Email Bouncing Back With a 550 Error
You sent an email and got back a "Mail Delivery Failed" message with a 550 code in it. The receiving server refused your message on purpose — and the bounce usually says exactly why, if you know where to look.
Common signs of this issue
- You get a message titled "Undeliverable", "Mail Delivery Failed", "Delivery Status Notification (Failure)", or "Returned mail" shortly after sending.
- Somewhere in the bounce is a line starting with 550, often followed by a code like 5.1.1, 5.7.1, 5.7.26, or 5.4.1.
- The wording includes phrases like "user unknown", "mailbox unavailable", "message rejected", "access denied", "blocked", or "SPF check failed".
- It happens with one recipient only — or with every message you send to Gmail, Outlook, or a particular company.
- A similar bounce with 552 instead of 550 mentions the mailbox being full or over quota.
- It started after you changed email providers, added a new sending service, moved your website, or edited your domain's DNS.
Safe checks you can do yourself
None of these require sharing passwords with anyone.
- Open the bounce and find the diagnostic line. Skip the friendly paragraph at the top and look for the technical part — usually labelled "Diagnostic-Code", "Remote server returned", or shown under "Technical details". It contains the number (550), a three-part code (like 5.1.1), and a sentence from the receiving server. That sentence is the diagnosis.
- 550 5.1.1, "user unknown", "no such user", "address not found", or "mailbox unavailable" almost always means the address does not exist. Check the spelling letter by letter — gmial.com, a missing letter in a name, or .con instead of .com. Also ask whether the person has left the company; a deleted mailbox bounces exactly like a typo.
- 552 or "mailbox full" / "over quota" is the recipient's problem, not yours. Nothing is wrong with your email. Try again later or reach them another way and let them know their mailbox is full.
- 550 5.7.1, 5.7.26, 5.7.509, "SPF", "DMARC", "DKIM", or "unauthenticated" means the receiving server did not believe the message really came from your domain. Check your domain's SPF, DKIM and DMARC records with a free lookup tool such as MXToolbox or your email provider's own checker. This is the most common cause after a provider change or after adding a new sending service like a newsletter tool or a website form.
- "Blocked", "listed", "blacklisted", "poor reputation", or a link to Spamhaus or a similar list means the server that sent your mail is on a spam blocklist. Run your domain and your mail server's IP address through a blocklist checker. If you use Google Workspace or Microsoft 365, the listed IP is often theirs, not yours — tell their support and include the bounce.
- Test one address outside the problem. Send the same message to a personal Gmail or Outlook account. If that goes through, your email works and the issue is that one recipient's server or policy. If it bounces too, the problem is on your side.
- Note what changed recently. A new email provider, a website move, a DNS edit, or a new tool sending "as" your domain are the usual triggers for authentication bounces. The date the bounces started often lines up with one of them.
- Keep a full copy of one bounce, headers included (in most mail apps: forward as attachment or "show original"). Anyone helping you will want it, and it saves a round of guessing.
What this usually means
A 550 is a permanent refusal: the receiving mail server looked at your message and decided not to accept it. That is different from a temporary delay (codes starting with 4), where servers keep retrying on their own. With a 550, nothing will retry — the message is gone until you fix the reason and send again. The good news is that the refusing server almost always states its reason in the bounce, in plain words next to the code.
Most 550 bounces fall into a few buckets. Wrong or dead address (5.1.1, user unknown) is a typo or a closed mailbox and is fixed by getting the right address. Full mailbox (552, over quota) is on the recipient's side. Authentication failure (5.7.1, 5.7.26, SPF or DMARC mentioned) means your domain's DNS records do not list the service that actually sent the message — very common after switching providers or adding a tool that sends email for you. Reputation or blocklist (blocked, listed, poor reputation) means the sending server's IP or your domain has been flagged, sometimes because of your own sending and sometimes because of a neighbor on shared hosting.
Since early 2024, Gmail, Yahoo, and more recently Microsoft have tightened the rules for mail they accept, especially for anyone sending in volume: SPF or DKIM must pass, a DMARC record must exist, and messages must line up with the domain they claim to come from. A business that sent happily for years with no DMARC record, or with an SPF record missing its newsletter service, can now see bounces that never used to happen. That is why authentication problems are the most common "it just started" cause of 550s for small businesses.
What not to do
- Don't keep resending the same message to an address that returned user unknown. Repeated sends to dead addresses can hurt your sending reputation.
- Don't create a second SPF record to add a new service. A domain must have only one SPF record; two of them makes SPF fail for everything.
- Don't publish a strict DMARC policy (reject) before checking that all your legitimate senders pass. That can turn a few bounces into all of your mail bouncing.
- Don't pay a service that promises to get you "removed from all blacklists" before you know which list you are on and why. Most major lists have free removal once the cause is fixed.
- Don't switch to sending business email from a personal Gmail account as a quiet workaround. It hides the problem and confuses customers.
- Don't delete the bounce messages. They are the most useful evidence you have.
When to get help
If the bounce is a typo or a full mailbox, you do not need anyone. It is worth bringing in help when the bounces mention SPF, DKIM, DMARC, or a blocklist and you have more than one thing sending as your domain — your mailbox provider, a website contact form, a newsletter tool, an invoicing system. Getting all of them into one correct SPF record, signed with DKIM, under a sensible DMARC policy is fiddly, and a mistake takes down legitimate mail along with the bad. Someone who does this regularly can usually read one bounce and a DNS lookup, tell you which sender is failing, and fix the records in a single pass without touching your mailbox.
Not sure what to do next?
Answer a few short questions and we'll point you to the safest next step — DIY, a freelancer, or a direct review. No passwords required.
Is this a business website? If this issue may be costing you leads, sales, or trust, you may want a direct review instead of trial and error.
Frequently asked questions
What does a 550 error mean in email?
It means the receiving mail server permanently refused your message. The bounce includes a short reason — most often the address does not exist, the message failed authentication checks like SPF or DMARC, or the sending server is on a blocklist.
What does 550 5.1.1 user unknown mean?
The address you sent to does not exist on that server. Check it for typos, and check whether the person has left the organization. It is not a problem with your own email.
What does 550 5.7.1 message rejected mean?
The receiving server refused the message by policy. The text after the code says which policy — commonly failed SPF, DKIM or DMARC checks, a blocklisted sending IP, or content the server flagged as spam.
Is a 552 error the same as a 550?
No. A 552 usually means the recipient's mailbox is full or the message is too large. It is on their side or about attachment size, not about your address or reputation.
Why did my emails suddenly start bouncing to Gmail or Outlook?
The most likely cause is authentication. Large providers now require working SPF or DKIM and a DMARC record, and a recent provider change or new sending tool can leave your records incomplete. Check your domain's records against what your email provider tells you to publish.
Will my email be delivered later on its own?
Not after a 550. It is a permanent failure, so the sending server stops trying. Fix the cause, then send the message again yourself.