smtp bounce code
550 5.4.1Recipient address rejected: access denied
what to do
Keep the address, fix your side
Microsoft 365's catch-all refusal. It usually means the address does not exist, but it is also returned for tenant policy, so it is weaker evidence than 5.1.1.
What the server is telling you
Exchange Online returns this both for unknown recipients and for addresses that exist but are not accepting external mail. The two cases are indistinguishable from outside, which is deliberate: it stops attackers enumerating a tenant's mailboxes.
Next steps
- →Treat as risky rather than dead unless you have other evidence.
- →If the domain is Microsoft 365, expect this for most invalid addresses.
- →A pattern check helps: if colleagues at the same domain follow first.last and yours does not, it is probably wrong.
Commonly returned by: Microsoft 365 / Exchange Online
Find these before you send, not after
Paste a list and see which addresses sit on domains that accept no mail, which are one character from a real inbox, and which are on catch-all domains where nothing can tell you anything. Free, no signup, nothing stored.
Check a list →