEs

4,833+IT support tickets analysed (Mar 2025 – Oct 2026)
101Email & Hosting cases — the group with the widest business impact
20+years running mail servers for Thai businesses (since 2004)

“Our email won't send” is a classic case the Hinet team sees every year. For one healthcare-sector client, the team started by checking the mail server's IP reputation against multiple blacklists; another client running email on a VPS had its IP blocked in the same way.

The lesson: IPs don't get blacklisted by themselves. We always trace the root cause — especially accounts that may have been compromised. In one case we closely monitored the email logs and sign-in history of a hacked account after remediation. For clients whose mail kept bouncing repeatedly, some cases were resolved by re-tuning the mail server's filters.

Our view: delisting alone treats the symptom. SMEs running their own mail server or VPS should enforce MFA on every mailbox and turn on automatic blacklist alerts — far cheaper than a day when the whole company can't send email.

How do you stop bounces from happening again?

Close the paths that damage your IP's reputation, and set alerts so you know before your users do.

  • Keep SPF + DKIM + DMARC complete and re-check whenever you change email provider or add a system that sends as your domain (ERP, website, scanners).
  • Enable 2FA / MFA on every mailbox — compromised accounts are the number-one cause.
  • Set up automatic blacklist monitoring that alerts you by email or LINE the moment your IP is listed.
  • Limit outbound messages per hour per account in the control panel to contain damage if an account is breached.
  • Separate marketing email from business email — send newsletters through an email-marketing service with its own IPs, not the company mail server.

When should you call an expert?

If the whole company has been unable to send email for more than an hour, or you'd need to change DNS or mail-server settings you're unsure about, let a system administrator handle it.

A wrong DNS change can stop incoming mail too, and delisting without fixing the cause gets you listed again. The Hinet team manages Email Hosting, Microsoft 365 Business and IT Support Outsourcing for SMEs. You can describe the problem to our engineers using the form below.

FAQ: 550 5.7.1 email bounces

Is a 550 5.7.1 bounce my problem or the recipient's?

Usually the sender's. 550 5.7.1 means the receiving server rejected the message for policy or trust reasons, such as a blacklisted IP or failed SPF/DKIM/DMARC. The quickest test is to send to several destinations: if everything bounces, the problem is on your side; if only one bounces, ask that recipient to whitelist you.

How long does it take to get off a blacklist?

It depends on the list. Some delist within hours of a request, others expire automatically after a few days. Always fix the cause first — if spam is still leaving your server, the IP will be listed again.

Will email fail completely without SPF, DKIM or DMARC?

Not everywhere, but since 2024 Gmail and Yahoo require all senders to have SPF or DKIM, and bulk senders (5,000+ messages a day) to have SPF, DKIM and DMARC. Set up all three.

Why can't I send to Gmail when other domains work?

Usually Gmail's authentication checks are failing — code 5.7.26 (SPF/DKIM/DMARC failed) or 5.7.25 (no reverse DNS/PTR on the sending IP). Check all of your domain's DNS records and the PTR of your mail server IP.

Will moving to Microsoft 365 or Google Workspace solve this?

It helps a lot, because the provider manages sending reputation. You still need correct SPF, DKIM and DMARC, and a compromised account sending spam can still be blocked — so enable MFA for every account.

How often should we check our mail server against blacklists?

For SMEs running their own mail server or VPS, set up automatic alerts (e.g. MXToolbox Monitoring) and check manually at least monthly, or immediately when users report bounces.

References

Technically reviewed by the Hinet Computer System engineering team · Last updated 10 Oct 2026

Hinet IT Support

Still stuck? Let the Hinet team fix it

Describe the problem briefly. Our engineers will check your IP, DNS and mail server and get back to you within 1 business day.

  • Supporting Thai businesses since 2004
  • Mail servers / VPS, Microsoft 365 and Google Workspace
  • Free initial assessment, no obligation

Report an IT issue

Fields marked * are required

We only use your details to follow up on this issue, per our privacy policy.

LINE Get help