Blazalek.com

5.7.1SMTP 5.7.1: Delivery not authorized, message refused

The system permanently refused the message because the sender was not authorized to send to the destination. Per-host or per-recipient filtering may produce this decision. Do not retry the same unchanged attempt.

Category
Security, authentication and policy
Class
Permanent failure
Retry
Do not retry unchanged
Suppression
Check the full context

TL;DR

Permanent refusal because the sender was not authorized for that destination: host or recipient filtering may apply. Fix identity, sending path, or policy before any new attempt. Unresolved authorization issues can hurt sender reputation and deliverability. Do not retry the unchanged attempt.

What this code means

Code 5.7.1 is the class-5 permanent form of an authorization refusal for the named destination. Per-host or per-recipient filtering can yield the same reply, but the code alone does not name the applied rule or system and does not prove that the recipient address is invalid.

Provider examples

Gmail example
550 5.7.1 This message violates example.com email policy. - gcdp <sessionid> - gsmtp
Microsoft / Outlook example
550 5.7.1 RESOLVER.RST.AuthRequired; authentication required [Stage: CreateMessage]
Microsoft / Outlook example
530 5.7.1 Client was not authenticated
Interia example
550 5.7.1 Recipient doesn't want your mail
Outlook.com example
550 5.7.1 Unfortunately, messages from [31.57.142.204] weren't sent. Please contact your Internet service provider since part of their network is on our block list (S3140). You can also refer your provider to http://mail.live.com/mail/troubleshooting.aspx#errors. [WP1FDK33EO054.eop-nam02.prod.protection.outlook.com 2023-01-01T00:00:00.001Z 03SDKS32D1WER234]
Outlook.com example
550 5.7.1 Unfortunately, messages from [x.xx.xx.xx] weren't sent. Please contact your Internet service provider since part of their network is on our block list (S3150). You can also refer your provider to http://mail.live.com/mail/troubleshooting.aspx#errors. [#.eop-nam02.prod.protection.outlook.com]
Microsoft / Outlook example
550 5.7.1 Service unavailable, Helo domain is listed in Spamhaus. To request removal from this list see https://www.spamhaus.org/query/lookup/ (S8001) [#.prod.protection.outlook.com]
Outlook.com example
550 5.7.1 Service unavailable, MailFrom domain is listed in Spamhaus. To request removal from this list see https://www.spamhaus.org/query/lookup/ (S8002) [#.eop-nam02.prod.protection.outlook.com]
iCloud example
554 5.7.1 [CS01] Message rejected due to local policy. Please visit https://support.apple.com/en-us/HT204137
iCloud example
550 5.7.1 [CS01] Message rejected due to local policy. Please visit https://support.apple.com/en-us/HT204137
Yahoo / AOL example
host xx.yahoodns.net [x.xx.xx.xx] SMTP error from remote mail server after MAIL FROM:<user@example.com> SIZE=2022: 553 5.7.1 [BL21] Connections will not be accepted from x.xx.xx.xx, because the ip is in Spamhaus's list; see http://postmaster.yahoo.com/550-bl23.html
Yahoo / AOL example
host xx.yahoodns.net [x.xx.xx.xx] SMTP error from remote mail server after MAIL FROM:<user@example.com> SIZE=2022: 553 Mail from x.xx.xx.xx not allowed - 5.7.1 [BL23] Connections not accepted from IP addresses on Spamhaus XBL; see http://postmaster.yahoo.com/errors/550-bl23.html [550]
Gmail example
550 5.7.1 [x.xx.xx.xx] Our system has detected that this message is likely unsolicited mail. To reduce the amount of spam sent to Gmail, this message has been blocked. Please visit https://support.google.com/mail/?p=UnsolicitedMessageError for more information. - gsmtp
Gmail example
550 5.7.1 The user or domain that you are sending to (or from) has a policy that prohibits the email that you sent. Contact your domain administrator for assistance. For more information, go to Sorry, a policy is in place that prevents your message from being sent. - gsmtp
Gmail example
550 5.7.1 Invalid credentials for relay ip-address. The IP address you've registered in your Workspace SMTP Relay service doesn't match the domain of the account this email is being sent from. If you are trying to relay email from a domain that isn't registered under your Workspace account or has empty envelope-from:, you must configure your email server either to use SMTP AUTH to identify the sending domain or to present one of your domain names in the HELO or EHLO command. For more information, go to SMTP relay service error messages. - gsmtp
Gmail example
550 5.7.1 This message is likely unsolicited email. To reduce the amount of spam sent to Gmail, this message has been blocked. For more information, go to Why has Gmail blocked my messages? - gsmtp
Gmail example
550 5.7.1 This message does not meet IPv6 sending guidelines regarding PTR records and authentication. For more information, go to Email sender guidelines. - gsmtp
Gmail example
550 5.7.1 This message is likely suspicious due to the very low reputation of the sending IP address. To best protect our users from spam, the message has been blocked. For more information, go to Why has Gmail blocked my messages? - gsmtp
Yahoo / AOL example
A 553 or 554 SMTP error indicates an email could not be delivered due to a permanent problem. … Your IP is listed by Spamhaus. Please check with https://www.spamhaus.org.
Outlook.com consumer example
550 SC-001 — Mail rejected by Outlook.com for policy reasons. Reasons for rejection may be related to content with spam-like characteristics or IP/domain reputation. If you are not an email/network admin please contact your Email/Internet Service Provider for help.
Outlook.com consumer example
550 SC-002 — Mail rejected by Outlook.com for policy reasons. The mail server IP connecting to Outlook.com has exhibited namespace mining behavior. If you are not an email/network admin please contact your Email/Internet Service Provider for help.
Outlook.com consumer example
550 SC-004 — Mail rejected by Outlook.com for policy reasons. A block has been placed against your IP address because we have received complaints concerning mail coming from that IP address. We recommend enrolling in our Junk Email Reporting Program (JMRP), a free program intended to help senders remove unwanted recipients from their email list. If you are not an email/network admin please contact your Email/Internet Service Provider for help.
Outlook.com consumer example
550 DY-001 — Mail rejected by Outlook.com for policy reasons. We generally do not accept email from dynamic IP's as they are not typically used to deliver unauthenticated SMTP email to an Internet mail server. If you are not an email/network admin please contact your Email/Internet Service Provider for help. For more information, Spamhaus maintains lists of dynamic and residential IP addresses.
Outlook.com consumer example
550 OU-001 — Mail rejected by Outlook.com for policy reasons. If you are not an email/network admin please contact your Email/Internet Service Provider for help. For more information about this block and to request removal please go to: Spamhaus .
Outlook.com consumer example
550 OU-002 — Mail rejected by Outlook.com for policy reasons. Reasons for rejection may be related to content with spam-like characteristics or IP/domain reputation. If you are not an email/network admin please contact your Email/Internet Service Provider for help.
Gmail example
550 5.7.1 [2500:1109:110::11      91] Gmail has detected that this message is likely suspicious due to the very low reputation of the sending domain. To best protect our users from spam, the message has been blocked. Please visit https://support.google.com/mail/answer/188131 for more information. t64-20020a1fc343000000b0049d0aa186d9si449748vkf.30 - gsmtp
Gmail example
<john@zovit.com>: host aspmx.l.google.com[124.205.72.72] said: 550-5.7.1 [93.177.84.58      12] Gmail has detected that this message is likely 550-5.7.1 unsolicited mail. To reduce the amount of spam sent to Gmail, this 550-5.7.1 message has been blocked. Please visit 550-5.7.1 https://support.google.com/mail/?p=UnsolicitedMessageError for more 550 5.7.1 information. ga24-20020a1709070c1800b009e0f32d8e62si964060ejc.893 - gsmtp (in reply to end of DATA command)
iCloud example
550 5.7.1 Your message was rejected due to example.com DMARC policy.
iCloud example
550 5.7.1 Your email was rejected due to having a domain present in the Spamhaus DBL -- see https://www.spamhaus.org/dbl/
iCloud example
554 5.7.1 <example@icloud.com>: Relay access denied
iCloud example
554 5.7.1 [CS01] Message rejected due to local policy.
iCloud example
554 5.7.1 [HM08] Message rejected due to local policy.
iCloud example
554 5.7.1 [BS01] Message rejected due to local policy.
iCloud example
smtp;550 5.7.1 Your message was rejected due to example.com’s DMARC policy. See https://support.apple.com/en-us/HT204137 for info
Microsoft / Outlook example
550 5.7.1 Service unavailable, Client host [x.xx.xx.xx] blocked using Spamhaus. (AS16012611)
Microsoft / Outlook example
550 5.7.1 Service unavailable, Helo domain is listed in Spamhaus. (S8001) [#.prod.protection.outlook.com]
Microsoft / Outlook example
550 5.7.1 TRANSPORT.RULES.RejectMessage; the message was rejected by organization policy
proofpoint example
smtp;550 5.7.1 <email@example.com>: Recipient address rejected: User email address is marked as invalid.
proofpoint example
smtp;550 5.7.1 Relaying denied
proofpoint example
smtp;550 5.7.1 Service unavailable; client [x.xx.xx.xx] blocked using prs.proofpoint.com
proofpoint example
smtp;550 5.7.1 Service unavailable; client [x.xx.xx.xx] blocked using Cloudmark Sender Intelligence (Visit http://csi.cloudmark.com/reset-request/ if you feel this is in error)
proofpoint example
smtp;554 5.7.1 <email@example>: Relay access denied

Technical meaning

Unauthorized sending to the destination, with the message refused, is the meaning of X.7.1; per-host or per-recipient filtering may produce this result. The registry description says this detail is useful only as a permanent error, and concrete code 5.7.1 applies it in class 5.

Delivery status

The leading digit 5 denotes a permanent failure of the current attempt. The code alone does not identify the specific rule or system that applied it, and it does not establish that the recipient address is invalid.

Class
Permanent failure
Retry
Do not retry unchanged
Suppression
Check the full context

Retry decision

Operational guidance: stop automatic and manual retries of the same unchanged attempt. Consider a new send only after a verified change to the sender identity or authorization, the applicable rule, or the sending path; check suppression again before the attempt.

Suppression decision

Operational guidance: do not automatically add an address or domain to a suppression list based on 5.7.1 alone. Inspect the complete response, authorization and filtering context, event history, and applicable policy, then make the suppression decision in that context.

Common causes

  • The reporting system determined that the sender was not authorized to send to the destination, for example because of per-host or per-recipient filtering.
  • In the accepted Gmail example, the message violated a custom-domain email policy.
  • In the accepted Exchange Online example, delivery from an external sender to a mail-enabled public folder required authentication.

Diagnostic steps

  1. Inspect the raw SMTP response or nondelivery report and confirm that the enhanced code is exactly 5.7.1 and that the basic reply is in the 5xx class; retain the complete response text.
  2. Correlate the event with the intended message, attempt time, sender identity and host, destination, transaction stage, and system that returned the code; identify the specific rule from available logs instead of inferring it from the code alone.
  3. If the response contains Gmail marker “gcdp”, inspect the applicable custom-domain policy; if it contains “RESOLVER.RST.AuthRequired”, inspect the authentication requirement for the specified Exchange Online public-folder delivery.
  4. Stop unchanged retries; before a controlled new send, verify a material correction and reassess suppression.

Actions by owner

Sender

  • Do not resend the same unchanged message; confirm the intended sender identity and destination, then give the administrator the complete response.
  • Correct only a confirmed error in the sender, recipient, or required sending path, without treating the address as invalid from this code alone.

Sender administrator

  • Retain the complete response and attempt context, then inspect the sender identity, host, authentication, and sending-path configuration used for the specific refusal.
  • Stop unchanged retries; after a verified correction, make a controlled new attempt and reassess suppression.

Recipient administrator

  • If the code came from a recipient system you manage, inspect authorization rules and host- or recipient-level filters for the specified attempt, including the applicable domain policy or authentication requirement.
  • If the confirmed rule does not match the intended policy, correct it within your authority and verify the result of a new, controlled attempt.

Provider

  • For the specified attempt, inspect managed-service logs and the applied rule, then give the administrator exact, safe context for the refusal.
  • Correct a confirmed problem in the managed layer or identify the owner of the required correction; do not trigger automatic suppression from 5.7.1 alone.

Sources

These sources define what this enhanced status code means, mainly through the IANA registry and related RFCs. When provider examples appear on the page, they come from that provider's published documentation. Follow the links to read the original wording in context.

Last verified:

Found an error or inaccuracy? Report a correction.

Point out the part of this page that should be checked. Every report is reviewed manually.

Type of problem

Describe the issue and, if useful, suggest corrected wording.

For a factual report, include a public source when possible.

You can submit anonymously. A reply is not guaranteed.

Do not paste full bounce messages, headers, email addresses, Message-IDs, tokens, or other personal data. Redact evidence before sending.

Sending a correction shares the information you enter with Formspree so I can review and improve this page. Read the privacy notice.

Guide

  • List Management

    Permanent 5.7.1 refusal is a hard-bounce class — suppress, do not retry unchanged.

  • Deliverability

    SPF/DKIM/DMARC and related auth policy are required for inbox delivery.

Incidents

Wojtek Blazalek

Email deliverability expert

Stuck on this error code? I help teams identify rejection causes and fix authentication and reputation, so email reaches the inbox.

Hands-on deliverability work for teams that send at scale.