Join our Newsletter — 33% off our NHI Course
Home› Glossary› Cyber Security› 550 SMTP Response Code
Cyber Security

550 SMTP Response Code

← Back to Glossary
By NHI Mgmt Group Updated September 28, 2026 Domain: Cyber Security

A 550 SMTP response code indicates that a message was rejected at delivery time. In this context, Microsoft uses specific 550 variants to signal that a tenant has exceeded its external recipient limit. The code is operationally important because it tells teams the failure is policy enforcement, not a transient mail routing issue.

What a 550 SMTP response code means

A 550 SMTP response code means the receiving system rejected the message at delivery time. In Microsoft environments, specific 550 variants often indicate the tenant has exceeded an external recipient limit, which makes the failure a policy block rather than a transient routing problem.

Why 550 is different from temporary mail failures

SMTP uses response codes to tell senders whether a delivery problem is temporary or permanent. A 550 response is generally a permanent rejection, so retrying the same message unchanged will not usually succeed unless the underlying policy or recipient condition changes.

That distinction matters operationally because teams can waste time chasing mail flow, DNS, or transport issues when the actual issue is policy enforcement. In practice, the code is a signal to inspect the recipient limit, sender behavior, or tenant mail controls rather than message queue health.

Microsoft-specific 550 variants and policy enforcement

Microsoft uses some 550 responses to express tenant-level enforcement decisions, especially where sending volume or recipient counts exceed a configured threshold. That makes the code useful as an administrative signal: the mail system is functioning as designed, but the sending pattern has crossed an allowed boundary.

In those cases, the error is less about message content and more about abuse prevention, tenant hygiene, and service protection. The response can therefore reflect how the provider distinguishes normal bulk mail from suspicious or excessive outbound activity.

How to read the code in delivery troubleshooting

A 550 response should be read in context with the enhanced status text, sender domain, and affected recipient pattern. The SMTP number alone tells you the class of failure, but the attached text usually identifies whether the rejection is due to policy, invalid recipients, authentication, or another delivery rule.

For troubleshooting, the key question is whether the message was rejected by the destination for a permanent reason or whether the problem sits upstream in the sending infrastructure. That interpretation determines whether the next step is mail policy review, recipient validation, or broader message transport investigation.

Risk and Threat Considerations

Persistent 550 rejections can expose a mail governance problem, not just a delivery inconvenience. When the code is triggered by recipient-limit enforcement, it may indicate oversharing, bulk-sending behavior, misconfigured automation, or a tenant that is approaching abuse thresholds.

Failure mechanism: A sender exceeds an external-recipient policy or otherwise trips a permanent rejection rule, which stops delivery and can hide a larger pattern of excessive or unexpected outbound mail.

Impact: Legitimate communications can fail at scale, monitoring may miss the root cause if the code is treated as a generic mail error, and repeated rejections can signal policy drift or unauthorized sending behavior.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Identity Management, Authentication, and Access Control550 policy rejections often reflect enforced sending authorization boundaries.
Recommendation — Review mail-sending entitlements and restrict bulk send paths to approved accounts.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeRecipient-limit enforcement is a privilege boundary on outbound mail behavior.
AU-6 — Audit Review, Analysis, and Reporting550 rejections are operational evidence that should be monitored and analyzed.
Recommendation — Limit outbound mail privileges to the minimum needed for each sender role. Correlate repeated 550 rejections in logs to identify policy breaches or misconfiguration.
CIS Controls v8CIS-6 — Access Control ManagementOutbound mail limits depend on account and service permissions for sending.
Recommendation — Remove unnecessary bulk-send access and approve only required mail capabilities.
ISO/IEC 27001:2022A.8.16 — Monitoring activitiesDelivery rejections are signals that monitoring should surface for investigation.
Recommendation — Alert on repeated 550 responses and route them to mail operations review.

Practitioner Guidance

What to watch for: Treat repeated 550s as a classification problem first, not a transport problem. The most useful next step is to read the enhanced SMTP text and confirm whether the rejection is policy-based, recipient-based, or authentication-related.

Governance implication: If the 550 is tied to recipient limits, align mail-sending controls with business processes so batch mail, automation, and human sends do not unintentionally exceed the tenant’s allowed behavior.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org