5.4.1

Enhanced Status Code 5.4.1: Relay Access Denied

Permanent failure High severity Security RFC 3463
What it means

Enhanced Status Code 5.4.1 means “Relay Access Denied.” The receiving server will not relay your message or has refused the recipient outright. In Exchange Online this is one of the most common permanent rejections senders meet.

At a glance
Code5.4.1
Bounce typeHard (permanent)
SeverityHigh
CategorySecurity
What to doSuppress the address; do not retry
StandardRFC 3463
What it looks like in your mail logs
550 5.4.1 Recipient address rejected: Access denied

What does 5.4.1 mean?

In practice 5.4.1 is a Microsoft code. Exchange Online returns it as recipient address rejected with access denied, and as relay access denied. The registry assigns X.4.1 to no answer from host, which is a network condition, and Microsoft's usage has no relation to it.

The two Microsoft forms mean different things. Recipient address rejected with access denied usually means the address does not exist in the tenant, or exists but is configured to reject external mail. Distribution groups and shared mailboxes are frequently set to accept only from authenticated internal senders, which produces this code for every external sender while internal mail flows perfectly. Relay access denied means the server does not consider you authorised to send through it to that destination at all.

The recipient-side restriction is the one worth knowing about, because it is invisible from outside and looks exactly like a bad address. A group configured to require sender authentication rejects everyone external with no indication that the address is valid. If a recipient insists their address works and you are getting 5.4.1, that setting is the first thing for them to check.

How 5.4.1 plays out

Your server attempts delivery
The recipient server returns a permanent 5.4.1 rejection
This is a hard bounce: the message will not be accepted as sent
Suppress the address and fix the root cause before resending

Where 5.4.1 sits: soft vs hard bounce

Soft bounce (4xx) Hard bounce (5xx)
NatureTemporaryPermanent
SMTP class4xx5xx
What to doLet it retrySuppress the address
Recoverable?OftenNo
5.4.1 is✓ this code

What each provider means by 5.4.1

A registered code does not oblige a provider to use it that way, and the large ones diverge. Match the wording in your own bounce, not the definition above.

Exchange Online Recipient address rejected with access denied, or relay access denied Reference
IANA registry The registry assigns 5.4.1 to no answer from host Reference

Common causes of 5.4.1

  • The recipient address does not exist in the destination tenant
  • A distribution group or shared mailbox is set to accept mail only from authenticated senders
  • A mail flow rule at the destination blocks your domain or address
  • You are attempting to relay through a server that does not authorise you
  • The destination applies a directory-based edge block to unknown recipients
  • The recipient organisation restricts inbound mail to an allowed sender list

How to fix 5.4.1

  • Confirm the recipient address exists and is spelled correctly
  • Ask the recipient to check whether the group or mailbox requires sender authentication
  • If relaying, verify you are authenticating and that the domain is registered with the relay
  • Ask the recipient administrator to check mail flow rules for a block on your domain
  • Do not retry, since the leading 5 makes this permanent and retries harm reputation
  • Distinguish this from 5.1.1, which means the address genuinely does not exist

Frequently asked questions

What does 550 5.4.1 mean?
From Microsoft it means either that the recipient address was rejected with access denied, or that relay access was denied. The first usually means the address does not exist or is restricted; the second means the server does not consider you authorised to relay through it. It is a permanent rejection either way.
The recipient says their address works, so why am I rejected?
Most likely because the address is a distribution group or shared mailbox configured to accept mail only from authenticated internal senders. That setting rejects every external sender while internal mail flows normally, so the recipient sees nothing wrong. Ask them to check whether sender authentication is required on that address.
How is 5.4.1 different from 5.1.1?
5.1.1 means the mailbox does not exist. 5.4.1 from Microsoft usually means it exists but you are not permitted to send to it, or that relaying was refused. The practical difference matters for list hygiene: a 5.1.1 address should be suppressed, while a 5.4.1 may be a perfectly valid address behind a restriction that can be lifted.
Why does the registry say 5.4.1 means no answer from host?
Because IANA assigns X.4.1 to that network condition, and Microsoft uses the number for something entirely unrelated. Both meanings exist in the wild. If your bounce came from Exchange Online, read it as relay or recipient access denial rather than as a connectivity problem.
Should I remove 5.4.1 addresses from my list?
Not automatically. Unlike 5.1.1, a 5.4.1 often indicates a valid address behind a policy restriction rather than an invalid one. Suppress it for now to protect your bounce rate, but treat it as recoverable and worth a conversation with the recipient rather than as a dead address.
Reviewed by Jennifer Jackson, Email Deliverability Analyst · June 2026 ← All bounce codes