{"id":5217,"date":"2026-08-06T11:25:36","date_gmt":"2026-08-06T11:25:36","guid":{"rendered":"https:\/\/www.mailercloud.com\/blog\/?p=5217"},"modified":"2026-09-08T04:33:25","modified_gmt":"2026-09-08T04:33:25","slug":"microsoft-sender-requirements","status":"publish","type":"post","link":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements","title":{"rendered":"Microsoft Sender Requirements: The Complete 2026 Reference"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">If you send more than 5,000 messages a day to Outlook.com, Hotmail, Live or MSN addresses from a single From domain, Microsoft requires SPF, DKIM and DMARC to pass. Mail that fails is not junked. It is rejected at the SMTP transaction:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>550 5.7.515 Access denied, sending domain [SendingDomain] does not meet the required authentication level<\/em><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\"><em>(Microsoft&#8217;s announcement blog renders the code as <code>550; 5.7.515<\/code> with a semicolon, while the support article uses <code>550 5.7.515<\/code>. If you grep bounce logs for an exact string, match both.)<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/substrate.office.com\/ip-domain-management-snds\/postmaster\" rel=\"nofollow\">Microsoft&#8217;s postmaster policies page<\/a> still describes the superseded junk-first sequence. Disregard it: the announcement blog was revised on 29 April 2025, and the original junking paragraph survives there only as struck-through text.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That has been the behavior since 5 May 2025. It is also only one of the things Microsoft checks, and it applies to only one of the two Microsoft mail systems you send to. This page is the maintained reference for both.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Last reviewed: 18 July 2026<\/strong><\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_88 counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements\/#The_two_Microsofts\" >The two Microsofts<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements\/#Requirements_at_a_glance\" >Requirements at a glance<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements\/#Authentication_requirements\" >Authentication requirements<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements\/#Volume_thresholds_and_who_counts_as_a_bulk_sender\" >Volume thresholds and who counts as a bulk sender<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements\/#SNDS_and_JMRP_the_tools_Microsoft_gives_you\" >SNDS and JMRP: the tools Microsoft gives you<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements\/#Tenant-side_controls_you_do_not_control\" >Tenant-side controls you do not control<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements\/#Reputation_and_throttling_behavior\" >Reputation and throttling behavior<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements\/#The_sender_support_and_mitigation_path\" >The sender support and mitigation path<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements\/#Compliance_checklist\" >Compliance checklist<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements\/#Changelog_how_Microsofts_requirements_evolved\" >Changelog: how Microsoft&#8217;s requirements evolved<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements\/#How_Mailercloud_handles_Microsoft_delivery\" >How Mailercloud handles Microsoft delivery<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements\/#FAQ_Microsoft_Sender_Requirements\" >FAQ : Microsoft Sender Requirements<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_two_Microsofts\"><\/span>The two Microsofts<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Almost every unproductive conversation about Microsoft deliverability comes from treating Microsoft as one destination. It is two.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Consumer Outlook.com<\/strong> covers outlook.com, hotmail.com, live.com and msn.com. Microsoft owns the filtering, the reputation model and the remedy \u2014 this is the side with the 5,000\/day rule, SmartScreen, SNDS, JMRP, the RP and SC error codes, and a delisting path you can walk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Microsoft 365 corporate tenants<\/strong> run Exchange Online Protection, where your recipient&#8217;s employer configures the filter: spam and bulk thresholds, quarantine actions, IP allow and block lists, tenant allow\/block entries. Microsoft&#8217;s global signals feed in, but the admin overrides them in either direction. No feedback loop, no dashboard, no sender-side visibility.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So a fix that works on one side often does nothing on the other. Delisting at <code>sender.office.com<\/code> has no effect on a tenant that block-listed your domain. Establish which Microsoft you face before spending effort.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Requirements_at_a_glance\"><\/span>Requirements at a glance<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<!--\n  TABLE 1 \u2014 Requirements at a glance (Microsoft sender requirements post)\n  Paste into a WordPress \"Custom HTML\" block. All styles inline; no theme CSS needed.\n  Navy header #1F3A5C \u00b7 striped rows #F5F6F7\/#FFFFFF\n  Colour code: 550 rejections red #C0392B \u00b7 421 throttles amber #B7791F \u00b7 reputation\/soft grey #6B7280\n-->\n<div style=\"overflow-x:auto;border:1px solid #EAECEF;border-radius:8px;margin:24px 0;\">\n  <table style=\"width:100%;border-collapse:collapse;min-width:760px;font-family:inherit;\">\n    <thead>\n      <tr>\n        <th style=\"background:#1F3A5C;color:#ffffff;text-align:left;font-weight:700;font-size:14px;letter-spacing:.2px;padding:16px 20px;font-family:inherit;\">Requirement<\/th>\n        <th style=\"background:#1F3A5C;color:#ffffff;text-align:left;font-weight:700;font-size:14px;letter-spacing:.2px;padding:16px 20px;font-family:inherit;\">Consumer Outlook.com<\/th>\n        <th style=\"background:#1F3A5C;color:#ffffff;text-align:left;font-weight:700;font-size:14px;letter-spacing:.2px;padding:16px 20px;font-family:inherit;\">Microsoft 365 (EOP)<\/th>\n        <th style=\"background:#1F3A5C;color:#ffffff;text-align:left;font-weight:700;font-size:14px;letter-spacing:.2px;padding:16px 20px;font-family:inherit;\">Enforcement behavior<\/th>\n      <\/tr>\n    <\/thead>\n    <tbody>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">SPF passing<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">Required<\/strong> above 5,000\/day<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\">Strong signal, not a hard gate<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#C0392B;font-weight:600;border-bottom:1px solid #EAECEF;font-family:inherit;\">550 5.7.515 rejection<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">DKIM passing<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">Required<\/strong> above 5,000\/day<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\">Strong signal, not a hard gate<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#C0392B;font-weight:600;border-bottom:1px solid #EAECEF;font-family:inherit;\">550 5.7.515 rejection<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">DMARC record, minimum p=none<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">Required<\/strong> above 5,000\/day<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\">Honored inbound<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#C0392B;font-weight:600;border-bottom:1px solid #EAECEF;font-family:inherit;\">550 5.7.515, or 550 5.7.509 on p=reject<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">SPF or DKIM aligned to 5322.From<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">Required<\/strong> above 5,000\/day<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\">Feeds composite authentication<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#C0392B;font-weight:600;border-bottom:1px solid #EAECEF;font-family:inherit;\">Rejection on failure<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">Valid reverse DNS<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\">Long-standing policy<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\">Reputation input<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#B7791F;font-weight:600;border-bottom:1px solid #EAECEF;font-family:inherit;\">Discretionary rejection<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">Functional From and Reply-To<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#6B7280;border-bottom:1px solid #EAECEF;font-family:inherit;\">Recommended<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#6B7280;border-bottom:1px solid #EAECEF;font-family:inherit;\">Recommended<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#6B7280;border-bottom:1px solid #EAECEF;font-family:inherit;\">Reputation input<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">Visible unsubscribe<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#6B7280;border-bottom:1px solid #EAECEF;font-family:inherit;\">Recommended<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#6B7280;border-bottom:1px solid #EAECEF;font-family:inherit;\">Recommended<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#6B7280;border-bottom:1px solid #EAECEF;font-family:inherit;\">Complaint-rate driven<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">List hygiene, bounce handling<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#6B7280;border-bottom:1px solid #EAECEF;font-family:inherit;\">Recommended<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#6B7280;border-bottom:1px solid #EAECEF;font-family:inherit;\">Recommended<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#6B7280;border-bottom:1px solid #EAECEF;font-family:inherit;\">Reputation input<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">Max 500 simultaneous connections<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\">Policy limit<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#6B7280;border-bottom:1px solid #EAECEF;font-family:inherit;\">Not published<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#B7791F;font-weight:600;border-bottom:1px solid #EAECEF;font-family:inherit;\">421 RP-003<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">BCL below tenant threshold<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#6B7280;border-bottom:1px solid #EAECEF;font-family:inherit;\">Not applicable<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\">Tenant-configured, default 7<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#6B7280;border-bottom:1px solid #EAECEF;font-family:inherit;\">Junk, quarantine or delete<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">Not on the tenant&#8217;s block list<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#6B7280;font-family:inherit;\">Not applicable<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;font-family:inherit;\">Entirely tenant-controlled<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#C0392B;font-weight:600;font-family:inherit;\">550 5.7.703<\/td>\n      <\/tr>\n    <\/tbody>\n  <\/table>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">One caution on the &#8220;recommended&#8221; rows. Many 2026 guides claim Microsoft mandates <a href=\"https:\/\/www.rfc-editor.org\/rfc\/rfc8058\" rel=\"nofollow\">RFC 8058<\/a> one-click unsubscribe and a published complaint-rate ceiling. Those are <a href=\"https:\/\/www.mailercloud.com\/blog\/gmail-yahoo-sender-requirements\">the Google and Yahoo requirements from February 2024<\/a>, misattributed \u2014 Microsoft frames everything beyond SPF, DKIM and DMARC as practices large senders &#8220;should also adopt.&#8221; Implement one-click unsubscribe anyway, because it reduces complaints, but it is not what triggers 5.7.515.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Authentication_requirements\"><\/span>Authentication requirements<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft&#8217;s stated minimum for high-volume senders: SPF passes, DKIM passes, and a DMARC record exists at <code>p=none<\/code> or stricter, aligned with either SPF or DKIM \u2014 &#8220;preferably both,&#8221; in Microsoft&#8217;s wording. Both SPF and DKIM must <em>pass<\/em>; the either\/or applies only to <em>alignment<\/em>. Take the strict reading anyway and align both. Our implementation guide walks through getting SPF, DKIM and DMARC aligned.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft&#8217;s own documentation is genuinely inconsistent in one place worth knowing about: the <code>MarkAsSpamBulkMail<\/code> documentation says a BCL <em>greater than<\/em> the configured threshold is converted to an SCL of 6, while the BCL reference and the portal describe the trigger as the threshold being <em>met or exceeded<\/em>. At a threshold of 7 that is the difference between BCL 7 converting and not. Assume the stricter reading \u2014 that hitting the number is enough.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Separate two failure modes. <strong>550 5.7.515<\/strong> is the bulk sender rule: you are over the threshold and your authentication does not meet the bar. <strong>550 5.7.509<\/strong> \u2014 &#8220;does not pass DMARC verification and has a DMARC policy of reject&#8221; \u2014 is Microsoft honoring <em>your own<\/em> published policy, and applies at any volume.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Enforcement is real but not uniform. Practitioners report partial-campaign rejections traced to differing envelope domains, header folding, duplicate headers, DNS timeouts during DKIM lookup, and content modification in transit. If you see <code>dkim=Fail<\/code> on mail you know is signed correctly, examine the transport path before your DNS. Recipient Safe Sender entries should not be expected to bypass any of this: <code>5.7.515<\/code> is a rejection issued during the SMTP transaction, before the message is ever accepted and before any mailbox-level rule can apply to it.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Volume_thresholds_and_who_counts_as_a_bulk_sender\"><\/span>Volume thresholds and who counts as a bulk sender<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The threshold is <strong>5,000 or more messages per day to Microsoft consumer services, where all messages use the same domain in the 5322.From address<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>A footnote on that number, because Microsoft&#8217;s own wording drifts. The announcement blog and the postmaster policies page both say &#8220;more than 5,000 emails per day&#8221;; the support article says &#8220;5,000 or more&#8221; and omits &#8220;per day&#8221; altogether. Treat 5,000 as the trigger rather than the ceiling \u2014 do not build a sending plan that sits at 4,999 and assumes safety.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Three things in that phrasing catch senders out. The count is <strong>per From domain, not per IP<\/strong>, so splitting across IPs does not put you under it. It counts <strong>only consumer Microsoft recipients<\/strong>, so your total daily send is irrelevant. And it is a <strong>daily<\/strong> measure, so a monthly newsletter crossing 5,000 consumer recipients is in scope on send day. There is no published grace band and no exemption path. Note the direction of travel: Microsoft&#8217;s wording is &#8220;after you reach this threshold, we expect all messages from senders in the domain&#8221; to comply \u2014 once a From domain crosses 5,000, the requirement attaches to the domain, not to that day&#8217;s volume. Microsoft publishes no reset condition or lookback window, so assume compliance is permanent once triggered. And every reputation mechanism on this page applies at any volume, threshold or not.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"SNDS_and_JMRP_the_tools_Microsoft_gives_you\"><\/span>SNDS and JMRP: the tools Microsoft gives you<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft is one of very few mailbox providers operating a genuine feedback loop. Both tools moved hosts in 2026 \u2014 any guide citing the old addresses is stale.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>SNDS portal:<\/strong> <code>https:\/\/substrate.office.com\/ip-domain-management-snds\/snds<\/code><\/li>\n\n\n\n<li><strong>SNDS FAQ:<\/strong> <code>https:\/\/substrate.office.com\/ip-domain-management-snds\/snds\/faq<\/code><\/li>\n\n\n\n<li><strong>JMRP enrollment:<\/strong> <code>https:\/\/substrate.office.com\/ip-domain-management-snds\/snds\/jmrp<\/code><\/li>\n\n\n\n<li><strong>Outlook.com postmaster:<\/strong> <code>https:\/\/substrate.office.com\/ip-domain-management-snds\/postmaster<\/code><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The legacy <code>sendersupport.olc.protection.outlook.com<\/code> and <code>postmaster.live.com<\/code> paths 308-redirect, but lossily \u2014 old <code>.aspx<\/code> deep links land at a section root. <code>junkmailreporting.microsoft.com<\/code> no longer resolves at all.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/substrate.office.com\/ip-domain-management-snds\/snds\" rel=\"nofollow\">SNDS<\/a> is per-IP-range and requires proof of control. Microsoft derives authorization addresses from reverse DNS, WHOIS and the routing table, then mails a request key to <code>postmaster@<\/code> and <code>abuse@<\/code> that domain. Access is not permanent once granted. Microsoft periodically requires the authorizing contact to reauthorize, and the FAQ is explicit about the window: if they do not successfully complete that process within 7 days, they lose access. Access is also removed automatically when the advertised subnets covering your IPs change \u2014 a renumbering or a new upstream announcement can silently drop you out of SNDS.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Reading SNDS data<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The Data page reports per IP, per PST day, with 90-day retention: RCPT and DATA counts, message recipients, sample HELO and MAIL FROM, filter result, complaint rate, sample messages, and flags for virus-infected mail, malware hosting and open-proxy status.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The color bands apply to the filter result column only<\/strong>, measuring the proportion of that IP&#8217;s mail SmartScreen classified as spam: green under 10%, yellow 10% to 90%, red above 90%.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft publishes no color-coded <em>complaint rate<\/em> bands \u2014 the most repeated falsehood about SNDS. The FAQ&#8217;s only complaint figure is a peer benchmark: more than 30% of IPs sending to Outlook.com keep complaint rates below 0.3%. That is a distribution statistic, not a line Microsoft enforces. Nor does green mean inbox \u2014 IPs routinely show green, low complaints and zero trap hits while landing in Junk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Trap hit counts are scheduled to be removed from SNDS Data Reports starting 22 July 2026<\/strong>, per the portal&#8217;s own announcement \u2014 an upcoming change, not one that has landed yet. Automated Data Access changed too: URLs beginning with the legacy host prefix <code>https:\/\/sendersupport.olc.protection.outlook.com\/snds\/<\/code> were deprecated on 22 June 2026. <em>(Generated links are also reported to expire after 30 days, and several sources describe a replacement REST API with OAuth 2.0; neither is stated in the announcement or the FAQ, so treat both as unconfirmed.)<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">JMRP, and what it stopped telling you<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">JMRP forwards a copy of any message a consumer Outlook.com user marks as junk. Enrollment happens inside the SNDS portal and requires the IP verified under your SNDS account \u2014 feeds not linked to one were removed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As of mid-2026, JMRP reports are standard ARF and heavily redacted. The complainant&#8217;s address is gone, the proprietary <code>X-HmXmrOriginalRecipient<\/code> header is gone, <code>To:<\/code> reads &#8220;Undisclosed Recipients,&#8221; and <strong>the message body is stripped entirely<\/strong>. Downloadable samples were discontinued. Microsoft has published nothing about this; the change was observed in the wild from mid-June 2026 and is corroborated across independent practitioner reports.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If your suppression automation parsed the recipient address or scraped the body for a customer ID, it is broken. What survives is the <code>Message-ID<\/code>, mapped back to your send log, plus custom <code>X-<\/code> headers you inject at send time \u2014 provided they are not formatted like an email address, or they get redacted too. If you inject nothing today, add an opaque subscriber identifier now.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Tenant-side_controls_you_do_not_control\"><\/span>Tenant-side controls you do not control<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Bulk Complaint Level (BCL)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><a href=\"https:\/\/learn.microsoft.com\/en-us\/defender-office-365\/anti-spam-bulk-complaint-level-bcl-about\" rel=\"nofollow\">Bulk Complaint Level<\/a><\/strong> runs 0 to 9: zero is not a bulk sender, 1 to 3 few complaints, 4 to 7 mixed, 8 and 9 high. The default policy and any newly created policy use a threshold of <strong>7<\/strong>; the Standard preset <strong>6<\/strong>; the Strict preset <strong>5<\/strong>. Default and Standard route at-or-above-threshold mail to Junk; Strict quarantines it. The PowerShell-only setting <code>MarkAsSpamBulkMail<\/code> is <strong>on by default<\/strong> and converts a BCL breach into an SCL of 6 \u2014 a full Spam verdict, not a soft &#8220;bulk&#8221; label. Microsoft publishes no BCL formula; the only named driver is complaint rate. This is the mechanism behind mail that is <a href=\"https:\/\/www.mailercloud.com\/blog\/emails-going-to-spam-only-outlook\">accepted but junked at Microsoft 365<\/a>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Connection filtering: IP allow and block lists<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><a href=\"https:\/\/learn.microsoft.com\/en-us\/defender-office-365\/connection-filter-policies-configure\" rel=\"nofollow\">Connection filtering<\/a><\/strong> gives admins an IP Allow List and IP Block List, no IPv6, each list capped at 1,273 entries \u2014 the cap is per list, not shared between them. The \/24 through \/32 CIDR restriction is documented as an Allow List limit. Block List messages are rejected with no spam scoring and <strong>do not appear in the tenant&#8217;s own message trace<\/strong> \u2014 which explains the &#8220;our admin says there is no record of your email&#8221; dead end. An IP allow entry does not change throttling: allow-listing buys filtering relief, not rate headroom.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The Tenant Allow\/Block List<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><a href=\"https:\/\/learn.microsoft.com\/en-us\/defender-office-365\/tenant-allow-block-list-about\" rel=\"nofollow\">The Tenant Allow\/Block List<\/a><\/strong> covers domains, addresses, URLs, files, IPv6 addresses and spoofed senders, and block entries beat allow entries. A domain block means your mail <em>can be<\/em> classified as high confidence phishing and quarantined \u2014 recipients can only request release, not release it themselves. You will see no bounce at all, which is the tell. (<code>550 5.7.703<\/code> is the related code, but it is what the tenant&#8217;s own users get when sending outbound to a blocked domain \u2014 not what you receive.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Allow entries for domains, addresses, URLs and files persist 45 days after Microsoft&#8217;s filters judge the entity clean \u2014 the clock starts at the verdict, not at creation. An admin may instead pin an expiry up to 30 days out. Spoofed-sender allow entries never expire. Microsoft also removes allow entries unprompted once it decides they are no longer needed, so any allow-listing you win is temporary.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What you can actually do<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Everything routes through the recipient. Ask for the full internet headers and read <code>X-Forefront-Antispam-Report<\/code> \u2014 <code>CIP<\/code>, <code>SCL<\/code>, <code>CAT<\/code> (e.g. <code>BULK<\/code>, <code>SPM<\/code>, <code>PHSH<\/code>), <code>SFV<\/code>, <code>PTR<\/code>, <code>H<\/code> \u2014 and <code>X-Microsoft-Antispam<\/code>, which is where <code>BCL<\/code> lives. It is <em>not<\/em> in the Forefront header, despite what most guides claim.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><code>SFV<\/code> is the most useful field you can obtain. <code>SFV:SPM<\/code> means Microsoft&#8217;s filter judged you spam. <code>SFV:SKB<\/code> means you are on the tenant&#8217;s blocked senders list, and <code>SFV:SKS<\/code> means a mail flow rule stamped you as spam before filtering ran \u2014 both prove a human at the recipient organization made a decision that no reputation work will change. <code>SFV:BLK<\/code> is the more common case and a different conversation entirely: filtering was skipped and the message blocked because it came from an address in <em>that individual user&#8217;s<\/em> Blocked Senders list \u2014 SKB is the admin&#8217;s anti-spam policy list, BLK is the one person you are writing to. <code>SFV:SKA<\/code> means you are allow-listed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The only remedy reaching beyond one tenant is having the recipient admin report your message as a false positive through the Microsoft Defender Submissions page. That creates a tenant allow entry <em>and<\/em> feeds signal back to Microsoft&#8217;s global filters.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Reputation_and_throttling_behavior\"><\/span>Reputation and throttling behavior<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">The 421 codes: which limit you hit<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft&#8217;s rate limits are dynamic and reputation-scaled, not published quotas. Three distinct 421 codes tell you which limit you hit: <strong>421 RP-001<\/strong> is the connecting IP exceeding its allowed send rate, <strong>421 RP-002<\/strong> is the rate allowed on that single connection, and <strong>421 RP-003<\/strong> is the concurrent connection count. Senders treat these interchangeably and apply the wrong fix \u2014 RP-003 is solved by reducing concurrency, RP-001 by reducing throughput and repairing reputation. The published ceiling is 500 simultaneous connections without prior arrangement, but reputation throttles you well below that.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The 550 series: SC, OU and DY codes<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The 550 series distinguishes causes usefully. <strong>SC-001<\/strong> and <strong>OU-002<\/strong> are content or reputation rejections; <strong>SC-002<\/strong> means Microsoft saw directory-harvest behavior; <strong>SC-003<\/strong> flags an open proxy; <strong>SC-004<\/strong> is a complaint-driven block whose stated remedy is enrolling in JMRP; <strong>DY-001<\/strong> and <strong>DY-002<\/strong> mean you look like a dynamic IP or compromised machine. <strong>OU-001<\/strong> is Microsoft enforcing a Spamhaus listing \u2014 Microsoft will not lift it, you must delist at Spamhaus, and senders file Microsoft requests for it constantly and get nowhere. On the Microsoft 365 side, <code>451 4.7.500-699 Access denied, please try again later<\/code> \u2014 the range 4.7.550 falls inside \u2014 is a temporary restriction while Microsoft evaluates your traffic; it clears on its own, with no published duration. Our companion guide walks through <a href=\"https:\/\/www.mailercloud.com\/blog\/microsoft-550-5-7-1-blocked\">decoding S3140, S3150 and the 550 block codes<\/a>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Why recovery is slow<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Recovery is slow because reputation is built from sustained observed behavior, and traffic sent while blocked is mostly retries \u2014 not the signal Microsoft needs. Microsoft&#8217;s only published warm-up guidance says &#8220;A new IP can expect to be fully ramped within a couple of weeks or sooner depending on volume, list accuracy and as long as their junk email complaint rates are kept at a minimum,&#8221; and notes that a new IP under a domain with good existing reputation inherits some of it. Treat that as directional rather than a schedule \u2014 but the useful part holds: domain reputation carries across IP changes.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_sender_support_and_mitigation_path\"><\/span>The sender support and mitigation path<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">There are three separate paths, and using the wrong one wastes days.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Microsoft 365 IP blocks.<\/strong> If your NDR reads <code>550 5.7.606-649 Access denied, banned sending IP<\/code>, use the <a href=\"https:\/\/sender.office.com\/\" rel=\"nofollow\">Office 365 Anti-Spam IP Delist Portal<\/a> at <code>https:\/\/sender.office.com\/<\/code>. One email address and one IP per visit, plus a CAPTCHA, then verification, confirmation and Delist IP. Microsoft&#8217;s stated timing: &#8220;It might take up to 24 hours or longer.&#8221; Delisting is not durable \u2014 messages must still pass composite authentication, or the IP is blocked again.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The 5.7.511 exception.<\/strong> <code>550 5.7.511 Access denied, banned sender<\/code> cannot use the delist portal. Forward the full NDR with the code and IP to <code>delist@microsoft.com<\/code>. Microsoft commits to responding within 48 hours \u2014 the only response-time commitment published across any of these paths.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Consumer Outlook.com.<\/strong> The entry point is <code>http:\/\/go.microsoft.com\/fwlink\/?LinkID=614866<\/code>, which now redirects to <code>olcsupport.office.com<\/code> behind a Microsoft account sign-in. The historically anonymous form is gone. <em>(I could not enumerate the form&#8217;s fields or any stated SLA because of the login wall.)<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What none of these can do is override a tenant-level block. If a Microsoft 365 customer IP-blocked you, TABL-blocked you or added you to blocked senders, Microsoft has no documented mechanism to reverse it. That is deliberate: the tenant is the customer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On <strong>shared IPs<\/strong>, your ESP files mitigation requests, since the delist portal assumes you control the IP; your leverage is list quality, because pool reputation is collective. On <strong>dedicated IPs<\/strong>, every path above is yours to walk. <em>(Microsoft publishes nothing about mitigation for shared infrastructure \u2014 this reflects practice, not documented policy.)<\/em><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Compliance_checklist\"><\/span>Compliance checklist<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<!--\n  TABLE 2 \u2014 Compliance checklist (Microsoft sender requirements post)\n  Paste into a WordPress \"Custom HTML\" block. All styles inline; no theme CSS needed.\n  Navy header #1F3A5C \u00b7 striped rows #F5F6F7\/#FFFFFF \u00b7 commands in monospace chips\n-->\n<div style=\"overflow-x:auto;border:1px solid #EAECEF;border-radius:8px;margin:24px 0;\">\n  <table style=\"width:100%;border-collapse:collapse;min-width:680px;font-family:inherit;\">\n    <thead>\n      <tr>\n        <th style=\"background:#1F3A5C;color:#ffffff;text-align:center;font-weight:700;font-size:14px;letter-spacing:.2px;padding:16px 14px;width:48px;font-family:inherit;\">#<\/th>\n        <th style=\"background:#1F3A5C;color:#ffffff;text-align:left;font-weight:700;font-size:14px;letter-spacing:.2px;padding:16px 20px;font-family:inherit;\">Check<\/th>\n        <th style=\"background:#1F3A5C;color:#ffffff;text-align:left;font-weight:700;font-size:14px;letter-spacing:.2px;padding:16px 20px;font-family:inherit;\">How to verify<\/th>\n      <\/tr>\n    <\/thead>\n    <tbody>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:14px 14px;text-align:center;font-size:15px;font-weight:700;color:#1E9E57;border-bottom:1px solid #EAECEF;font-family:inherit;\">1<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">SPF exists and passes<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:13px;background:#F3F4F6;padding:1px 6px;border-radius:4px;\">dig +short TXT yourdomain.com | grep spf1<\/code> \u2014 confirm under 10 lookups<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:14px 14px;text-align:center;font-size:15px;font-weight:700;color:#1E9E57;border-bottom:1px solid #EAECEF;font-family:inherit;\">2<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">DKIM signs and validates<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:13px;background:#F3F4F6;padding:1px 6px;border-radius:4px;\">dig +short TXT selector._domainkey.yourdomain.com<\/code>; confirm <code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:13px;background:#F3F4F6;padding:1px 6px;border-radius:4px;\">dkim=pass<\/code> on a delivered message<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:14px 14px;text-align:center;font-size:15px;font-weight:700;color:#1E9E57;border-bottom:1px solid #EAECEF;font-family:inherit;\">3<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">DMARC published, minimum p=none<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:13px;background:#F3F4F6;padding:1px 6px;border-radius:4px;\">dig +short TXT _dmarc.yourdomain.com<\/code><\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:14px 14px;text-align:center;font-size:15px;font-weight:700;color:#1E9E57;border-bottom:1px solid #EAECEF;font-family:inherit;\">4<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">SPF or DKIM aligns to 5322.From<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\">Test send; check <code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:13px;background:#F3F4F6;padding:1px 6px;border-radius:4px;\">Authentication-Results<\/code> for <code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:13px;background:#F3F4F6;padding:1px 6px;border-radius:4px;\">dmarc=pass<\/code><\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:14px 14px;text-align:center;font-size:15px;font-weight:700;color:#1E9E57;border-bottom:1px solid #EAECEF;font-family:inherit;\">5<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">Reverse DNS resolves and matches HELO<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:13px;background:#F3F4F6;padding:1px 6px;border-radius:4px;\">dig +short -x YOUR.SENDING.IP<\/code>, then forward-resolve the result<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:14px 14px;text-align:center;font-size:15px;font-weight:700;color:#1E9E57;border-bottom:1px solid #EAECEF;font-family:inherit;\">6<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">Daily consumer-Microsoft volume known per From domain<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\">Segment send logs across outlook.com, hotmail.com, live.com, msn.com<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:14px 14px;text-align:center;font-size:15px;font-weight:700;color:#1E9E57;border-bottom:1px solid #EAECEF;font-family:inherit;\">7<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">SNDS access active for every sending IP<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\">SNDS portal \u2014 confirm access is still granted; reauthorization requests must be completed within 7 days, and changes to advertised subnets remove access automatically<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:14px 14px;text-align:center;font-size:15px;font-weight:700;color:#1E9E57;border-bottom:1px solid #EAECEF;font-family:inherit;\">8<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">SNDS filter result green<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\">SNDS Data page \u2014 under 10% spam-classified<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:14px 14px;text-align:center;font-size:15px;font-weight:700;color:#1E9E57;border-bottom:1px solid #EAECEF;font-family:inherit;\">9<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">Complaint rate benchmarked<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\">SNDS Data page \u2014 compare against the 0.3% peer benchmark<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:14px 14px;text-align:center;font-size:15px;font-weight:700;color:#1E9E57;border-bottom:1px solid #EAECEF;font-family:inherit;\">10<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">JMRP enrolled and linked to SNDS<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\">SNDS portal, JMRP section<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:14px 14px;text-align:center;font-size:15px;font-weight:700;color:#1E9E57;border-bottom:1px solid #EAECEF;font-family:inherit;\">11<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">Complaint processing keys on Message-ID<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\">Audit suppression pipeline against post-redaction ARF reports<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:14px 14px;text-align:center;font-size:15px;font-weight:700;color:#1E9E57;border-bottom:1px solid #EAECEF;font-family:inherit;\">12<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">Opaque subscriber ID in a custom X- header<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\">Inspect raw headers of a delivered message<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:14px 14px;text-align:center;font-size:15px;font-weight:700;color:#1E9E57;border-bottom:1px solid #EAECEF;font-family:inherit;\">13<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">Automated Data Access link uses a current URL<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\">Not the deprecated <code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:13px;background:#F3F4F6;padding:1px 6px;border-radius:4px;\">sendersupport.olc.protection.outlook.com\/snds\/<\/code> host prefix \u2014 regenerate in SNDS Automated Access settings if it still points at the legacy host<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:14px 14px;text-align:center;font-size:15px;font-weight:700;color:#1E9E57;border-bottom:1px solid #EAECEF;font-family:inherit;\">14<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">Concurrent connections under 500<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\">MTA connection pool configuration<\/td>\n      <\/tr>\n      <tr style=\"background:#FFFFFF;\">\n        <td style=\"padding:14px 14px;text-align:center;font-size:15px;font-weight:700;color:#1E9E57;border-bottom:1px solid #EAECEF;font-family:inherit;\">15<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">Deferral monitoring separates RP-001 from RP-003<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;border-bottom:1px solid #EAECEF;font-family:inherit;\">Bounce log parsing rules<\/td>\n      <\/tr>\n      <tr style=\"background:#F5F6F7;\">\n        <td style=\"padding:14px 14px;text-align:center;font-size:15px;font-weight:700;color:#1E9E57;font-family:inherit;\">16<\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;font-family:inherit;\"><strong style=\"color:#1F3A5C;\">One-click unsubscribe functional<\/strong><\/td>\n        <td style=\"padding:14px 20px;vertical-align:top;font-size:15px;line-height:1.5;color:#24262B;font-family:inherit;\">Verify <code style=\"font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace;font-size:13px;background:#F3F4F6;padding:1px 6px;border-radius:4px;\">List-Unsubscribe-Post<\/code> header on a live campaign<\/td>\n      <\/tr>\n    <\/tbody>\n  <\/table>\n<\/div>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Changelog_how_Microsofts_requirements_evolved\"><\/span>Changelog: how Microsoft&#8217;s requirements evolved<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Upcoming:<\/strong> from <strong>22 July 2026<\/strong>, trap hit counts will no longer be included in the SNDS Data Report, per the portal&#8217;s announcement. This has not taken effect yet.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>June 2026<\/strong> \u2014 JMRP moves to standard ARF: complainant address redacted, <code>X-HmXmrOriginalRecipient<\/code> removed, message body stripped, downloadable samples discontinued.<\/li>\n\n\n\n<li><strong>22 June 2026<\/strong> \u2014 SNDS Automated Data Access URLs beginning with the legacy host prefix <code>https:\/\/sendersupport.olc.protection.outlook.com\/snds\/<\/code> deprecated.<\/li>\n\n\n\n<li><strong>Mid-2026<\/strong> \u2014 SNDS and the Outlook.com postmaster site migrate to <code>substrate.office.com<\/code>; <code>junkmailreporting.microsoft.com<\/code> retired.<\/li>\n\n\n\n<li><strong>5 May 2025<\/strong> \u2014 Enforcement of the 5,000\/day authentication requirement begins, with <code>550 5.7.515<\/code> rejections.<\/li>\n\n\n\n<li><strong>29 April 2025<\/strong> \u2014 Microsoft revises the plan: rather than junking non-compliant mail first and rejecting later, it rejects from day one, &#8220;to remove any confusion on why a message was in the junk folder.&#8221; The junking phase never ran as a standalone stage \u2014 which most secondary coverage still gets wrong.<\/li>\n\n\n\n<li><strong>2 April 2025<\/strong> \u2014 Microsoft announces SPF, DKIM and DMARC requirements for Outlook.com senders above 5,000 messages a day.<\/li>\n\n\n\n<li><strong>2023<\/strong> \u2014 EOP adopts stricter inbound DMARC policy handling defaults, honoring published <code>p=quarantine<\/code> and <code>p=reject<\/code>.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_Mailercloud_handles_Microsoft_delivery\"><\/span>How Mailercloud handles Microsoft delivery<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We send over a billion emails a month, so Microsoft is a daily operational concern rather than an occasional incident. Our deliverability team maintains SNDS and JMRP registration across every sending IP, feeds complaint data into suppression automatically, enforces authentication alignment before a domain can send, throttles to Outlook.com on RP-code signals rather than blind retries, and owns the mitigation path on shared pools.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you are looking at 550 5.7.515 bounces or unexplained Junk placement at Microsoft 365 tenants, <a href=\"https:\/\/www.mailercloud.com\/contact\">talk to our deliverability team<\/a> \u2014 or <a href=\"https:\/\/www.mailercloud.com\/signup\">start free with Mailercloud<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"FAQ_Microsoft_Sender_Requirements\"><\/span>FAQ : Microsoft Sender Requirements<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<div class=\"schema-faq wp-block-yoast-faq-block\"><div class=\"schema-faq-section\" id=\"faq-question-1786014788181\"><strong class=\"schema-faq-question\">Does the 5,000\/day rule apply to Microsoft 365 corporate recipients?<\/strong> <p class=\"schema-faq-answer\">No. It applies to consumer services only \u2014 outlook.com, hotmail.com, live.com and msn.com. Corporate tenants running Exchange Online Protection are governed by their own admin&#8217;s configuration plus Microsoft&#8217;s global signals.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1786014804424\"><strong class=\"schema-faq-question\">Is p=none really enough for DMARC?<\/strong> <p class=\"schema-faq-answer\">For Microsoft&#8217;s requirement, yes \u2014 <code>p=none<\/code> with SPF or DKIM alignment satisfies it. That is the floor, not the recommendation, and it gives no protection against exact-domain spoofing. Use it to become compliant and collect aggregate reports, then progress to quarantine and reject.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1786014822912\"><strong class=\"schema-faq-question\">SNDS shows green with low complaints, but Microsoft still junks my mail. Why?<\/strong> <p class=\"schema-faq-answer\">Green means SmartScreen is not classifying your traffic as spam-shaped, not that you reached the inbox. Microsoft applies reputation logic SNDS does not surface, and on the Microsoft 365 side a tenant&#8217;s bulk threshold and block lists override everything. Check the recipient&#8217;s headers for <code>SFV<\/code> and <code>BCL<\/code> first.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1786014842427\"><strong class=\"schema-faq-question\">Do SNDS or JMRP cover Microsoft 365 tenants?<\/strong> <p class=\"schema-faq-answer\">No. Both are consumer-only. There is no equivalent feedback loop or reputation dashboard for corporate Microsoft 365 mail. Your only diagnostic there is header data the recipient supplies.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1786014865194\"><strong class=\"schema-faq-question\">JMRP no longer tells me who complained. How do I suppress them?<\/strong> <p class=\"schema-faq-answer\">Match the <code>Message-ID<\/code> from the ARF report against your send log \u2014 that is now the primary attribution key. Also inject an opaque subscriber identifier as a custom <code>X-<\/code> header at send time, formatted so it does not resemble an email address, or Microsoft&#8217;s redaction strips it too.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1786014884430\"><strong class=\"schema-faq-question\"><strong>What is error 550 5.7.515 and how do I fix it?<\/strong><\/strong> <p class=\"schema-faq-answer\">It means Microsoft rejected your message because the domain in your 5322.From address didn&#8217;t meet the authentication bar for high-volume senders. Fix it by making SPF and DKIM pass, publishing a DMARC record at minimum p=none, and aligning at least one of SPF or DKIM to your From domain. It&#8217;s a hard SMTP rejection, not a Junk placement \u2014 so nothing mailbox-side will route around it.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1786015006665\"><strong class=\"schema-faq-question\">What&#8217;s the difference between 550 5.7.515 and 550 5.7.509?<\/strong> <p class=\"schema-faq-answer\">5.7.515 is the bulk-sender rule: you&#8217;re over 5,000\/day and your authentication doesn&#8217;t meet Microsoft&#8217;s bar. 5.7.509 is Microsoft honoring <em>your own<\/em> published DMARC policy of p=reject, and it applies at any volume. One is Microsoft&#8217;s requirement; the other is your policy enforced against you.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1786015031579\"><strong class=\"schema-faq-question\">Does the 5,000\/day limit reset if my sending volume drops?<\/strong> <p class=\"schema-faq-answer\">No. Once a From domain crosses 5,000 messages a day to Microsoft consumer inboxes, Microsoft treats the domain as a bulk sender from then on \u2014 the requirement attaches to the domain, and Microsoft publishes no reset window. Don&#8217;t plan a send that sits just under 5,000 assuming it keeps you exempt; treat the number as the trigger, not a ceiling.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1788841995156\"><strong class=\"schema-faq-question\"><\/strong> <p class=\"schema-faq-answer\"><\/p> <\/div> <\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Every current Microsoft sender requirement in one maintained reference: the 5,000\/day rule, 550 5.7.515, SNDS, JMRP, EOP bulk thresholds, and delisting.<\/p>\n","protected":false},"author":19,"featured_media":5347,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[28],"tags":[45,75,58,74,73,60],"class_list":["post-5217","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-email-delivery","tag-deliverability","tag-exchange-online-protection","tag-microsoft","tag-outlook-com","tag-sender-requirements","tag-snds"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Microsoft Sender Requirements: The Complete 2026 Reference<\/title>\n<meta name=\"description\" content=\"Microsoft rejects unauthenticated bulk mail with 550 5.7.515. The complete 2026 reference on SPF, DKIM, DMARC, SNDS, JMRP, and delisting.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Microsoft Sender Requirements: The Complete 2026 Reference\" \/>\n<meta property=\"og:description\" content=\"Microsoft rejects unauthenticated bulk mail with 550 5.7.515. The complete 2026 reference on SPF, DKIM, DMARC, SNDS, JMRP, and delisting.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements\" \/>\n<meta property=\"og:site_name\" content=\"Mailercloud Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/mailercloud\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/cherikkapoyil.amar\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-06T11:25:36+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-08T04:33:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.mailercloud.com\/blog\/wp-content\/uploads\/2026\/07\/Microsoft-Sender-Requirements_-The-Complete-2026-Reference.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"760\" \/>\n\t<meta property=\"og:image:height\" content=\"380\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Amar\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@mailercloud\" \/>\n<meta name=\"twitter:site\" content=\"@mailercloud\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Amar\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"16 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements\"},\"author\":{\"name\":\"Amar\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/#\\\/schema\\\/person\\\/0f3151b32a261b5f5df0a7968fa64945\"},\"headline\":\"Microsoft Sender Requirements: The Complete 2026 Reference\",\"datePublished\":\"2026-08-06T11:25:36+00:00\",\"dateModified\":\"2026-09-08T04:33:25+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements\"},\"wordCount\":3525,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/Microsoft-Sender-Requirements_-The-Complete-2026-Reference.jpg\",\"keywords\":[\"deliverability\",\"exchange online protection\",\"microsoft\",\"outlook.com\",\"sender requirements\",\"snds\"],\"articleSection\":[\"Email Delivery\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#respond\"]}]},{\"@type\":[\"WebPage\",\"FAQPage\"],\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements\",\"url\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements\",\"name\":\"Microsoft Sender Requirements: The Complete 2026 Reference\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/Microsoft-Sender-Requirements_-The-Complete-2026-Reference.jpg\",\"datePublished\":\"2026-08-06T11:25:36+00:00\",\"dateModified\":\"2026-09-08T04:33:25+00:00\",\"description\":\"Microsoft rejects unauthenticated bulk mail with 550 5.7.515. The complete 2026 reference on SPF, DKIM, DMARC, SNDS, JMRP, and delisting.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#breadcrumb\"},\"mainEntity\":[{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#faq-question-1786014788181\"},{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#faq-question-1786014804424\"},{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#faq-question-1786014822912\"},{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#faq-question-1786014842427\"},{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#faq-question-1786014865194\"},{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#faq-question-1786014884430\"},{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#faq-question-1786015006665\"},{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#faq-question-1786015031579\"}],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#primaryimage\",\"url\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/Microsoft-Sender-Requirements_-The-Complete-2026-Reference.jpg\",\"contentUrl\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/Microsoft-Sender-Requirements_-The-Complete-2026-Reference.jpg\",\"width\":760,\"height\":380,\"caption\":\"Microsoft Sender Requirements: The Complete 2026 Reference\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Microsoft Sender Requirements: The Complete 2026 Reference\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/\",\"name\":\"Mailercloud Blog\",\"description\":\"Create And Implement Email Marketing Campaigns\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/#organization\",\"name\":\"Mailercloud Blog\",\"url\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/footer_logo.png\",\"contentUrl\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/footer_logo.png\",\"width\":141,\"height\":30,\"caption\":\"Mailercloud Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/mailercloud\",\"https:\\\/\\\/x.com\\\/mailercloud\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/mailercloud\\\/\",\"https:\\\/\\\/www.instagram.com\\\/mailercloud\\\/\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCslSwv-TECN8rLvFM8wRlog\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/#\\\/schema\\\/person\\\/0f3151b32a261b5f5df0a7968fa64945\",\"name\":\"Amar\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/04\\\/1547012193070-150x150.jpeg\",\"url\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/04\\\/1547012193070-150x150.jpeg\",\"contentUrl\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/04\\\/1547012193070-150x150.jpeg\",\"caption\":\"Amar\"},\"description\":\"Amar CP is the Co-Founder and Sales Director at Mailercloud, where he leads partnerships, alliances, and customer growth. With over a decade of experience in application development, database architecture, and scaling web systems, Amar brings a rare blend of engineering depth and go-to-market expertise to email marketing. He writes about email deliverability, marketing automation, and helping small businesses grow smarter with data-driven campaigns.\",\"sameAs\":[\"http:\\\/\\\/www.mailercloud.com\",\"https:\\\/\\\/www.facebook.com\\\/cherikkapoyil.amar\",\"https:\\\/\\\/www.instagram.com\\\/amar.cp\\\/\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/amarcp\\\/\"],\"url\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/author\\\/amarmailercloud-com\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#faq-question-1786014788181\",\"position\":1,\"url\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#faq-question-1786014788181\",\"name\":\"Does the 5,000\\\/day rule apply to Microsoft 365 corporate recipients?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"No. It applies to consumer services only \u2014 outlook.com, hotmail.com, live.com and msn.com. Corporate tenants running Exchange Online Protection are governed by their own admin's configuration plus Microsoft's global signals.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#faq-question-1786014804424\",\"position\":2,\"url\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#faq-question-1786014804424\",\"name\":\"Is p=none really enough for DMARC?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"For Microsoft's requirement, yes \u2014 p=none with SPF or DKIM alignment satisfies it. That is the floor, not the recommendation, and it gives no protection against exact-domain spoofing. Use it to become compliant and collect aggregate reports, then progress to quarantine and reject.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#faq-question-1786014822912\",\"position\":3,\"url\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#faq-question-1786014822912\",\"name\":\"SNDS shows green with low complaints, but Microsoft still junks my mail. Why?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Green means SmartScreen is not classifying your traffic as spam-shaped, not that you reached the inbox. Microsoft applies reputation logic SNDS does not surface, and on the Microsoft 365 side a tenant's bulk threshold and block lists override everything. Check the recipient's headers for SFV and BCL first.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#faq-question-1786014842427\",\"position\":4,\"url\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#faq-question-1786014842427\",\"name\":\"Do SNDS or JMRP cover Microsoft 365 tenants?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"No. Both are consumer-only. There is no equivalent feedback loop or reputation dashboard for corporate Microsoft 365 mail. Your only diagnostic there is header data the recipient supplies.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#faq-question-1786014865194\",\"position\":5,\"url\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#faq-question-1786014865194\",\"name\":\"JMRP no longer tells me who complained. How do I suppress them?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Match the Message-ID from the ARF report against your send log \u2014 that is now the primary attribution key. Also inject an opaque subscriber identifier as a custom X- header at send time, formatted so it does not resemble an email address, or Microsoft's redaction strips it too.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#faq-question-1786014884430\",\"position\":6,\"url\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#faq-question-1786014884430\",\"name\":\"What is error 550 5.7.515 and how do I fix it?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"It means Microsoft rejected your message because the domain in your 5322.From address didn't meet the authentication bar for high-volume senders. Fix it by making SPF and DKIM pass, publishing a DMARC record at minimum p=none, and aligning at least one of SPF or DKIM to your From domain. It's a hard SMTP rejection, not a Junk placement \u2014 so nothing mailbox-side will route around it.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#faq-question-1786015006665\",\"position\":7,\"url\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#faq-question-1786015006665\",\"name\":\"What's the difference between 550 5.7.515 and 550 5.7.509?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"5.7.515 is the bulk-sender rule: you're over 5,000\\\/day and your authentication doesn't meet Microsoft's bar. 5.7.509 is Microsoft honoring <em>your own<\\\/em> published DMARC policy of p=reject, and it applies at any volume. One is Microsoft's requirement; the other is your policy enforced against you.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#faq-question-1786015031579\",\"position\":8,\"url\":\"https:\\\/\\\/www.mailercloud.com\\\/blog\\\/microsoft-sender-requirements#faq-question-1786015031579\",\"name\":\"Does the 5,000\\\/day limit reset if my sending volume drops?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"No. Once a From domain crosses 5,000 messages a day to Microsoft consumer inboxes, Microsoft treats the domain as a bulk sender from then on \u2014 the requirement attaches to the domain, and Microsoft publishes no reset window. Don't plan a send that sits just under 5,000 assuming it keeps you exempt; treat the number as the trigger, not a ceiling.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Microsoft Sender Requirements: The Complete 2026 Reference","description":"Microsoft rejects unauthenticated bulk mail with 550 5.7.515. The complete 2026 reference on SPF, DKIM, DMARC, SNDS, JMRP, and delisting.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements","og_locale":"en_US","og_type":"article","og_title":"Microsoft Sender Requirements: The Complete 2026 Reference","og_description":"Microsoft rejects unauthenticated bulk mail with 550 5.7.515. The complete 2026 reference on SPF, DKIM, DMARC, SNDS, JMRP, and delisting.","og_url":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements","og_site_name":"Mailercloud Blog","article_publisher":"https:\/\/www.facebook.com\/mailercloud","article_author":"https:\/\/www.facebook.com\/cherikkapoyil.amar","article_published_time":"2026-08-06T11:25:36+00:00","article_modified_time":"2026-09-08T04:33:25+00:00","og_image":[{"width":760,"height":380,"url":"https:\/\/www.mailercloud.com\/blog\/wp-content\/uploads\/2026\/07\/Microsoft-Sender-Requirements_-The-Complete-2026-Reference.jpg","type":"image\/jpeg"}],"author":"Amar","twitter_card":"summary_large_image","twitter_creator":"@mailercloud","twitter_site":"@mailercloud","twitter_misc":{"Written by":"Amar","Est. reading time":"16 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#article","isPartOf":{"@id":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements"},"author":{"name":"Amar","@id":"https:\/\/www.mailercloud.com\/blog\/#\/schema\/person\/0f3151b32a261b5f5df0a7968fa64945"},"headline":"Microsoft Sender Requirements: The Complete 2026 Reference","datePublished":"2026-08-06T11:25:36+00:00","dateModified":"2026-09-08T04:33:25+00:00","mainEntityOfPage":{"@id":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements"},"wordCount":3525,"commentCount":0,"publisher":{"@id":"https:\/\/www.mailercloud.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#primaryimage"},"thumbnailUrl":"https:\/\/www.mailercloud.com\/blog\/wp-content\/uploads\/2026\/07\/Microsoft-Sender-Requirements_-The-Complete-2026-Reference.jpg","keywords":["deliverability","exchange online protection","microsoft","outlook.com","sender requirements","snds"],"articleSection":["Email Delivery"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#respond"]}]},{"@type":["WebPage","FAQPage"],"@id":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements","url":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements","name":"Microsoft Sender Requirements: The Complete 2026 Reference","isPartOf":{"@id":"https:\/\/www.mailercloud.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#primaryimage"},"image":{"@id":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#primaryimage"},"thumbnailUrl":"https:\/\/www.mailercloud.com\/blog\/wp-content\/uploads\/2026\/07\/Microsoft-Sender-Requirements_-The-Complete-2026-Reference.jpg","datePublished":"2026-08-06T11:25:36+00:00","dateModified":"2026-09-08T04:33:25+00:00","description":"Microsoft rejects unauthenticated bulk mail with 550 5.7.515. The complete 2026 reference on SPF, DKIM, DMARC, SNDS, JMRP, and delisting.","breadcrumb":{"@id":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#breadcrumb"},"mainEntity":[{"@id":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#faq-question-1786014788181"},{"@id":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#faq-question-1786014804424"},{"@id":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#faq-question-1786014822912"},{"@id":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#faq-question-1786014842427"},{"@id":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#faq-question-1786014865194"},{"@id":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#faq-question-1786014884430"},{"@id":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#faq-question-1786015006665"},{"@id":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#faq-question-1786015031579"}],"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#primaryimage","url":"https:\/\/www.mailercloud.com\/blog\/wp-content\/uploads\/2026\/07\/Microsoft-Sender-Requirements_-The-Complete-2026-Reference.jpg","contentUrl":"https:\/\/www.mailercloud.com\/blog\/wp-content\/uploads\/2026\/07\/Microsoft-Sender-Requirements_-The-Complete-2026-Reference.jpg","width":760,"height":380,"caption":"Microsoft Sender Requirements: The Complete 2026 Reference"},{"@type":"BreadcrumbList","@id":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.mailercloud.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Microsoft Sender Requirements: The Complete 2026 Reference"}]},{"@type":"WebSite","@id":"https:\/\/www.mailercloud.com\/blog\/#website","url":"https:\/\/www.mailercloud.com\/blog\/","name":"Mailercloud Blog","description":"Create And Implement Email Marketing Campaigns","publisher":{"@id":"https:\/\/www.mailercloud.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.mailercloud.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.mailercloud.com\/blog\/#organization","name":"Mailercloud Blog","url":"https:\/\/www.mailercloud.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mailercloud.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.mailercloud.com\/blog\/wp-content\/uploads\/2025\/02\/footer_logo.png","contentUrl":"https:\/\/www.mailercloud.com\/blog\/wp-content\/uploads\/2025\/02\/footer_logo.png","width":141,"height":30,"caption":"Mailercloud Blog"},"image":{"@id":"https:\/\/www.mailercloud.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/mailercloud","https:\/\/x.com\/mailercloud","https:\/\/www.linkedin.com\/company\/mailercloud\/","https:\/\/www.instagram.com\/mailercloud\/","https:\/\/www.youtube.com\/channel\/UCslSwv-TECN8rLvFM8wRlog"]},{"@type":"Person","@id":"https:\/\/www.mailercloud.com\/blog\/#\/schema\/person\/0f3151b32a261b5f5df0a7968fa64945","name":"Amar","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.mailercloud.com\/blog\/wp-content\/uploads\/2026\/04\/1547012193070-150x150.jpeg","url":"https:\/\/www.mailercloud.com\/blog\/wp-content\/uploads\/2026\/04\/1547012193070-150x150.jpeg","contentUrl":"https:\/\/www.mailercloud.com\/blog\/wp-content\/uploads\/2026\/04\/1547012193070-150x150.jpeg","caption":"Amar"},"description":"Amar CP is the Co-Founder and Sales Director at Mailercloud, where he leads partnerships, alliances, and customer growth. With over a decade of experience in application development, database architecture, and scaling web systems, Amar brings a rare blend of engineering depth and go-to-market expertise to email marketing. He writes about email deliverability, marketing automation, and helping small businesses grow smarter with data-driven campaigns.","sameAs":["http:\/\/www.mailercloud.com","https:\/\/www.facebook.com\/cherikkapoyil.amar","https:\/\/www.instagram.com\/amar.cp\/","https:\/\/www.linkedin.com\/in\/amarcp\/"],"url":"https:\/\/www.mailercloud.com\/blog\/author\/amarmailercloud-com"},{"@type":"Question","@id":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#faq-question-1786014788181","position":1,"url":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#faq-question-1786014788181","name":"Does the 5,000\/day rule apply to Microsoft 365 corporate recipients?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"No. It applies to consumer services only \u2014 outlook.com, hotmail.com, live.com and msn.com. Corporate tenants running Exchange Online Protection are governed by their own admin's configuration plus Microsoft's global signals.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#faq-question-1786014804424","position":2,"url":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#faq-question-1786014804424","name":"Is p=none really enough for DMARC?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"For Microsoft's requirement, yes \u2014 p=none with SPF or DKIM alignment satisfies it. That is the floor, not the recommendation, and it gives no protection against exact-domain spoofing. Use it to become compliant and collect aggregate reports, then progress to quarantine and reject.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#faq-question-1786014822912","position":3,"url":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#faq-question-1786014822912","name":"SNDS shows green with low complaints, but Microsoft still junks my mail. Why?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Green means SmartScreen is not classifying your traffic as spam-shaped, not that you reached the inbox. Microsoft applies reputation logic SNDS does not surface, and on the Microsoft 365 side a tenant's bulk threshold and block lists override everything. Check the recipient's headers for SFV and BCL first.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#faq-question-1786014842427","position":4,"url":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#faq-question-1786014842427","name":"Do SNDS or JMRP cover Microsoft 365 tenants?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"No. Both are consumer-only. There is no equivalent feedback loop or reputation dashboard for corporate Microsoft 365 mail. Your only diagnostic there is header data the recipient supplies.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#faq-question-1786014865194","position":5,"url":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#faq-question-1786014865194","name":"JMRP no longer tells me who complained. How do I suppress them?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Match the Message-ID from the ARF report against your send log \u2014 that is now the primary attribution key. Also inject an opaque subscriber identifier as a custom X- header at send time, formatted so it does not resemble an email address, or Microsoft's redaction strips it too.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#faq-question-1786014884430","position":6,"url":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#faq-question-1786014884430","name":"What is error 550 5.7.515 and how do I fix it?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"It means Microsoft rejected your message because the domain in your 5322.From address didn't meet the authentication bar for high-volume senders. Fix it by making SPF and DKIM pass, publishing a DMARC record at minimum p=none, and aligning at least one of SPF or DKIM to your From domain. It's a hard SMTP rejection, not a Junk placement \u2014 so nothing mailbox-side will route around it.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#faq-question-1786015006665","position":7,"url":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#faq-question-1786015006665","name":"What's the difference between 550 5.7.515 and 550 5.7.509?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"5.7.515 is the bulk-sender rule: you're over 5,000\/day and your authentication doesn't meet Microsoft's bar. 5.7.509 is Microsoft honoring <em>your own<\/em> published DMARC policy of p=reject, and it applies at any volume. One is Microsoft's requirement; the other is your policy enforced against you.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#faq-question-1786015031579","position":8,"url":"https:\/\/www.mailercloud.com\/blog\/microsoft-sender-requirements#faq-question-1786015031579","name":"Does the 5,000\/day limit reset if my sending volume drops?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"No. Once a From domain crosses 5,000 messages a day to Microsoft consumer inboxes, Microsoft treats the domain as a bulk sender from then on \u2014 the requirement attaches to the domain, and Microsoft publishes no reset window. Don't plan a send that sits just under 5,000 assuming it keeps you exempt; treat the number as the trigger, not a ceiling.","inLanguage":"en-US"},"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/www.mailercloud.com\/blog\/wp-json\/wp\/v2\/posts\/5217","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.mailercloud.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.mailercloud.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.mailercloud.com\/blog\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mailercloud.com\/blog\/wp-json\/wp\/v2\/comments?post=5217"}],"version-history":[{"count":8,"href":"https:\/\/www.mailercloud.com\/blog\/wp-json\/wp\/v2\/posts\/5217\/revisions"}],"predecessor-version":[{"id":5572,"href":"https:\/\/www.mailercloud.com\/blog\/wp-json\/wp\/v2\/posts\/5217\/revisions\/5572"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.mailercloud.com\/blog\/wp-json\/wp\/v2\/media\/5347"}],"wp:attachment":[{"href":"https:\/\/www.mailercloud.com\/blog\/wp-json\/wp\/v2\/media?parent=5217"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.mailercloud.com\/blog\/wp-json\/wp\/v2\/categories?post=5217"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.mailercloud.com\/blog\/wp-json\/wp\/v2\/tags?post=5217"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}