What the receiver is telling you

This is Microsoft telling one of its own tenants that a user account has been restricted from sending. It fires when an account's outbound mail looks compromised or spammy: too many recipients, too many sends, a spike in bounces or complaints. If you run cold email from Microsoft 365 inboxes, this is what a burned inbox looks like. The account still receives mail; it cannot send until an admin unblocks it in the Defender portal, and if it is unblocked without changing the behaviour it is re-blocked within hours.

Why a policy block must not be treated as a bad address

Sending tools file every 5xx under "bounced", and the natural reflex is to scrub the address. For a policy block that is exactly wrong. The recipient exists and would have received the mail; the receiver refused it because of your domain, IP, authentication or content. Scrubbing throws away a lead and leaves the cause in place, so the next send produces the same block against the next thousand addresses. The right response is to stop sending from the affected domain, find what the receiver named, fix it, and resume at low volume.

What to do

  1. In the Microsoft 365 Defender portal, go to Review → Restricted entities, find the user and remove the restriction.
  2. Before you do, cut that inbox's daily sends to under 20 and check the list it was sending to.
  3. If several inboxes on one tenant are restricted, the tenant is at risk of a tenant-wide outbound block; pause everything for a day.

don't Do not create a new user in the same tenant and carry on. Tenant-level restrictions follow.

Decode the whole bounce

Paste the complete failure notice — every code and the receiver's wording — and get each part explained together.

Common questions

How long does a 5.7.510 restriction last?

Until an admin removes it. Microsoft does not lift it automatically.

What triggers it?

Outbound spam detection: high recipient counts, high bounce or complaint rates, or patterns that resemble a compromised account.

Related codes

Often seen alongside

Go deeper

Related reading

When it is broken

If this is the thing going wrong

The pages explain it. If you would rather it was simply fixed, that is the work I do.

← All error codesEmail authenticationReputationDeliveryInfrastructureBook a call →
Back to top