Short answer: 550 5.7.515 Access denied, sending domain [SendingDomain] does not meet the required authentication level is Outlook.com rejecting mail from a domain that sends more than 5,000 messages a day to its consumer mailboxes (outlook.com, hotmail.com, live.com) without passing SPF, DKIM and DMARC. Fix it by making SPF pass for the envelope domain, signing with DKIM for the From domain, and publishing a DMARC record of at least p=none that aligns with SPF or DKIM. Safe-sender lists do not bypass it.
We ran the Exim routing and log checks below on our lab servers (AlmaLinux 9.8 with cPanel & WHM 11.138, and DirectAdmin 1.712, Exim 4.100.1) on 6 October 2026. The requirements were checked against Microsoft’s Outlook.com postmaster pages and its Tech Community announcement (linked below) on the same day.
Table of Contents
What 550 5.7.515 means and who it hits
In April 2025 Microsoft announced requirements for domains that send more than 5,000 emails per day to Outlook.com, its consumer service for hotmail.com, live.com and outlook.com addresses. The Outlook.com postmaster error table describes 550 5.7.515 as mail rejected for policy reasons because the sending domain is above that volume and is not authenticated with SPF, DKIM and DMARC.
It is not a Microsoft 365 (Exchange Online) business-tenant rule. If the recipient is bob@contoso.com hosted on Microsoft 365, this code is not the one you will see. Mail to consumer Outlook.com addresses is what triggers it.
The volume is counted for the sending domain, so many small senders on one domain add up. A hosting company whose customers all send from their own domains is usually below the line per domain. A SaaS app or newsletter platform sending as one domain often is not.
The requirements
| Check | Microsoft requirement | What to verify |
|---|---|---|
| SPF | Must pass for the sending domain | The Return-Path (envelope) domain has one SPF record that lists the sending IP and stays under 10 lookups |
| DKIM | Must pass | Messages carry a valid DKIM signature; the key in DNS matches the signing key |
| DMARC | At least p=none, aligned with SPF or DKIM (preferably both) | _dmarc.example.com exists and the From domain matches the SPF or DKIM domain |
Microsoft also lists hygiene practices for large senders: a valid From or Reply-To address that can receive replies, a working unsubscribe link, regular removal of invalid addresses, and honest subjects and headers. These are recommendations, but Microsoft says it may filter or block senders that ignore them. Its FAQ also says that adding the sender to a recipient’s safe-senders list does not bypass the authentication rule.
Junk folder or rejection: what Microsoft has said
Microsoft’s own pages are not consistent here, so read them with care:
- The original announcement (2 April 2025) said non-compliant mail would go to Junk first and might be rejected later.
- An update to the same post (end of April 2025) says Microsoft decided to reject failing messages with
550; 5.7.515, taking effect on 5 May 2025. The text below the update still describes Junk routing. - The Outlook.com postmaster Policies page, as of 6 October 2026, still says Junk first and rejection if issues remain unresolved, while its error table lists
550 5.7.515.
For a sysadmin the practical answer is the same: if you see the code, mail is bouncing now, and the only fix is authentication. Do not wait for Junk-folder warnings.
Find the failing domain and stream
The bounce names the domain. Search your MTA log for the code to find which sender and which system sent the mail. On cPanel the main log is /var/log/exim_mainlog; on DirectAdmin it is /var/log/exim/mainlog. exigrep prints every log line for each matching message:
exigrep '5\.7\.515' /var/log/exim_mainlog | less # cPanel
exigrep '5\.7\.515' /var/log/exim/mainlog | less # DirectAdmin
To confirm where Exim delivers Outlook.com mail, test the routing without sending anything:
exim -bt someone@outlook.com
On both labs this showed router = lookuphost, transport = remote_smtp and the outlook-com.olc.protection.outlook.com MX hosts, so the message leaves through Exim’s normal remote transport, which is where DKIM signing happens. If you relay through a smarthost, the relay signs and its settings matter instead.
Bounce texts reported by senders on Microsoft’s announcement post include the SPF, DKIM and DMARC results after the main message. Read those results first: they tell you which check failed.
Fix SPF, DKIM and DMARC for the domain
SPF
Check the envelope domain, which is often different from the From address on web servers:
dig +short TXT example.com | grep -i "v=spf1"
The sending IP (or the include for your relay or ESP) must be in the record, there must be only one SPF record, and the total must stay within 10 DNS lookups. Use our SPF Record Checker.
DKIM
Find the selector in the s= tag of the DKIM-Signature header of a sent message, then look up the key:
dig +short TXT default._domainkey.example.com # cPanel default selector
dig +short TXT x._domainkey.example.com # DirectAdmin default selector
We confirmed those selectors in the Exim configuration of our cPanel and DirectAdmin labs. Microsoft 365 uses selector1 and selector2 CNAME records instead. If no signature is present, turn DKIM on for the domain (cPanel: Email Deliverability; DirectAdmin: the admin can run /usr/local/directadmin/scripts/dkim_create.sh example.com, which creates a 2048-bit key and queues the DNS update) and publish the key. Our DKIM Checker confirms the record parses.
DMARC
_dmarc.example.com. TXT "v=DMARC1; p=none; rua=mailto:dmarc@example.com"
p=none satisfies Microsoft’s minimum. Generate one with our DMARC Record Generator. The From domain must then align: the DKIM d= domain or the SPF envelope domain must be the same organizational domain as the From address.
Alignment traps on hosting servers
- PHP
mail()from a website often uses the account user at the server hostname as the envelope sender. SPF then passes for the hostname, not for the From domain, so it does not align. Send through SMTP with a real mailbox on the domain. - A smarthost or ESP that signs only with its own domain gives a DKIM pass that does not align. Set up custom DKIM for your domain at the provider.
- Forwarders break SPF. Microsoft recommends ARC for forwarding and mailing lists; on your side, make sure DKIM signing is in place so forwarded mail still aligns.
Check that it worked
- Send a test message from the same system that bounced to an outlook.com or hotmail.com mailbox you control.
- Open the message source and read
Authentication-Results. You needspf=pass,dkim=passanddmarc=pass, withheader.frommatching your domain. Paste the headers into our Email Header Analyzer for a summary. - Watch the log for new 5.7.515 bounces with the
exigrepcommand above. - Read the DMARC aggregate reports Microsoft sends to your
ruaaddress. Microsoft says it sends aggregate reports but has no plans to send failure (ruf) reports.
Common problems
- SPF passes, DKIM passes, still 5.7.515. Usually alignment: both passed for domains other than the From domain. Compare
smtp.mailfromandheader.dwithheader.from. - DMARC record exists but is not found. Two TXT records at
_dmarc, or the record does not start withv=DMARC1, means receivers discard it. - DKIM key published but the signature fails. A long key pasted with a broken split, or an old key left in DNS after the panel regenerated it. Compare the published key with the one in
/var/cpanel/domain_keys/public/or/etc/virtual/DOMAIN/dkim.public.key. - Other Outlook.com codes.
421 RP-001toRP-003are rate limits tied to reputation,550 SC-001andOU-002are reputation or content blocks, and550 OU-001points to a Spamhaus listing. Those need SNDS, JMRP and delisting work, not DNS changes.
Official documentation: Microsoft: Outlook’s requirements for high-volume senders · Outlook.com postmaster: policies and guidelines · Outlook.com postmaster: troubleshooting and SMTP error codes
Related: Microsoft 365 SPF DKIM DMARC: Secure Exchange Online Setup · SPF, DKIM and DMARC in cPanel DNS: Setup and Checks · DMARC Checker · Email Header Analyzer · Warm Up New Mail Server IP Without Spam Problems
See also: Gmail and Yahoo Bulk Sender Requirements: 2026 Host Checklist · One-Click Unsubscribe (RFC 8058) for Exim, Postfix, WordPress · Emails Going to Junk in Outlook and Hotmail: Sender-Side Fix · Microsoft SNDS and JMRP Setup: 2026 Portal, Access and Reports · IP Warm-Up Schedule Generator for New Mail Servers
Frequently asked questions
What does 550 5.7.515 mean?
Outlook.com rejected the message because the sending domain sends more than 5,000 messages a day to its consumer mailboxes and does not meet the SPF, DKIM and DMARC requirements.
Does 550 5.7.515 apply to Microsoft 365 business mailboxes?
The requirement Microsoft announced is for Outlook.com, its consumer service for outlook.com, hotmail.com and live.com addresses. Microsoft 365 tenants have their own anti-spam rules.
Is DMARC p=none enough for Outlook.com?
Yes. Microsoft asks for at least p=none, aligned with SPF or DKIM. It recommends moving towards p=reject once all legitimate mail is aligned.
Can recipients whitelist us to avoid the rejection?
No. Microsoft says the safe-senders list is not honoured for this enforcement.
We send fewer than 5,000 a day. Should we still fix this?
Yes. Microsoft says enforcement starts with large senders, but authenticated mail delivers better for everyone, and Gmail and Yahoo require similar setups.