550 5.4.1: recipient address rejected, access denied
Likely causes
- The recipient address is misspelled or doesn't exist.
- The recipient exists on-premises but isn't synced to Exchange Online (hybrid).
- The recipient is a mail-enabled public folder or dynamic distribution group that Exchange Online doesn't know about.
- MX or DNS records point to a server that doesn't accept mail for the domain (Relay Access Denied).
How to fix it
- Check the address in the bounce for typos and send again.
- Work out the scope: one recipient, or every address in the domain? One recipient points to that object. The whole domain points to domain or DNS setup.
- Admins: confirm the recipient exists in Exchange Online. For hybrid users, check directory sync is working and the proxy addresses are right.
- Admins: check the domain’s MX record points to Exchange Online and the domain is an accepted domain.
- Admins in hybrid: Authoritative domains reject unknown addresses. Only use Internal Relay if a connector routes unmatched mail to your on-premises servers.
Checked against: learn.microsoft.com, support.microsoft.com