Quick answer
A 550 5.7.1 bounce means the receiving server rejected your email for trust reasons. The two main causes are (1) your mail server's IP is on a blacklist — usually because a compromised account sent spam — and (2) your domain's SPF, DKIM or DMARC records are missing or wrong. Read the bounce message, check the IP at MXToolbox, verify all three DNS records, fix the root cause first, then request delisting.
Contents
What does a 550 5.7.1 bounce mean?
550 5.7.1 means “permanently rejected for policy or security reasons”. The receiving server got your message but refused it because it does not trust the sending IP address or domain.
A bounce message (Non-Delivery Report, or NDR) carries two codes, as defined in RFC 3463:
- 550 — the 3-digit SMTP reply. A leading 5 means permanent failure: resending will not help until the cause is fixed. (A leading 4 is temporary and the server will retry by itself.)
- 5.7.1 — the enhanced status code. Class .7 = Security / Policy, not a typo in the address or a full mailbox.
The text after the code matters most — for example blocked using zen.spamhaus.org, listed in ... or Sender not authorized — because it tells you exactly where to look.
Common bounce codes and what they mean
The code alone tells you whether the problem is on the sender side, the recipient side, or just temporary.
| Code | Meaning | Problem side | What to do |
|---|---|---|---|
550 5.7.1 | Rejected by policy / IP blacklisted | Sender (usually) | Check blacklists + SPF/DKIM/DMARC |
550 5.7.26 | Gmail: authentication failed (DMARC/SPF/DKIM) | Sender | Fix the domain's DNS records |
550 5.7.25 | Gmail: sending IP has no reverse DNS (PTR) | Sender / IP provider | Ask your VPS provider to set a PTR |
550 5.1.1 | Recipient not found | Typo / mailbox deleted | Double-check the address |
552 5.2.2 | Recipient mailbox full | Recipient | Tell the recipient / use another channel |
421 4.7.0 | Temporarily deferred (rate limit / timeout) | Temporary | Let it retry; investigate after 24 h |
Microsoft 365 / Exchange Online codes are documented in Microsoft's NDR reference.
6 steps to fix a 550 5.7.1 bounce
Work top to bottom. The first steps take minutes and rule out the most causes.
-
Read the full bounce message
Open the NDR and find the Remote server / Reporting-MTA line, the
550 5.7.1code and the text after it. If you seespamhaus,barracuda,spamcoporlisted, your IP is blacklisted — jump to step 3. -
Send test emails to several destinations
Send a test to Gmail, Outlook.com and one or two other company domains.
- Bounces everywhere = the problem is on your side (IP / DNS / compromised account)
- Bounces at one recipient only = that recipient's own policy — go to step 6
-
Check your IP and domain against blacklists
Find your mail server's IP (from the headers of a sent message, or ask your hosting provider) and check it at:
- MXToolbox Blacklist Check — dozens of lists in one go
- Spamhaus Lookup — the list most banks and large organisations rely on
-
Check SPF, DKIM, DMARC and PTR
Open Command Prompt on Windows and run (replace
example.co.thwith your domain):nslookup -type=txt example.co.th :: SPF (v=spf1 ...) nslookup -type=txt _dmarc.example.co.th :: DMARC nslookup -type=txt default._domainkey.example.co.th :: DKIM (your selector may differ) nslookup 203.0.113.25 :: PTR of the mail server IPIf a record is missing, or you see more than one SPF record, fix it as described in the next section.
-
Find the root cause before asking to be delisted
This is the step people skip most often. IPs don't get blacklisted on their own — usually an employee account was compromised and used to send spam. In your mail server's control panel, check:
- whether the outbound queue is abnormally large
- which account has been sending unusual volumes
- whether there are logins from foreign IP addresses
If you find one, reset the password and enable MFA immediately. See Email account hacked and sending spam: what to do first.
-
Request delisting and follow up
Once the cause is closed, submit a delisting request on the website of every list you appear on. Timing depends on each provider. If only one recipient rejects you, ask them in writing to whitelist your domain or IP.
How should SPF, DKIM and DMARC be set up?
Your domain needs all three DNS records, because receiving servers use them to verify that the email really came from you.
Since 2024, Gmail's sender guidelines require every sender to have SPF or DKIM, and senders of more than 5,000 messages a day to have SPF, DKIM and DMARC.
| Record | Purpose | Example value (TXT) |
|---|---|---|
| SPF @ or example.co.th | Lists which servers may send mail for the domain | v=spf1 mx a include:spf.protection.outlook.com -all |
| DKIM selector._domainkey | Digital signature proving the content wasn't altered | v=DKIM1; k=rsa; p=MIIBIjANBg...Generated in your control panel / Microsoft Defender |
| DMARC _dmarc | Tells receivers what to do if SPF/DKIM fail, and sends reports | v=DMARC1; p=none; rua=mailto:dmarc@example.co.th |
p=none, review reports for 2–4 weeks, then move to quarantine or reject.What the Hinet team sees managing email for SMEs
“Our email won't send” is a classic case the Hinet team sees every year. For one healthcare-sector client, the team started by checking the mail server's IP reputation against multiple blacklists; another client running email on a VPS had its IP blocked in the same way.
The lesson: IPs don't get blacklisted by themselves. We always trace the root cause — especially accounts that may have been compromised. In one case we closely monitored the email logs and sign-in history of a hacked account after remediation. For clients whose mail kept bouncing repeatedly, some cases were resolved by re-tuning the mail server's filters.
Our view: delisting alone treats the symptom. SMEs running their own mail server or VPS should enforce MFA on every mailbox and turn on automatic blacklist alerts — far cheaper than a day when the whole company can't send email.
How do you stop bounces from happening again?
Close the paths that damage your IP's reputation, and set alerts so you know before your users do.
- Keep SPF + DKIM + DMARC complete and re-check whenever you change email provider or add a system that sends as your domain (ERP, website, scanners).
- Enable 2FA / MFA on every mailbox — compromised accounts are the number-one cause.
- Set up automatic blacklist monitoring that alerts you by email or LINE the moment your IP is listed.
- Limit outbound messages per hour per account in the control panel to contain damage if an account is breached.
- Separate marketing email from business email — send newsletters through an email-marketing service with its own IPs, not the company mail server.
When should you call an expert?
If the whole company has been unable to send email for more than an hour, or you'd need to change DNS or mail-server settings you're unsure about, let a system administrator handle it.
A wrong DNS change can stop incoming mail too, and delisting without fixing the cause gets you listed again. The Hinet team manages Email Hosting, Microsoft 365 Business and IT Support Outsourcing for SMEs. You can describe the problem to our engineers using the form below.
FAQ: 550 5.7.1 email bounces
Is a 550 5.7.1 bounce my problem or the recipient's?
Usually the sender's. 550 5.7.1 means the receiving server rejected the message for policy or trust reasons, such as a blacklisted IP or failed SPF/DKIM/DMARC. The quickest test is to send to several destinations: if everything bounces, the problem is on your side; if only one bounces, ask that recipient to whitelist you.
How long does it take to get off a blacklist?
It depends on the list. Some delist within hours of a request, others expire automatically after a few days. Always fix the cause first — if spam is still leaving your server, the IP will be listed again.
Will email fail completely without SPF, DKIM or DMARC?
Not everywhere, but since 2024 Gmail and Yahoo require all senders to have SPF or DKIM, and bulk senders (5,000+ messages a day) to have SPF, DKIM and DMARC. Set up all three.
Why can't I send to Gmail when other domains work?
Usually Gmail's authentication checks are failing — code 5.7.26 (SPF/DKIM/DMARC failed) or 5.7.25 (no reverse DNS/PTR on the sending IP). Check all of your domain's DNS records and the PTR of your mail server IP.
Will moving to Microsoft 365 or Google Workspace solve this?
It helps a lot, because the provider manages sending reputation. You still need correct SPF, DKIM and DMARC, and a compromised account sending spam can still be blocked — so enable MFA for every account.
How often should we check our mail server against blacklists?
For SMEs running their own mail server or VPS, set up automatic alerts (e.g. MXToolbox Monitoring) and check manually at least monthly, or immediately when users report bounces.
References
- RFC 3463 — Enhanced Mail System Status Codes
- Google — Email sender guidelines
- Microsoft Learn — NDRs in Exchange Online
- Spamhaus — IP & Domain Reputation Checker
- MXToolbox — Blacklist Check
Related guides
Technically reviewed by the Hinet Computer System engineering team · Last updated 10 Oct 2026