Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

550 Connection Rejected is a permanent SMTP rejection, not a diagnosis. The fix depends on the full reply—especially its enhanced status code, the server that rejected the message, and the point in delivery where it happened. For forwarded mail, common causes include SPF/DKIM/DMARC problems, sender reputation, relay permissions, disabled external forwarding, and malformed headers.

Start with the exact bounce text, then use the matching clue below. A generic 550 5.7.1 can mean several different things; do not assume it means “spam.”

Find the cause from the complete bounce

SMTP replies have three useful parts:

  • 550: the basic SMTP reply code. A 5xx response is normally treated as a permanent failure, although the sending system controls its retry behavior.
  • An enhanced status code, such as 5.7.1: a more specific category. Other examples include 5.7.25 for a PTR/reverse-DNS problem and 5.7.29 for a TLS problem in Gmail’s documentation.
  • The diagnostic text: the receiving server’s explanation. This is often the most useful clue.

Two bounces that begin with 550 5.7.1 may need completely different fixes. Google lists many possible Gmail rejection causes under that code, while Microsoft says Exchange Online 5.7.1 can involve permissions, relay authorization, routing, or an organizational security setting. See Google’s Gmail SMTP error reference and Microsoft’s 550 5.7.1 troubleshooting guide.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Mail apps often show only a shortened notification. Open the full delivery-status notification (DSN), or ask the mail administrator or hosting provider for the mail log. Record:

SMTP reply and enhanced status code:
Rejecting server:
Sending IP:
Envelope sender (MAIL FROM):
Visible From address:
Recipient:
Stage of rejection:
Provider reference or error ID:

The rejection stage can help distinguish a connection-level problem from a rejected sender, recipient, relay, or message. The host named in a line such as “Remote server returned” is usually the system that made the rejection. For example, gmail-smtp-in.l.google.com indicates Google’s mail system; a hostname ending in protection.outlook.com indicates Microsoft-hosted mail. A hosting server’s own Exim or Postfix hostname may instead point to a local routing or relay issue.

Quick fixes by bounce wording

Bounce clue Likely issue First action
IP is not authorized to send directly The server is attempting direct delivery without an authorized sending path. Use the mail provider’s authenticated SMTP service or approved relay. Do not try to bypass the recipient’s policy.
Authentication checks, unauthenticated email, SPF, DKIM, or DMARC Sender authentication failed, or forwarding broke alignment. Check the actual sending path, envelope sender, and authentication results. Preserve valid DKIM; have the forwarder use SRS or equivalent envelope rewriting where supported.
PTR, reverse DNS, or 5.7.25 The sending IP lacks valid reverse DNS, or its PTR hostname does not resolve back to that IP. Ask the IP owner or hosting provider to set and verify the PTR record.
Not sent over TLS or 5.7.29 The SMTP connection did not meet the recipient’s TLS requirement. Correct TLS on the sending client or relay; changing SPF will not fix a TLS failure.
S3140, S3150, or explicit block-list language Microsoft rejected the sending IP or its reputation. Check for compromised accounts, websites, or scripts and contact the IP owner or mail provider about remediation.
Automatic forwarding is disabled An organization policy blocks external forwarding. Ask the Microsoft 365 administrator to review outbound spam policy, remote-domain restrictions, and mail-flow rules together.
Relaying denied or not permitted to relay The server is not authorized to send through that relay, or its routing configuration is wrong. Authenticate with the permitted SMTP service and verify accepted-domain and relay settings.
Suspicious, likely unsolicited, rate limit, or reputation language The recipient distrusts the sending IP, domain, volume, or content. Review traffic, complaints, bounces, compromised credentials, and the provider’s stated limits before sending again.
Missing Message-ID, duplicate headers, or invalid From The message or forwarding software produced malformed headers. Correct the application or forwarder. Do not keep resending a malformed message.

The diagnostic text matters: “550” by itself does not prove that a public blocklist caused the failure, nor does it establish that the recipient address is invalid.

Why forwarding causes email authentication failures

Original sender  →  Your forwarding service  →  Final recipient

The forwarding service accepts the original message, then makes a new SMTP delivery to the final mailbox. The final recipient sees the forwarder’s server IP as the immediate sender, while the original sender’s envelope address may still be present. The original sender’s SPF record usually authorizes its own sending infrastructure—not every forwarding service—so SPF can fail on the second hop.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Keep these identities separate:

  • Envelope sender: the SMTP MAIL FROM address, used for bounces and SPF evaluation.
  • Visible From: the address displayed to the recipient and used in DMARC alignment.
  • DKIM signer: the domain in the message’s valid DKIM signature, if one survives forwarding.

Sender Rewriting Scheme (SRS) changes the envelope sender so SPF can be checked against the forwarder’s domain. It does not change the visible From address and does not, by itself, guarantee DMARC alignment. DMARC can still fail if neither the SPF-authenticated domain nor the DKIM signing domain aligns with the visible From domain. A valid original DKIM signature may survive if the forwarder does not alter signed headers or message content; ARC can provide authentication context, but whether a recipient trusts it is that recipient’s decision. See Google’s forwarding guidance and Microsoft’s explanation of SRS.

Simply adding a forwarder to the original sender’s SPF record is usually not the right fix: SPF is evaluated against the envelope sender, and you may not control that sender’s domain. Ask the forwarding provider whether it supports SRS, preserves DKIM, and adds useful forwarding headers. Google recommends envelope-sender rewriting, preserving DKIM, avoiding message changes that invalidate signatures, adding forwarding headers such as X-Forwarded-For or X-Forwarded-To, and filtering spam before forwarding.

Check DNS and authentication

Run these checks for your own domain and, where relevant, the actual sending hostname and IP. Replace the example names and IP with your real values:

dig MX example.com
dig TXT example.com
dig TXT _dmarc.example.com
dig TXT selector1._domainkey.example.com
dig -x 203.0.113.25
dig A mail.example.com

On Windows, use:

nslookup -type=MX example.com
nslookup -type=TXT example.com
nslookup -type=TXT _dmarc.example.com
nslookup -type=PTR 203.0.113.25

SPF

There should be one SPF record for a domain, containing the authorized sending services. If you add a provider, merge its mechanism into the existing record rather than publishing a second SPF record. SPF also has a limit of ten DNS lookups during evaluation; nested includes can exceed it. A DNS lookup can show what is published, but it cannot alone prove that the recipient evaluated the expected envelope sender or that the whole authentication chain passed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Forvencer Server Book, 2 Zipper Pocket, Server Books for Waitress
  • Upgraded Two Zipper Pockets: Forvencer server books feature two secure zipper pockets for better organization of coins, cash, and receipts, ensuring that everything you collect has a safe and secure place
  • Smart Storage & Quick Access: Designed with 8 multi-functional compartments, the right side includes a guest receipt pad, while the left has a money pocket, ticket pocket, and credit card slot. Two small clear pockets store bills, receipts, and other visible items. A stitched pen loop ensures you always have your favorite pen ready
  • High-quality & Easy to Clean: Crafted from high-quality PU leather with heavy-duty stitching, this server book is built to last. It resists tears, scratches, and its waterproof surface makes cleaning easy with just a damp cloth or a non-chlorine sanitizer
  • Perfect Fit for Your Apron: Measuring 5” x 8”, this compact organizer is slightly smaller than other models, making it ideal for bending or sitting while carrying in your server apron. It holds everything a waitress needs—a place for everything
  • What's Included: This server organizer comes with multiple open and zippered pockets to store money, receipts, tips, etc. Clear sleeves are perfect for keeping menus or special lists while serving. Available in a variety of colors, allowing you to express yourself even when in uniform

DKIM

Check the recipient’s Authentication-Results header for dkim=pass and identify the signing domain and selector. Forwarders, mailing lists, or gateways that change the body or a signed header can invalidate a signature. If the forwarder adds its own signature, its selector’s public key must also be published correctly in DNS.

DMARC

DMARC checks whether the visible From domain aligns with a domain that passed SPF or DKIM. SRS can help SPF pass for a forwarded hop without making that SPF identity align with the original visible From. A preserved, aligned DKIM signature may allow DMARC to pass even when SPF fails.

Do not change p=reject to p=none as a blanket remedy. Review DMARC reports and identify the actual sender or forwarding path first. A temporary policy change, if an administrator chooses to make one, is a controlled diagnostic—not a repair for bad reputation, malformed messages, disabled forwarding, or unauthorized relay.

PTR and reverse DNS

If the bounce identifies reverse DNS, find the public IP actually making the outbound connection. Query its PTR with dig -x, then confirm that the returned hostname has an A record pointing back to the same IP. The IP owner normally controls the PTR, so shared-hosting customers should ask the provider to correct it. Google documents 550 5.7.25 for a missing PTR or a forward-DNS mismatch in its SMTP error reference.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

TLS

If the response explicitly cites TLS, verify that the sending MTA or SMTP client negotiates TLS with the relay or recipient as required. Gmail documents 550 5.7.29 for mail blocked because it was not sent over a TLS connection. DNS changes do not correct a broken TLS configuration.

Check forwarding settings and mail routing

Identify exactly where forwarding happens: Gmail or Google Workspace, Microsoft 365, cPanel/Exim, a self-hosted Postfix/Exim server, Cloudflare Email Routing, or a dedicated forwarding service. Then check:

  • Whether the destination address has been verified, and whether the mailbox or domain has forwarding enabled.
  • Whether external forwarding is prohibited by an organization policy, mail-flow rule, remote-domain restriction, or security control.
  • Whether the domain’s MX records point to the intended mail host or instead to an old server, parking provider, or gateway.
  • Whether cPanel is set to the correct local or remote mail exchanger for the domain.
  • Whether the sender is using an authorized SMTP relay with authentication where required.
  • Whether two aliases forward mail back and forth, creating a loop, or whether several forwarding hops alter the message.
  • Whether a mailbox, website, contact form, or application has been compromised and is generating unwanted outbound mail.

Microsoft 365’s external-forwarding controls deserve particular attention. Microsoft documents that Automatic - System-controlled has the effective behavior of forwarding being disabled, and other mail-flow rules or remote-domain settings may also block a user-created forwarding rule. Review the controls together in Microsoft’s external forwarding guidance; changing one setting may not override another.

Rank #3
Sale
Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022
  • Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022, 3rd Edition
  • ABIS BOOK
  • Packt Publishing

Provider-specific checks

If Gmail is rejecting the message

Use the full Google response to distinguish among unauthorized direct delivery, authentication, PTR, TLS, reputation, malformed headers, and rate or policy limits. Check the actual outbound IP, SPF and DKIM results, DMARC alignment, and whether forwarding preserved the original DKIM signature. If the connection uses IPv6, verify the IPv6 address’s PTR and forward DNS too. Google’s Gmail SMTP error list describes multiple different rejection conditions, including several under 5.7.1.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a personal Gmail account receiving forwarded mail, the forwarding service’s configuration matters; changing Gmail’s settings will not repair a sender-side PTR, relay, or reputation problem. If you need to send replies as a non-Gmail address, configure that identity using Gmail’s Send mail as feature and the address provider’s supported sending method. Inbound forwarding alone does not authenticate outbound mail as your custom domain.

If Microsoft 365 or Outlook is involved

Determine whether Microsoft is the sender’s forwarding organization or the final recipient. If Microsoft 365 is forwarding externally, have its administrator inspect the outbound spam policy, remote-domain settings, and mail-flow rules. If Microsoft-hosted mail is the destination, investigate the rejection text for relay, routing, permissions, IP reputation, and any Microsoft block identifier. Microsoft’s 550 5.7.1 guide notes that action may be needed by the sender’s or recipient’s administrator.

Microsoft 365 uses SRS for applicable external forwarding, but that does not change the visible From address or guarantee DMARC alignment. See Microsoft’s SRS reference.

If you use cPanel or shared hosting

Open Email Deliverability in cPanel and review its SPF and DKIM recommendations. Confirm that MX records point to the intended host and that the domain’s mail exchanger setting matches the actual arrangement. Ask the host to inspect Exim logs for the precise destination response, sending IP, and message stage.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If Microsoft’s response names S3140 or S3150, the sending IP’s reputation or block status may be involved. cPanel lists incorrect authentication, spam from the server, compromised websites, and IP blocklisting among possible causes in its Microsoft blocklist troubleshooting note. The IP owner or hosting provider, not a customer without IP control, will usually need to investigate or request remediation.

A message such as 550 Please turn on SMTP Authentication points to a relay or client configuration problem; see cPanel’s SMTP-authentication guidance. For Gmail connection timeouts from a cPanel server, the host may also need to check outbound port 25 connectivity; cPanel discusses this in its Gmail delivery troubleshooting article.

Rank #4
Forvencer Server Book High Volume, Expandable Waitress Book with 2 Zipper
  • Upgraded Magnetic Closure Pocket and Two Zipper Pockets: Unlike other brands, Forvencer server books are designed with two secure zipper pockets and two expandable magnetic pockets. These allow you to easily store and organize a large number of coins, cash, and receipts.
  • Smart Storage & Quick Lookup: 10 multi-functional compartments. On the right side has a check pad, and on the other has a Money Pocket, Tickets Pocket and Credit Card Slot. Two small clear pockets can store bills, receipts and other items to be viewed. A stitched pen loop to store your favorite pen.
  • Long-Lasting and Easy to Clean: Serving book features high-quality PU leather and heavy-duty stitching. PU is extremely strong with high tensile strength and good resistance to tearing, abrasion and scratching. Waterproof leather makes it simple to wipe down your server book with warm water or non-chlorine sanitizer solution to remove any dirt, soil, grime, or soda residue to keep it clean.
  • Fit Perfectly in your Apron: Our 5" x 9" server book is designed to accommodate regular checks and fit easily in your apron pocket.
  • What You Get: Forvencer server book in strict quality control, our worry-free 1-Year warranty, and friendly customer service.

If you use Cloudflare Email Routing

Cloudflare Email Routing is an inbound forwarding service, not a hosted mailbox or a general-purpose outbound SMTP relay. It requires Cloudflare DNS for the domain’s routing setup; follow the current setup documentation and check its domain configuration for the required records. Cloudflare documents SRS and ARC support in its postmaster information, but a destination provider still makes its own acceptance decision. Cloudflare also notes that Email Routing does not forward non-delivery reports to the original sender, and replies originate from the destination address unless a separate sending arrangement is configured.

If you run Postfix, Exim, or another mail server

Check the outbound queue and MTA logs for the complete remote response and the exact outbound IP. Verify that the server routes mail through the intended smarthost, authenticates where required, uses TLS where required, and has correct SPF, DKIM, PTR, and forward DNS. A controlled SMTP test can help identify where a connection fails, but only test a server and recipient you are authorized to use. For example, swaks can test an authenticated submission connection on port 587:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
swaks --server smtp.example.com 
      --port 587 
      --tls 
      --auth LOGIN 
      --auth-user [email protected] 
      --auth-password 'REDACTED' 
      --from [email protected] 
      --to [email protected]

Use your provider’s current SMTP settings and supported authentication method. Do not put real passwords in shell history, screenshots, or support tickets. A successful test to one provider does not prove that Gmail, Microsoft, Yahoo, or another recipient will accept the message.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Check reputation and blocklist claims carefully

If the bounce explicitly names a blocklist or provider block, investigate the sending IP and domain with the provider that controls them. Look for unusual outbound volume, high bounce or complaint rates, compromised mailboxes, stolen SMTP credentials, malware, and scripts or contact forms sending mail. On shared hosting, another customer may affect the shared IP’s reputation; the host must investigate the IP and handle provider escalation.

Do not call a rejection a “public blocklist” problem unless the response or a separate check supports that conclusion. A recipient can distrust an IP based on its own reputation and policy signals without identifying a public DNS blocklist. For Microsoft S3140/S3150-style errors, see the cPanel explanation and, for a sending-platform case, SendGrid’s Microsoft delivery guidance.

Choose an architecture that fits the job

  • Keep ordinary forwarding if you only need low-volume inbound delivery and the forwarder handles SRS or equivalent rewriting, preserves DKIM, and is accepted by the destination.
  • Use a hosted mailbox if you need reliable send-and-reply behavior as your custom-domain address, multiple users, administration, retention, or organizational controls. Google Workspace or Microsoft 365 may be a better fit than a fragile chain of aliases; check current availability and terms for your location.
  • Use a dedicated forwarding service if you want custom-domain inbound aliases without a full mailbox. Check for SRS, DKIM/ARC handling, abuse controls, destination verification, and limitations on replies and bounce handling.
  • Use a transactional email provider for application-generated or transactional sending that needs delivery logs, bounce processing, and authenticated outbound infrastructure. It is not automatically appropriate for receiving mail or relaying arbitrary third-party forwarded messages; follow its acceptable-use policy.

Changing providers does not necessarily fix a compromised source, malformed forwarder, missing authentication, or recipient-side policy. Fix the cause before moving mail to another service.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Test safely after a change

  1. Change one relevant setting at a time and allow DNS changes to become visible where applicable.
  2. Send a minimal plain-text test to one mailbox you control. Avoid bulk tests or repeated retries while the same 5xx cause remains.
  3. Inspect the delivered message’s headers for Received, Return-Path, Authentication-Results, DKIM-Signature, and, where present, ARC-Seal, ARC-Message-Signature, ARC-Authentication-Results, X-Forwarded-For, and X-Forwarded-To. Note whether SPF, DKIM, DMARC, and ARC passed, and which domains were evaluated.
  4. Test separately to Gmail, Outlook.com or Microsoft 365, and another provider if those destinations matter. Acceptance at one provider is not proof of universal deliverability.
  5. If rejected again, compare the new full response with the old one. A changed code or diagnostic can show that one issue was fixed while another remains.

A 4xx response generally indicates a temporary failure that a sending server may retry according to its queue policy. Treat a 550/5xx rejection as permanent until something relevant changes. Repeatedly resending the same rejected message is not a fix and can create duplicates or worsen reputation. Waiting may matter after a provider-side action or DNS update, but “wait 24 hours” is not a universal remedy.

When to contact the mail provider or administrator

Contact the party that controls the rejected part of the route: the forwarding service, outbound IP owner or hosting provider, sending organization’s mail administrator, or final recipient’s administrator. Provide the complete bounce, not just “550 Connection Rejected,” along with:

  • UTC time of the attempt, recipient provider, and any provider error or reference ID.
  • Sending IP, sending domain, envelope sender, and visible From address.
  • Whether the message was forwarded and the services or servers in the path.
  • Recent SPF, DKIM, DMARC, MX, and PTR check results, plus relevant authentication headers if a copy was delivered elsewhere.
  • Approximate sending volume, whether the IP is shared or dedicated, and any evidence that a compromised mailbox, website, or script has been secured.

If the response points to a recipient-side permission or policy, the sender may not be able to resolve it alone; the recipient’s administrator or provider may need to allow the message or correct routing.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.