{"id":5213,"date":"2026-08-11T05:23:46","date_gmt":"2026-08-11T05:23:46","guid":{"rendered":"https:\/\/www.mailercloud.com\/blog\/?p=5213"},"modified":"2026-09-08T04:42:48","modified_gmt":"2026-09-08T04:42:48","slug":"smtp-5-7-x-bounce-codes","status":"publish","type":"post","link":"https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes","title":{"rendered":"SMTP 5.7.x Bounce Codes Decoded: 5.7.1 and the Policy Family"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A message leaves your queue, gets accepted at the TCP level, negotiates TLS, sends its recipients, and then dies at the end of DATA with something like this:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>550 5.7.26 This email has been blocked because the sender is unauthenticated. Gmail requires all senders to authenticate with either SPF or DKIM.<\/em><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Or this:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>550 5.7.509 Access denied, sending domain [yourdomain.com] does not pass DMARC verification and has a DMARC policy of reject.<\/em><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">The <strong>5.7.x<\/strong> family is the hardest bounce class to diagnose, because it means the receiver understood you perfectly and refused you anyway. There is no typo to fix, no mailbox that doesn&#8217;t exist, no full quota. The recipient server parsed your envelope, evaluated it against a policy, and said no.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This page is a reference for that family specifically \u2014 every registered code, what the major providers add on top, and how to work out which one you&#8217;re actually looking at.<\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_88 counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes\/#How_to_read_an_SMTP_status_code\" >How to read an SMTP status code<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes\/#The_57x_family_decoded\" >The 5.7.x family decoded<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes\/#47x_the_same_family_temporary\" >4.7.x: the same family, temporary<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes\/#The_five_most_common_57x_causes_in_practice\" >The five most common 5.7.x causes in practice<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes\/#How_to_diagnose_from_your_bounce_logs\" >How to diagnose from your bounce logs<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes\/#Fixing_each_cause_the_order_that_works\" >Fixing each cause: the order that works<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes\/#Prevention\" >Prevention<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes\/#Shared_IP_vs_dedicated_IP_who_fixes_what\" >Shared IP vs dedicated IP: who fixes what<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes\/#How_Mailercloud_handles_bounce_diagnostics\" >How Mailercloud handles bounce diagnostics<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes\/#FAQ_SMTP_57x_errors\" >FAQ: SMTP 5.7.x errors<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_read_an_SMTP_status_code\"><\/span>How to read an SMTP status code<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A modern rejection line has three parts, and most senders read the wrong one.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><code>550 5.7.26 This email has been blocked because the sender is unauthenticated.<\/code><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. <strong>The reply code (<code>550<\/code>).<\/strong> <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The original three-digit SMTP code from RFC 5321. It tells you almost nothing beyond permanent (5xx) versus temporary (4xx). Nearly every policy rejection is a <code>550<\/code>, sometimes <code>554<\/code>, <code>552<\/code>, or <code>530<\/code>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>2. The enhanced status code (<code>5.7.26<\/code>).<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Defined by <a href=\"https:\/\/www.rfc-editor.org\/rfc\/rfc3463\" rel=\"nofollow\">RFC 3463<\/a> as <code>class.subject.detail<\/code>. The class is 2 (success), 4 (persistent transient failure) or 5 (permanent failure). The subject is the category. The detail narrows it down.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">RFC 3463 defines class 5 as a failure &#8220;not likely to be resolved by resending the message in the current form. Some change to the message or the destination must be made for successful delivery.&#8221; Class 4 is one where &#8220;persistence of some temporary condition has caused abandonment or delay\u2026 sending in the future may be successful.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Subject class <strong>7<\/strong> is the one that matters here. The IANA registry describes it as <em>Security or Policy Status<\/em>:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>&#8220;The security or policy status codes report failures involving policies such as per-recipient or per-host filtering and cryptographic operations. Security and policy status issues are assumed to be under the control of either or both the sender and recipient.&#8221;<\/em><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">That last clause is the useful part. A 5.7.x is not a machine failure. Someone \u2014 the receiving admin, the filtering vendor, or you, via your own DMARC policy \u2014 configured a rule, and your message met it.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>3. The free text.<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This is the part you should read first. The enhanced status code space is small and heavily overloaded; the free text is where the receiver tells you what actually happened, which IP was involved, and where to go. Two servers returning <code>550 5.7.1<\/code> can mean completely unrelated things. Two servers returning &#8220;Client host [x.x.x.x] blocked using Blocklist 1&#8221; mean exactly one thing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One structural warning before the table. The IANA registry registers codes in the class-agnostic form <code>X.7.n<\/code>, where <code>X<\/code> stands for the class digit 2, 4 or 5. That does not mean you may pick freely: each registry entry carries an &#8220;Associated basic status code&#8221; column that constrains which classes are valid for that code, and most X.7.x entries admit only 5xx. Providers are free to use the numeric detail space above 30 however they like, and they do. Gmail and Microsoft have both minted codes that collide with registered meanings. Those collisions are flagged below, because writing a filter rule against the number alone will burn you.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_57x_family_decoded\"><\/span>The 5.7.x family decoded<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Codes 5.7.0 through 5.7.30 are the IANA-registered range, sourced from the <a href=\"https:\/\/www.iana.org\/assignments\/smtp-enhanced-status-codes\/smtp-enhanced-status-codes.xhtml\" rel=\"nofollow\">SMTP Enhanced Status Codes Registry<\/a>. Anything numbered above that is vendor-specific. Google&#8217;s emitted strings are quoted from <a href=\"https:\/\/knowledge.workspace.google.com\/admin\/support\/troubleshooting\/gmail-smtp-errors-and-codes\" rel=\"nofollow\">Google&#8217;s Gmail SMTP errors and codes reference<\/a>.<\/p>\n\n\n\n<!--\n  5.7.x family decoded table (SMTP 5.7.x post)\n  Paste into a WordPress \"Custom HTML\" block. All styles inline; no theme CSS needed.\n  Fixed layout, no horizontal scroll. Code in monospace navy chip.\n  Group rows separate IANA-registered (5.7.0-5.7.30) from vendor-specific ranges.\n-->\n<div style=\"border:1px solid #EAECEF;border-radius:8px;overflow:hidden;margin:24px 0;\">\n  <table style=\"width:100%;border-collapse:collapse;table-layout:fixed;font-family:inherit;\">\n    <colgroup>\n      <col style=\"width:10%;\"><col style=\"width:30%;\"><col style=\"width:30%;\"><col style=\"width:30%;\">\n    <\/colgroup>\n    <thead>\n      <tr>\n        <th style=\"background:#1F3A5C;color:#fff;text-align:left;font-weight:700;font-size:13px;padding:12px 12px;font-family:inherit;\">Code<\/th>\n        <th style=\"background:#1F3A5C;color:#fff;text-align:left;font-weight:700;font-size:13px;padding:12px 12px;font-family:inherit;\">Registered \/ documented meaning<\/th>\n        <th style=\"background:#1F3A5C;color:#fff;text-align:left;font-weight:700;font-size:13px;padding:12px 12px;font-family:inherit;\">Likely cause<\/th>\n        <th style=\"background:#1F3A5C;color:#fff;text-align:left;font-weight:700;font-size:13px;padding:12px 12px;font-family:inherit;\">Fix<\/th>\n      <\/tr>\n    <\/thead>\n    <tbody>\n      <tr><td colspan=\"4\" style=\"background:#EAF0F7;color:#1F3A5C;font-weight:700;font-size:12px;letter-spacing:.5px;text-transform:uppercase;padding:9px 12px;border-bottom:1px solid #EAECEF;font-family:inherit;\">IANA-registered range (5.7.0 \u2013 5.7.30)<\/td><\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#1F3A5C;\">5.7.0<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Other\/undefined security status (RFC 3463). Used when the condition can&#8217;t be expressed by another detail code, or can&#8217;t be described for security reasons.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Catch-all. Many gateway blocks land here \u2014 but not all (Proofpoint&#8217;s own is 550 5.7.1), so check the free text. Gmail also uses it for content (552 5.7.0) and STARTTLS\/auth (530 5.7.0).<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Read the free text \u2014 it&#8217;s the only signal. Identify the filtering vendor from the MX hostname and follow their process.<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#1F3A5C;\">5.7.1<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Delivery not authorized, message refused (RFC 3463). Result of per-host or per-recipient filtering.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">The most overloaded code in email: IP blocklisting, relay denial, unauthenticated submission, distribution-list rules, transport rules, reputation refusal.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\"><strong style=\"color:#C0392B;\">Never diagnose 5.7.1 from the number.<\/strong> Group bounces by the free-text string first, then treat each as its own incident.<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#1F3A5C;\">5.7.2<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Mailing list expansion prohibited (RFC 3463). Permanent only.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">You sent to a list address you&#8217;re not an authorized poster for.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Get the sending address added to the list&#8217;s allowed-senders. Recipient-side config.<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#1F3A5C;\">5.7.3<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Security conversion required but not possible (RFC 3463).<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">A conversion between secure messaging protocols was needed and unavailable.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Rare in bulk sending. Usually an S\/MIME or gateway encryption mismatch.<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#1F3A5C;\">5.7.4<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Security features not supported (RFC 3463). Reply code 504.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">The message required a security feature the delivery path couldn&#8217;t support.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Remove the unsupported requirement, or route via a path that supports it.<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#1F3A5C;\">5.7.5<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Cryptographic failure (RFC 3463). Validation\/decryption failed \u2014 key material missing or invalid.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Key exchange or certificate problem.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Verify certificates and key distribution with the receiving party.<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#1F3A5C;\">5.7.6<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Cryptographic algorithm not supported (RFC 3463).<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Algorithm mismatch between sender and receiver.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Negotiate a mutually supported algorithm.<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#1F3A5C;\">5.7.7<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Message integrity failure (RFC 3463). The message was corrupted or altered.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">In-transit modification, often an intermediary rewriting content.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Check for gateways or forwarders altering the message body.<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#1F3A5C;\">5.7.8<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Authentication credentials invalid (RFC 4954). Response to AUTH.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Wrong SMTP username or password on your relay.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Reset the SMTP credentials. Common after a password rotation nobody told the mail server about.<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#1F3A5C;\">5.7.9<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Authentication mechanism too weak (RFC 4954).<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">You offered a mechanism weaker than server policy allows.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Retry with a stronger SASL mechanism.<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#1F3A5C;\">5.7.10<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Encryption needed (RFC 5248). External privacy layer required for the auth mechanism.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Cleartext auth attempted without TLS.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Enable STARTTLS before authenticating.<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#1F3A5C;\">5.7.11<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Encryption required for requested auth mechanism (RFC 4954). Historical.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Same class of problem as 5.7.10.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Establish TLS first.<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#1F3A5C;\">5.7.12<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">A password transition is needed (RFC 4954). Usually seen as 4.7.12 (reply 422\/432).<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Account requires a one-time auth via a different mechanism.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Authenticate once with PLAIN over TLS, then retry.<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#1F3A5C;\">5.7.13<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">User account disabled (RFC 5248). Microsoft also documents 5.7.13 (or 135) for a public folder rejecting external senders.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Sending account suspended, or a recipient public folder set to reject outside mail.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Your account: contact your provider (likely suspended). Public folder: only the recipient&#8217;s admin can change it.<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#1F3A5C;\">5.7.14<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Trust relationship required (RFC 5248).<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Missing federation or connector trust.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Configure the trust relationship on the submission server.<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#1F3A5C;\">5.7.15<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Priority level is too low (RFC 6710). Registry permits 4xx and 5xx.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Receiver accepting only higher-priority messages, often under load.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Often temporary \u2014 retry later, or raise MT-PRIORITY if you legitimately can.<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#1F3A5C;\">5.7.16<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Message too big for the specified priority (RFC 6710).<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Size limit applied at your priority tier.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Reduce message size or send at higher priority.<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#C0392B;\">5.7.17<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Mailbox owner has changed (RFC 7293). 5xx only.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">RRVS check: the mailbox hasn&#8217;t been continuously owned since your stated date. Classic reassigned-corporate-address case.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\"><strong style=\"color:#C0392B;\">Suppress the address.<\/strong> Strong signal the contact left the organization.<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#C0392B;\">5.7.18<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Domain owner has changed (RFC 7293). 5xx only.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">The recipient domain itself changed hands.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\"><strong style=\"color:#C0392B;\">Suppress the whole domain<\/strong> and re-verify.<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#1F3A5C;\">5.7.19<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">RRVS test cannot be completed (RFC 7293). The required timestamp wasn&#8217;t recorded.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Receiver can&#8217;t evaluate your RRVS assertion.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Reissue without RRVS protection if the risk is acceptable.<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#B7791F;\">5.7.20<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">No passing DKIM signature found (RFC 7372).<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">The message carried no valid DKIM signature and the receiver requires one.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Publish the DKIM public key and confirm your signer is actually signing outbound mail.<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#B7791F;\">5.7.21<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">No acceptable DKIM signature found (RFC 7372).<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">DKIM passed but no signature met the receiver&#8217;s policy (key length, algorithm, signing domain).<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Move off sha1, use a 2048-bit key, and sign with a domain the receiver accepts.<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#B7791F;\">5.7.22<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">No valid author-matched DKIM signature found (RFC 7372). Special case of 5.7.21.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">DKIM passes but the d= domain doesn&#8217;t match the From address \u2014 a DKIM alignment failure.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Sign with a domain that aligns with the From: header \u2014 what DMARC alignment requires.<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#B7791F;\">5.7.23<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">SPF validation failed (RFC 7372). Used in place of 5.7.1 per RFC 7208 \u00a78.4. Microsoft: an issue affects your SPF config.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Your sending IP isn&#8217;t authorized by the SPF record of the MAIL FROM (return-path) domain \u2014 not necessarily the From domain.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Add the platform&#8217;s include: to the return-path domain&#8217;s SPF. Stay under the 10-lookup limit; exceeding it is permerror, which many treat as fail.<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#B7791F;\">5.7.24<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">SPF validation error (RFC 7372). The only 5.7.20\u201326 code whose registry entry also lists a 4xx.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">SPF evaluation errored (syntax, permerror, DNS failure). Gmail also returns 550 5.7.24 for &#8220;suspicious entries&#8221; in an SPF record.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Validate SPF syntax. Look for multiple SPF TXT records (instant permerror) and stray +all.<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#B7791F;\">5.7.25<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Reverse DNS validation failed (RFC 7372). Gmail: no PTR, or forward DNS doesn&#8217;t reference the sending IP. Enforced hardest on IPv6.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Missing PTR, or PTR that doesn&#8217;t resolve forward to the same IP.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Set a PTR, confirm forward-confirmed reverse DNS. If you can&#8217;t get a PTR on IPv6, send over IPv4.<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#B7791F;\">5.7.26<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Multiple authentication checks failed (RFC 7372). Gmail uses it for its baseline auth requirement. <strong style=\"color:#C0392B;\">Not a Microsoft code.<\/strong><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Gmail returns 3 strings: sender unauthenticated (needs SPF or DKIM); MAIL FROM has -all and failed SPF; or unauthenticated mail rejected by the domain&#8217;s DMARC policy.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Read which string you got. DMARC string means <strong>your own policy<\/strong> rejected it \u2014 fix alignment, don&#8217;t weaken the policy.<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#B7791F;\">5.7.27<\/code> <span style=\"display:inline-block;font-size:10px;font-weight:700;color:#fff;background:#C0392B;border-radius:3px;padding:1px 4px;\">Gmail collision<\/span><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">IANA: sender address has null MX (RFC 7505). Gmail overloads it: &#8220;blocked because it didn&#8217;t pass SPF authentication.&#8221; (Google&#8217;s rationale is doc prose, not the response \u2014 don&#8217;t match on it.)<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Either your return-path domain publishes MX 0 . , or you&#8217;re a Gmail bulk sender failing SPF.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Check the free text. Null MX: use a return-path that can receive mail. Gmail variant: fix SPF on the return-path domain.<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#C0392B;\">5.7.28<\/code><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Mail flood detected (registered from an expired Internet-Draft, not an RFC). Gmail: &#8220;unusual rate of unsolicited email from your IP.&#8221;<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Rate and reputation. Too much, too fast, from an IP the receiver doesn&#8217;t trust.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\"><strong style=\"color:#C0392B;\">Throttle immediately.<\/strong> Cut volume, mail only engaged recipients, rebuild over days. Retrying at full rate hardens the block.<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#B7791F;\">5.7.29<\/code> <span style=\"display:inline-block;font-size:10px;font-weight:700;color:#fff;background:#C0392B;border-radius:3px;padding:1px 4px;\">Gmail collision<\/span><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">IANA: ARC validation failure (RFC 8617). Gmail overloads it: &#8220;blocked because it wasn&#8217;t sent over a TLS connection.&#8221;<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Either a broken ARC chain (a forwarder\/list server), or opportunistic TLS not used at all.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">TLS variant: enable STARTTLS on outbound. Genuine ARC failure: the problem is at the forwarding hop, not yours.<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#B7791F;\">5.7.30<\/code> <span style=\"display:inline-block;font-size:10px;font-weight:700;color:#fff;background:#C0392B;border-radius:3px;padding:1px 4px;\">Gmail collision<\/span><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">IANA: REQUIRETLS support required (RFC 8689). Gmail overloads it: &#8220;blocked because it didn&#8217;t pass DKIM authentication.&#8221;<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Almost always the Gmail DKIM variant in practice.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Publish a DKIM record and verify the signature validates on a live message, not just a test send.<\/td>\n      <\/tr>\n      <tr><td colspan=\"4\" style=\"background:#EAF0F7;color:#1F3A5C;font-weight:700;font-size:12px;letter-spacing:.5px;text-transform:uppercase;padding:9px 12px;border-bottom:1px solid #EAECEF;font-family:inherit;\">Vendor-specific (above 5.7.30 \u2014 no cross-provider meaning)<\/td><\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#1F3A5C;\">5.7.32<\/code> <span style=\"display:inline-block;font-size:10px;font-weight:700;color:#fff;background:#6B7280;border-radius:3px;padding:1px 4px;\">Gmail<\/span><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Gmail: From header isn&#8217;t aligned with the authenticated SPF or DKIM organizational domain. (Google&#8217;s docs show a 421 prefix \u2014 treat the alignment meaning as authoritative, not the class.)<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">DMARC alignment failure specifically, distinct from authentication failure.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Align the return-path (SPF) or DKIM d= domain with your From domain. A subdomain of the same org domain satisfies relaxed alignment.<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#1F3A5C;\">5.7.40<\/code> <span style=\"display:inline-block;font-size:10px;font-weight:700;color:#fff;background:#6B7280;border-radius:3px;padding:1px 4px;\">Gmail<\/span><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Gmail: the sending domain has no DMARC record, or the record specifies no policy. (Also used as 504 5.7.40 for &#8220;unrecognized authentication type.&#8221;)<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">No DMARC record, or malformed with no p= tag.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Publish _dmarc.yourdomain.com with at least v=DMARC1; p=none; rua=mailto:\u2026 , then tighten once reports are clean.<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#1F3A5C;\">5.7.57<\/code> <span style=\"display:inline-block;font-size:10px;font-weight:700;color:#fff;background:#6B7280;border-radius:3px;padding:1px 4px;\">Microsoft<\/span><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Microsoft: client wasn&#8217;t authenticated to send anonymous mail during MAIL FROM.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">An app\/device relaying through smtp.office365.com without authenticating.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Fix the app&#8217;s SMTP auth config, or use a connector instead of client submission.<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#1F3A5C;\">5.7.64<\/code> <span style=\"display:inline-block;font-size:10px;font-weight:700;color:#fff;background:#6B7280;border-radius:3px;padding:1px 4px;\">Microsoft<\/span><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Microsoft: TenantAttribution; Relay Access Denied.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">A hybrid inbound connector no longer matches the on-premises environment.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Re-check the inbound connector&#8217;s certificate or IP config against what your on-prem servers present.<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#C0392B;\">5.7.509<\/code> <span style=\"display:inline-block;font-size:10px;font-weight:700;color:#fff;background:#6B7280;border-radius:3px;padding:1px 4px;\">Microsoft<\/span><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Microsoft: sending domain doesn&#8217;t pass DMARC and has a policy of reject. Evaluated against the 5322.From address.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Your own DMARC p=reject enforced against you, because neither SPF nor DKIM aligned.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\"><strong style=\"color:#C0392B;\">Fix alignment.<\/strong> Most often catches a third-party tool nobody remembered was sending as your domain.<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#C0392B;\">5.7.511<\/code> <span style=\"display:inline-block;font-size:10px;font-weight:700;color:#fff;background:#6B7280;border-radius:3px;padding:1px 4px;\">Microsoft<\/span><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Microsoft: &#8220;Access denied, banned sender.&#8221; Not self-service delistable.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Serious reputation event on the sending IP.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Email the full NDR (code + IP) to delist@microsoft.com; Microsoft responds within 48h. The self-service portal won&#8217;t work for this code.<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:11px 12px;vertical-align:top;border-bottom:1px solid #EAECEF;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#C0392B;\">5.7.515<\/code> <span style=\"display:inline-block;font-size:10px;font-weight:700;color:#fff;background:#6B7280;border-radius:3px;padding:1px 4px;\">Microsoft<\/span><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Microsoft consumer (Outlook.com): sending domain doesn&#8217;t meet the required authentication level. Applies at 5,000+ messages to consumer services from one From domain.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Microsoft&#8217;s bulk sender requirement: SPF and DKIM passing plus a valid aligned DMARC policy.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;overflow-wrap:anywhere;\">Full SPF, DKIM, and DMARC alignment \u2014 not one of the three. Enforced (reject from day one) since 29 April 2025.<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:11px 12px;vertical-align:top;font-family:inherit;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:12px;font-weight:700;color:#C0392B;\">5.7.606\u2013649<\/code> <span style=\"display:inline-block;font-size:10px;font-weight:700;color:#fff;background:#6B7280;border-radius:3px;padding:1px 4px;\">Microsoft<\/span><\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;font-family:inherit;overflow-wrap:anywhere;\">Microsoft (collective range): &#8220;Access denied, banned sending IP.&#8221; The specific number carries no distinct published meaning.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;font-family:inherit;overflow-wrap:anywhere;\">Your sending IP is on Microsoft&#8217;s blocked senders list.<\/td>\n        <td style=\"padding:11px 12px;vertical-align:top;font-size:12.5px;line-height:1.5;color:#24262B;font-family:inherit;overflow-wrap:anywhere;\">Fix the behavior first, then use the delist portal at sender.office.com (one email + one IP per submission). Results &#8220;up to 24 hours or longer.&#8221;<\/td>\n      <\/tr>\n    <\/tbody>\n  <\/table>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Two things worth pinning to memory. First, the <strong>IANA registry ends at X.7.30<\/strong> \u2014 every code numbered above that is a vendor invention with no cross-provider meaning. Second, Gmail&#8217;s 5.7.27, 5.7.29 and 5.7.30 mean something completely different from the registered definitions of those numbers. Any bounce-classification logic that matches on the enhanced status code without also checking the receiving domain will misroute those three.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Worth adding as a footnote to the same point: the overloading is not only across vendors, it happens <em>within<\/em> a single vendor. Google itself uses 5.7.40 both for the missing-DMARC-record string in the table above and, as <code>504 5.7.40<\/code>, for &#8220;Unrecognized authentication type&#8221;. Google likewise attaches more than one meaning to 5.7.26, which is why the table lists three distinct strings for it. Matching on the number alone fails even when you already know the receiving domain is Gmail.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"47x_the_same_family_temporary\"><\/span>4.7.x: the same family, temporary<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Swap the leading 5 for a 4 and you get the same policy category as a <em>persistent transient failure<\/em> \u2014 the receiver is deferring, not refusing. RFC 3463&#8217;s own wording is the point: &#8220;sending in the future may be successful.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These are the most actionable bounces you will ever get, because they arrive before a block:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>421 4.7.0<\/code> \u2014 Gmail returns this when the sending IP has no PTR record or the forward DNS does not point back to the IP. A warning shot for the same condition that becomes <code>550 5.7.25<\/code>.<\/li>\n\n\n\n<li><code>451 4.7.23<\/code> \u2014 SPF failure being deferred rather than rejected.<\/li>\n\n\n\n<li><code>451 4.7.24<\/code> \u2014 SPF evaluation error. Among the RFC 7372 authentication codes (5.7.20\u20135.7.26), 5.7.24 is the only one whose registry entry lists a <em>4xx alongside 550<\/em> \u2014 the other six list 550 alone. Other X.7.x codes outside that block, such as X.7.0, X.7.1 and X.7.15, also admit both classes.<\/li>\n\n\n\n<li><code>421 4.7.26<\/code> \u2014 Gmail: &#8220;This email has been rate limited because it is unauthenticated.&#8221; Set up SPF or DKIM and this disappears before it becomes a rejection.<\/li>\n\n\n\n<li><code>451 4.7.26<\/code> \u2014 DMARC-specific: &#8220;Unauthenticated email from [domain] is not accepted due to domain&#8217;s DMARC policy, but temporary DNS failures prevent authentication.&#8221; The policy decision is DMARC; the reason it is deferred rather than rejected is that authentication could not be evaluated \u2014 often your own DNS provider, not the receiver.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">A rising 4.7.x rate to one destination is the single most reliable early warning in deliverability. It almost always precedes the equivalent 5.7.x. If you monitor one thing, monitor this.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_five_most_common_57x_causes_in_practice\"><\/span>The five most common 5.7.x causes in practice<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">1. Authentication failure<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.mailercloud.com\/blog\/spf-dkim-dmarc-implementation-guide\">SPF, DKIM, DMARC, or alignment between them<\/a>. Produces 5.7.23, 5.7.25, 5.7.26, 5.7.32, 5.7.40, 5.7.509 and 5.7.515. The most common single root cause is a return-path domain whose SPF record does not include the sending platform, combined with DKIM signed by the platform&#8217;s domain rather than yours \u2014 so both mechanisms technically pass but neither <em>aligns<\/em>, and DMARC rejects.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. IP reputation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">5.7.28, 5.7.508, 5.7.511, 5.7.606\u2013649, and a large share of unlabeled 5.7.1s. The receiver has decided your IP behaves badly. Reputation systems react to volume anomalies, complaint rates, and traps \u2014 and they react faster than they recover.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. Blocklist listing<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Distinguishable from general reputation by the free text naming a list: &#8220;blocked using Blocklist 1&#8221;, &#8220;blocked using Proofpoint&#8221;, <a href=\"https:\/\/www.mailercloud.com\/blog\/spamhaus-sbl-css-delisting\">a Spamhaus URL<\/a>, or a customer block list reference. Usually 5.7.1 or 5.7.0. The named list tells you exactly which delisting process applies, which is why the free text matters more than the number.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">4. Content and message-format policy<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">5.7.0 with a security-issue string, 5.7.512, and Gmail&#8217;s substantial family of RFC 5322 compliance rejections under 5.7.1 \u2014 missing Message-ID, duplicate headers, multiple From addresses, malformed headers, encoded-word syntax where it is not permitted. These are cheap to fix and frequently overlooked because senders assume 5.7.1 always means reputation.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">5. Recipient-side rules<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">5.7.2, 5.7.13 (public folder variant), 5.7.513, and the distribution-list and transport-rule variants of 5.7.1. Nothing is wrong with your infrastructure. One organization configured a rule. No amount of authentication or reputation work will change it \u2014 only the recipient&#8217;s admin can.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_diagnose_from_your_bounce_logs\"><\/span>How to diagnose from your bounce logs<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Do not read individual bounces. Aggregate them, and the pattern names the cause.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Group by recipient domain first. <\/strong>When 5.7.x bounces cluster in one domain, it&#8217;s a recipient-side rule or that organization&#8217;s block list \u2014 cause 5. Bounces spread across every Microsoft-hosted domain but nowhere else point to Microsoft reputation. And if they appear at Gmail, Microsoft, Yahoo and elsewhere simultaneously, the problem is yours: authentication or IP reputation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Then group by the free text string, not the code.<\/strong> A thousand 5.7.1 bounces will resolve into three or four distinct strings, each a separate incident with a separate fix. Treating them as one problem is the most common diagnostic error in this family.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Then group by sending IP.<\/strong> If only one IP in your pool is affected, you have an IP reputation problem. If all of them are, you have a domain or content problem.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Sudden onset versus gradual.<\/strong> A 5.7.x rate that goes from near zero to significant within a single send points at a configuration change \u2014 a rotated DKIM key, an edited SPF record, a DMARC policy tightened from <code>p=none<\/code> to <code>p=reject<\/code>, a new sending IP, a new third-party tool. Check what changed in DNS in the last 72 hours before anything else. A rate that climbs over days or weeks, usually preceded by rising 4.7.x deferrals, is reputation decay: list quality, complaint rate, or volume growth.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Check whether the code is temporary.<\/strong> Separate 4.7.x from 5.7.x in the same report. The 4.7.x line is where you still have time.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Fixing_each_cause_the_order_that_works\"><\/span>Fixing each cause: the order that works<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Order matters more than technique here. Most senders start at step 4, and it backfires.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Stop the failing traffic to the affected destination.<\/strong> Retrying through a policy block is itself a negative signal, and many reputation listings expire on their own once the triggering traffic stops. Retrying resets that clock.<\/li>\n\n\n\n<li><strong>Fix authentication.<\/strong> This is first among the real fixes because it is deterministic, fast, and verifiable. Confirm SPF passes for the return-path domain, DKIM validates on a live message, and at least one of them aligns with your From domain. Check the SPF 10-lookup limit. Check for a duplicate SPF TXT record. Authentication problems are the only 5.7.x cause you can fully verify from your side before sending again.<\/li>\n\n\n\n<li><strong>Fix list and content behavior.<\/strong> Suppress non-engaged contacts, remove any purchased data, verify addresses that have not engaged in months, and clean up header and format problems. This is the step that determines whether a delisting request works.<\/li>\n\n\n\n<li><strong>Request delisting \u2014 last, and only after steps 1\u20133.<\/strong> Every major provider evaluates whether your behavior changed. A request submitted while the bad traffic is still flowing gets ignored, and repeated ignored requests damage your credibility for future ones. For a 5.7.606\u2013649 use <a href=\"https:\/\/sender.office.com\" rel=\"nofollow\">sender.office.com<\/a>. For 5.7.511, that portal will not work \u2014 email <code>delist@microsoft.com<\/code> with the full NDR.<\/li>\n\n\n\n<li><strong>Re-warm.<\/strong> After delisting, return at a fraction of previous volume to your most engaged recipients only, and increase gradually while 4.7.x rates stay flat. Returning to full volume immediately reproduces the original signal.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Prevention\"><\/span>Prevention<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Meet the bulk sender requirements before you need to.<\/strong> Google requires SPF and DKIM, DMARC on the sending domain, valid forward and reverse DNS, TLS, From alignment with SPF or DKIM, and one-click unsubscribe for marketing mail at <a href=\"https:\/\/support.google.com\/mail\/answer\/81126\" rel=\"nofollow\">5,000+ messages a day to Gmail<\/a>; we cover <a href=\"https:\/\/www.mailercloud.com\/blog\/gmail-yahoo-sender-requirements\">Gmail&#8217;s bulk sender requirements<\/a> in full. Microsoft applies <a href=\"https:\/\/www.mailercloud.com\/blog\/microsoft-outlook-sender-requirements\">its own version at 5,000+ messages to consumer services, enforced via 5.7.515<\/a>.<\/li>\n\n\n\n<li><strong>Watch the complaint rate.<\/strong> Google publishes two figures at two different tiers, and conflating them is a common error. The <strong>0.30%<\/strong> figure is the hard requirement in Google&#8217;s bulk sender list \u2014 &#8220;avoid ever reaching a spam rate of 0.30% or higher.&#8221; The <strong>0.10%<\/strong> figure is best-practice guidance for the spam rate reported in Postmaster Tools, not an enforcement threshold. Treat 0.30% as the line you must not cross and 0.10% as the target you should operate below.<\/li>\n\n\n\n<li><strong>Alert on 4.7.x, not just 5.7.x.<\/strong> Set a threshold on deferral rate per destination domain. This is your only reliable pre-block warning.<\/li>\n\n\n\n<li><strong>Monitor authentication continuously.<\/strong> Enable DMARC aggregate reporting with a <code>rua=<\/code> address and actually read it. It will show you unauthenticated sources sending as your domain long before a receiver rejects them.<\/li>\n\n\n\n<li><strong>Set PTR records on every sending IP<\/strong>, and confirm forward-confirmed reverse DNS resolves back. Non-negotiable on IPv6.<\/li>\n\n\n\n<li><strong>Use the postmaster tools you have.<\/strong> Google&#8217;s Postmaster Tools at <a href=\"https:\/\/postmaster.google.com\" rel=\"nofollow\">postmaster.google.com<\/a> and Microsoft SNDS at <a href=\"https:\/\/aka.ms\/snds\" rel=\"nofollow\">aka.ms\/snds<\/a>. Note that SNDS has moved \u2014 the older <code>sendersupport.olc.protection.outlook.com\/snds\/<\/code> URLs are being deprecated, so use the <code>aka.ms<\/code> short link.<\/li>\n\n\n\n<li><strong>Change one thing at a time in DNS.<\/strong> Most sudden-onset 5.7.x incidents trace to a DNS edit made days earlier by someone who did not connect the two.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Shared_IP_vs_dedicated_IP_who_fixes_what\"><\/span>Shared IP vs dedicated IP: who fixes what<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The split falls cleanly along the causes above.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Authentication codes are always yours<\/strong> \u2014 5.7.23, 5.7.25, 5.7.26, 5.7.32, 5.7.40, 5.7.509, 5.7.515. They are evaluated against your domain and your DNS. No IP arrangement changes that, and no provider can fix them on your behalf. On shared infrastructure your platform may host the DKIM key, but the DNS records live on your domain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>IP reputation codes depend on the arrangement<\/strong> \u2014 5.7.28, 5.7.508, 5.7.511, 5.7.606\u2013649. On a <strong>shared pool<\/strong>, the platform owns the IP reputation and the delisting relationship; your obligation is list quality, because one sender&#8217;s bad list degrades the pool for everyone. On a <strong>dedicated IP<\/strong>, the reputation is entirely yours: you benefit fully from clean sending and absorb the whole cost of a mistake. The delisting request is still usually submitted by whoever controls the IP, but the behavioral fix is yours either way.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Recipient-side rules are neither.<\/strong> 5.7.2, 5.7.513 and the transport-rule 5.7.1s can only be resolved by the receiving organization.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_Mailercloud_handles_bounce_diagnostics\"><\/span>How Mailercloud handles bounce diagnostics<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">At Mailercloud we deliver over a billion emails a month, so we see the whole 5.7.x range daily. Bounces are classified by provider and by the free text string rather than the code alone, which keeps overloaded codes like Gmail&#8217;s 5.7.27 and 5.7.30 from being misfiled. Deferral rates are tracked per destination domain so 4.7.x patterns surface before they become blocks, authentication is validated at setup, and our deliverability team handles delisting and re-warming on shared pools.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you are looking at a 5.7.x bounce right now and cannot work out which cause it is, <a href=\"https:\/\/www.mailercloud.com\/contact\">talk to our deliverability team<\/a> \u2014 or <a href=\"https:\/\/app.mailercloud.com\/register\">start free with Mailercloud<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"FAQ_SMTP_57x_errors\"><\/span>FAQ: SMTP 5.7.x errors<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">What does a 5.7.1 SMTP error actually mean?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Formally, &#8220;delivery not authorized, message refused&#8221; \u2014 the receiver applied a per-host or per-recipient filter and declined. In practice 5.7.1 is the most overloaded code in email, covering IP blocklisting, relay denial, unauthenticated submission, distribution-list restrictions, transport rules and RFC 5322 format problems. The number alone is not diagnostic; the free text after it is.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Is a 5.7.x bounce permanent?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The 5 means permanent for that message as sent \u2014 resending it unchanged will fail again. It does not mean permanent for the address. Once you fix the underlying policy problem, most 5.7.x conditions clear. The exception is 5.7.17 and 5.7.18, where the mailbox or domain has changed owner; suppress those addresses.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Why do 5.7.26 and 5.7.509 both seem to be about DMARC?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">They are different checks by different providers. Gmail&#8217;s 5.7.26 covers its baseline requirement that every sender authenticate with SPF or DKIM, and one of its three variants also fires on a recipient-domain DMARC policy. Microsoft&#8217;s 5.7.509 fires specifically when the 5322.From domain fails DMARC and publishes <code>p=reject<\/code>. In both cases the fix is alignment, not a weaker policy.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Why does the same code mean different things at Gmail and elsewhere?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The IANA registry only defines codes up to X.7.30, and providers extend the space independently. Gmail assigned 5.7.27, 5.7.29 and 5.7.30 to bulk-sender SPF, TLS and DKIM requirements, while those numbers are registered for null MX, ARC validation and REQUIRETLS respectively. Always interpret a code together with the receiving domain.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Should I request delisting straight away?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No. Every major provider checks whether your behavior changed before granting a delisting. Stop the failing traffic, fix authentication, clean the list, and only then submit \u2014 one request, honestly describing what you fixed. Requests submitted while the problem is ongoing get ignored, and repeated ignored requests reduce your chances next time.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What does SMTP error 5.7.26 mean?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">It means the message failed authentication \u2014 Gmail returns 5.7.26 when a sender doesn&#8217;t authenticate with SPF or DKIM (and one variant fires on the recipient domain&#8217;s DMARC policy). It&#8217;s a Gmail code, not a Microsoft one. The fix is to get SPF or DKIM passing and aligned to your From domain \u2014 not to weaken any policy.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How do I fix a 5.7.509 or 5.7.515 bounce?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Both are authentication failures against your own domain. 5.7.509 means Microsoft enforced your published DMARC p=reject because neither SPF nor DKIM aligned \u2014 fix the alignment. 5.7.515 is Microsoft&#8217;s bulk-sender rule (5,000+\/day to consumer inboxes) and needs SPF, DKIM, and an aligned DMARC policy all in place. Neither is solved by retrying; fix the DNS, then resend.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A complete reference for 5.7.x policy rejections. What a 5.7.1 SMTP error, 5.7.26, 5.7.509 and 5.7.606-649 actually mean, and how to fix each one.<\/p>\n","protected":false},"author":19,"featured_media":5342,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[28],"tags":[48,45,53,50,47,66],"class_list":["post-5213","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-email-delivery","tag-bounce-codes","tag-deliverability","tag-dmarc","tag-email-authentication","tag-sender-reputation","tag-smtp"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>SMTP 5.7.x Bounce Codes Decoded: 5.7.1 &amp; the Policy Family<\/title>\n<meta name=\"description\" content=\"SMTP 5.7.x Errors Explained: Every Code &amp; How to Fix It (55) \u00b7 5.7.1 &amp; the SMTP 5.7.x Family: Bounce Codes Decoded (2026)\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SMTP 5.7.x Bounce Codes Decoded: 5.7.1 &amp; the Policy Family\" \/>\n<meta property=\"og:description\" content=\"SMTP 5.7.x Errors Explained: Every Code &amp; How to Fix It (55) \u00b7 5.7.1 &amp; the SMTP 5.7.x Family: Bounce Codes Decoded (2026)\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes\" \/>\n<meta property=\"og:site_name\" content=\"Mailercloud Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/mailercloud\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/cherikkapoyil.amar\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-11T05:23:46+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-08T04:42:48+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.mailercloud.com\/blog\/wp-content\/uploads\/2026\/07\/SMTP-5.7.x-Bounce-Codes-Decoded_-5.7.1-and-the-Policy-Family.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"760\" \/>\n\t<meta property=\"og:image:height\" content=\"380\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Amar\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@mailercloud\" \/>\n<meta name=\"twitter:site\" content=\"@mailercloud\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Amar\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"19 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/smtp-5-7-x-bounce-codes#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/smtp-5-7-x-bounce-codes\"},\"author\":{\"name\":\"Amar\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/#\\\/schema\\\/person\\\/0f3151b32a261b5f5df0a7968fa64945\"},\"headline\":\"SMTP 5.7.x Bounce Codes Decoded: 5.7.1 and the Policy Family\",\"datePublished\":\"2026-08-11T05:23:46+00:00\",\"dateModified\":\"2026-09-08T04:42:48+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/smtp-5-7-x-bounce-codes\"},\"wordCount\":4198,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/smtp-5-7-x-bounce-codes#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/SMTP-5.7.x-Bounce-Codes-Decoded_-5.7.1-and-the-Policy-Family.jpg\",\"keywords\":[\"bounce codes\",\"deliverability\",\"DMARC\",\"email authentication\",\"sender reputation\",\"smtp\"],\"articleSection\":[\"Email Delivery\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/smtp-5-7-x-bounce-codes#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/smtp-5-7-x-bounce-codes\",\"url\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/smtp-5-7-x-bounce-codes\",\"name\":\"SMTP 5.7.x Bounce Codes Decoded: 5.7.1 & the Policy Family\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/smtp-5-7-x-bounce-codes#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/smtp-5-7-x-bounce-codes#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/SMTP-5.7.x-Bounce-Codes-Decoded_-5.7.1-and-the-Policy-Family.jpg\",\"datePublished\":\"2026-08-11T05:23:46+00:00\",\"dateModified\":\"2026-09-08T04:42:48+00:00\",\"description\":\"SMTP 5.7.x Errors Explained: Every Code & How to Fix It (55) \u00b7 5.7.1 & the SMTP 5.7.x Family: Bounce Codes Decoded (2026)\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/smtp-5-7-x-bounce-codes#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/smtp-5-7-x-bounce-codes\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/smtp-5-7-x-bounce-codes#primaryimage\",\"url\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/SMTP-5.7.x-Bounce-Codes-Decoded_-5.7.1-and-the-Policy-Family.jpg\",\"contentUrl\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/SMTP-5.7.x-Bounce-Codes-Decoded_-5.7.1-and-the-Policy-Family.jpg\",\"width\":760,\"height\":380,\"caption\":\"SMTP 5.7.x Bounce Codes Decoded: 5.7.1 and the Policy Family\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/smtp-5-7-x-bounce-codes#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"SMTP 5.7.x Bounce Codes Decoded: 5.7.1 and the Policy Family\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/\",\"name\":\"Mailercloud Blog\",\"description\":\"Create And Implement Email Marketing Campaigns\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/#organization\",\"name\":\"Mailercloud Blog\",\"url\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/footer_logo.png\",\"contentUrl\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/footer_logo.png\",\"width\":141,\"height\":30,\"caption\":\"Mailercloud Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/mailercloud\",\"https:\\\/\\\/x.com\\\/mailercloud\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/mailercloud\\\/\",\"https:\\\/\\\/www.instagram.com\\\/mailercloud\\\/\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCslSwv-TECN8rLvFM8wRlog\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/#\\\/schema\\\/person\\\/0f3151b32a261b5f5df0a7968fa64945\",\"name\":\"Amar\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/04\\\/1547012193070-150x150.jpeg\",\"url\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/04\\\/1547012193070-150x150.jpeg\",\"contentUrl\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/04\\\/1547012193070-150x150.jpeg\",\"caption\":\"Amar\"},\"description\":\"Amar CP is the Co-Founder and Sales Director at Mailercloud, where he leads partnerships, alliances, and customer growth. With over a decade of experience in application development, database architecture, and scaling web systems, Amar brings a rare blend of engineering depth and go-to-market expertise to email marketing. He writes about email deliverability, marketing automation, and helping small businesses grow smarter with data-driven campaigns.\",\"sameAs\":[\"http:\\\/\\\/www.mailercloud.com\",\"https:\\\/\\\/www.facebook.com\\\/cherikkapoyil.amar\",\"https:\\\/\\\/www.instagram.com\\\/amar.cp\\\/\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/amarcp\\\/\"],\"url\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/author\\\/amarmailercloud-com\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"SMTP 5.7.x Bounce Codes Decoded: 5.7.1 & the Policy Family","description":"SMTP 5.7.x Errors Explained: Every Code & How to Fix It (55) \u00b7 5.7.1 & the SMTP 5.7.x Family: Bounce Codes Decoded (2026)","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes","og_locale":"en_US","og_type":"article","og_title":"SMTP 5.7.x Bounce Codes Decoded: 5.7.1 & the Policy Family","og_description":"SMTP 5.7.x Errors Explained: Every Code & How to Fix It (55) \u00b7 5.7.1 & the SMTP 5.7.x Family: Bounce Codes Decoded (2026)","og_url":"https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes","og_site_name":"Mailercloud Blog","article_publisher":"https:\/\/www.facebook.com\/mailercloud","article_author":"https:\/\/www.facebook.com\/cherikkapoyil.amar","article_published_time":"2026-08-11T05:23:46+00:00","article_modified_time":"2026-09-08T04:42:48+00:00","og_image":[{"width":760,"height":380,"url":"https:\/\/www.mailercloud.com\/blog\/wp-content\/uploads\/2026\/07\/SMTP-5.7.x-Bounce-Codes-Decoded_-5.7.1-and-the-Policy-Family.jpg","type":"image\/jpeg"}],"author":"Amar","twitter_card":"summary_large_image","twitter_creator":"@mailercloud","twitter_site":"@mailercloud","twitter_misc":{"Written by":"Amar","Est. reading time":"19 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes#article","isPartOf":{"@id":"https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes"},"author":{"name":"Amar","@id":"https:\/\/www.mailercloud.com\/blog\/#\/schema\/person\/0f3151b32a261b5f5df0a7968fa64945"},"headline":"SMTP 5.7.x Bounce Codes Decoded: 5.7.1 and the Policy Family","datePublished":"2026-08-11T05:23:46+00:00","dateModified":"2026-09-08T04:42:48+00:00","mainEntityOfPage":{"@id":"https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes"},"wordCount":4198,"commentCount":0,"publisher":{"@id":"https:\/\/www.mailercloud.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes#primaryimage"},"thumbnailUrl":"https:\/\/www.mailercloud.com\/blog\/wp-content\/uploads\/2026\/07\/SMTP-5.7.x-Bounce-Codes-Decoded_-5.7.1-and-the-Policy-Family.jpg","keywords":["bounce codes","deliverability","DMARC","email authentication","sender reputation","smtp"],"articleSection":["Email Delivery"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes","url":"https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes","name":"SMTP 5.7.x Bounce Codes Decoded: 5.7.1 & the Policy Family","isPartOf":{"@id":"https:\/\/www.mailercloud.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes#primaryimage"},"image":{"@id":"https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes#primaryimage"},"thumbnailUrl":"https:\/\/www.mailercloud.com\/blog\/wp-content\/uploads\/2026\/07\/SMTP-5.7.x-Bounce-Codes-Decoded_-5.7.1-and-the-Policy-Family.jpg","datePublished":"2026-08-11T05:23:46+00:00","dateModified":"2026-09-08T04:42:48+00:00","description":"SMTP 5.7.x Errors Explained: Every Code & How to Fix It (55) \u00b7 5.7.1 & the SMTP 5.7.x Family: Bounce Codes Decoded (2026)","breadcrumb":{"@id":"https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes#primaryimage","url":"https:\/\/www.mailercloud.com\/blog\/wp-content\/uploads\/2026\/07\/SMTP-5.7.x-Bounce-Codes-Decoded_-5.7.1-and-the-Policy-Family.jpg","contentUrl":"https:\/\/www.mailercloud.com\/blog\/wp-content\/uploads\/2026\/07\/SMTP-5.7.x-Bounce-Codes-Decoded_-5.7.1-and-the-Policy-Family.jpg","width":760,"height":380,"caption":"SMTP 5.7.x Bounce Codes Decoded: 5.7.1 and the Policy Family"},{"@type":"BreadcrumbList","@id":"https:\/\/www.mailercloud.com\/blog\/smtp-5-7-x-bounce-codes#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.mailercloud.com\/blog\/"},{"@type":"ListItem","position":2,"name":"SMTP 5.7.x Bounce Codes Decoded: 5.7.1 and the Policy Family"}]},{"@type":"WebSite","@id":"https:\/\/www.mailercloud.com\/blog\/#website","url":"https:\/\/www.mailercloud.com\/blog\/","name":"Mailercloud Blog","description":"Create And Implement Email Marketing Campaigns","publisher":{"@id":"https:\/\/www.mailercloud.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.mailercloud.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.mailercloud.com\/blog\/#organization","name":"Mailercloud Blog","url":"https:\/\/www.mailercloud.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mailercloud.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.mailercloud.com\/blog\/wp-content\/uploads\/2025\/02\/footer_logo.png","contentUrl":"https:\/\/www.mailercloud.com\/blog\/wp-content\/uploads\/2025\/02\/footer_logo.png","width":141,"height":30,"caption":"Mailercloud Blog"},"image":{"@id":"https:\/\/www.mailercloud.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/mailercloud","https:\/\/x.com\/mailercloud","https:\/\/www.linkedin.com\/company\/mailercloud\/","https:\/\/www.instagram.com\/mailercloud\/","https:\/\/www.youtube.com\/channel\/UCslSwv-TECN8rLvFM8wRlog"]},{"@type":"Person","@id":"https:\/\/www.mailercloud.com\/blog\/#\/schema\/person\/0f3151b32a261b5f5df0a7968fa64945","name":"Amar","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mailercloud.com\/blog\/wp-content\/uploads\/2026\/04\/1547012193070-150x150.jpeg","url":"https:\/\/www.mailercloud.com\/blog\/wp-content\/uploads\/2026\/04\/1547012193070-150x150.jpeg","contentUrl":"https:\/\/www.mailercloud.com\/blog\/wp-content\/uploads\/2026\/04\/1547012193070-150x150.jpeg","caption":"Amar"},"description":"Amar CP is the Co-Founder and Sales Director at Mailercloud, where he leads partnerships, alliances, and customer growth. With over a decade of experience in application development, database architecture, and scaling web systems, Amar brings a rare blend of engineering depth and go-to-market expertise to email marketing. He writes about email deliverability, marketing automation, and helping small businesses grow smarter with data-driven campaigns.","sameAs":["http:\/\/www.mailercloud.com","https:\/\/www.facebook.com\/cherikkapoyil.amar","https:\/\/www.instagram.com\/amar.cp\/","https:\/\/www.linkedin.com\/in\/amarcp\/"],"url":"https:\/\/www.mailercloud.com\/blog\/author\/amarmailercloud-com"}]}},"_links":{"self":[{"href":"https:\/\/www.mailercloud.com\/blog\/wp-json\/wp\/v2\/posts\/5213","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.mailercloud.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.mailercloud.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.mailercloud.com\/blog\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mailercloud.com\/blog\/wp-json\/wp\/v2\/comments?post=5213"}],"version-history":[{"count":7,"href":"https:\/\/www.mailercloud.com\/blog\/wp-json\/wp\/v2\/posts\/5213\/revisions"}],"predecessor-version":[{"id":5575,"href":"https:\/\/www.mailercloud.com\/blog\/wp-json\/wp\/v2\/posts\/5213\/revisions\/5575"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.mailercloud.com\/blog\/wp-json\/wp\/v2\/media\/5342"}],"wp:attachment":[{"href":"https:\/\/www.mailercloud.com\/blog\/wp-json\/wp\/v2\/media?parent=5213"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.mailercloud.com\/blog\/wp-json\/wp\/v2\/categories?post=5213"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.mailercloud.com\/blog\/wp-json\/wp\/v2\/tags?post=5213"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}