Skip to main content
Email

Email Rejected 550 5.7.515: What It Means and How to Fix It

If you sent an email and got back a bounce message containing the code "email rejected 550 5.7.515," Microsoft blocked your message before it reached the customer. This is not a problem with their inbox or your internet connection. It is an email authentication failure, and there is a specific five-step fix for it.

Here is what the code means, why it is happening, and how to stop it.

What does error 550 5.7.515 mean?

Error 550 5.7.515 means Microsoft's mail servers rejected your outbound email because your sending domain failed its authentication check. The full error reads: "Access denied, sending domain [yourdomain.com] does not meet sender requirements."

Microsoft began enforcing this check on May 5, 2025, for all email destined for Outlook.com, Hotmail, and Exchange Online addresses. If your emails were delivering fine before spring 2025 and started bouncing after, that enforcement change is almost certainly why. According to Microsoft's official NDR guidance, the error is a hard bounce, meaning the message is undeliverable and the customer sees nothing.

You get the non-delivery report. They get silence.

Why is my domain failing authentication?

Three gaps cause the 550 5.7.515 error: a missing SPF record, DKIM signature, or DMARC policy that is not aligned with those two records.

SPF (Sender Policy Framework) is a DNS record that tells Microsoft which mail servers are authorized to send email as your domain. Without it, any server looks like a potential impersonator. DKIM (DomainKeys Identified Mail) is a cryptographic signature added to each message that proves it was not tampered with in transit. DMARC ties both together and tells the receiving server what to do when either check fails. Without a published DMARC policy, Microsoft now defaults to rejection.

The gap is widespread. A Parallax Intelligence audit of 435 Southwest Michigan business domains found that 85.9% have no DMARC enforcement in place. Nearly 9 in 10 local businesses are missing the exact record that causes this bounce.

How do I fix a 550 5.7.515 email bounce?

The fix follows a set sequence. Skipping steps or doing them out of order usually means the bounce continues. Most businesses with a single email provider can complete this in under an hour.

  1. Check what is missing. Go to MXToolbox Email Health and enter your domain name. It runs in about 30 seconds and shows exactly which records are absent or broken. No account required.

  2. Fix your SPF record. Add or update the DNS TXT record at your registrar. For Google Workspace, the value is "v=spf1 include:_spf.google.com ~all". For Microsoft 365, it is "v=spf1 include:spf.protection.outlook.com ~all". If you use another provider, they document the exact include. Only one SPF record is allowed per domain.

  3. Enable DKIM signing. Both Google Workspace and Microsoft 365 have DKIM configuration inside the admin console. They generate a public key; you copy it into a DNS TXT record at your registrar. Allow 24 to 48 hours for DNS to propagate before testing.

  4. Add a DMARC record. Start with "p=none" so you can observe the traffic without disrupting delivery: "v=DMARC1; p=none; rua=mailto:[email protected]". After 30 days of clean reports, step up to "p=quarantine" or "p=reject" to enforce the policy.

  5. Test and monitor. Send a test email to an Outlook or Hotmail address after DNS propagates. If it delivers, the fix worked. Check your DMARC reports after 30 days before stepping up enforcement.

If you send from multiple services such as a CRM, a billing tool, and a contact form, each one needs an SPF include and its own DKIM key. That is where most small businesses hit friction. The how to stop quotes going to spam guide covers the multi-sender setup in detail.

Frequently asked questions about the 550 5.7.515 error

How long does it take to fix the 550 5.7.515 error?

DNS changes take 24 to 48 hours to propagate fully. If you complete all five steps in one afternoon, most customers will see successful delivery by the following business day. The actual configuration work usually takes under an hour for a single email provider.

Can I fix this myself without an IT person?

Yes, if you have login access to your domain registrar and your email provider's admin console. Google Workspace and Microsoft 365 both have step-by-step DKIM setup guides inside their admin interfaces. SPF and DMARC are standard DNS TXT records your registrar lets you add through a web form. The trickier situation is when you send from multiple services; that requires careful SPF merging to avoid breaking your current setup.

Does Gmail enforce the same rules as Microsoft?

The 550 5.7.515 code is specific to Microsoft (Outlook, Hotmail, Exchange Online). Gmail enforced its own authentication crackdown in November 2025 through updated Google sender requirements, and unauthenticated mail to Gmail addresses may be rejected at the gateway as well. The fix is the same for both platforms: SPF, DKIM, and DMARC aligned and published. Resolving one platform's issue resolves them both.

If I use Microsoft 365 already, am I protected?

Not automatically. Microsoft 365 gives you the tools to configure SPF and DKIM, but it does not add DNS records on your behalf. You need to add SPF at your registrar and enable DKIM through the Microsoft 365 admin center. Many businesses that have been on M365 for years still have neither configured. If you have not explicitly set these records up, your domain is likely missing them.

Need this fixed today?

If you run a service business in Battle Creek, Kalamazoo, or anywhere in Southwest Michigan and would rather have this handled than do it yourself, the Parallax DMARC audit service covers the full setup: SPF, DKIM, DMARC, testing, and a follow-up report confirming enforcement is working. The same fix that stops the bounce also closes the spoofing window, meaning no one can send email that appears to come from your domain. Reach out at (269) 460-1772 or through the contact form.

You can also see how your domain compares to the 435 businesses we have already audited in the why customers aren't getting your emails guide.

Matthew Williams

Founder of Parallax Intelligence. Automation and AI for Southwest Michigan businesses.

READY?

Ready to stop doing the machine's job?

Book a free 20-minute discovery call. We'll talk about what's eating your time.

Get in Touch

Or reach out: (269) 460-1772 | [email protected]