5.1.8 "Access denied, bad outbound sender" means a specific user has been placed on the restricted-users list because their account sent traffic Microsoft classified as spam or exceeded sending limits. The block is per user, and the usual cause is a compromised account.
Most common causes
- The account exceeded outbound sending limits
- The sender is suspected of spam or abusive activity
- The account was compromised and subsequently restricted
What to verify next
- Review account security before attempting to restore sending
- Verify whether the sender exceeded limits or generated unexpected volume
- Have the organization’s email administrator follow the provider remediation process
Why an account is restricted
Microsoft limits how many recipients a mailbox can address per day and watches for spam-like patterns. When either is exceeded, the user is added to the restricted list and their outbound mail is rejected with this code. Colleagues in the same tenant are unaffected, which is how it differs from tenant-wide 5.7.705.
In practice the account has usually been compromised: credentials phished, a mailbox rule created to hide replies, and the account used to send thousands of messages overnight. Occasionally the cause is legitimate but ill-advised bulk mail from a mailbox.
Secure before unblocking
Reset the password and revoke active sessions, then inspect the mailbox for forwarding rules and inbox rules the attacker created, check for OAuth applications granted mailbox access, and review sign-in history for unfamiliar locations.
Only after the account is secured should an administrator remove the user from the restricted list. Unblocking a still-compromised account results in a repeat within hours.
- Per-user block; the rest of the tenant sends normally.
- Assume compromise until sign-in history proves otherwise.
- Check mailbox rules — attackers hide their activity there.
Removing the restriction
A Microsoft 365 administrator removes the user from Restricted entities in the Defender portal. Delivery resumes shortly afterwards; there is no DNS propagation involved.
If the cause was legitimate bulk sending, move that workload to a proper sending platform. Mailboxes are not built for it, and the recipient limits exist precisely to catch abuse.
Best diagnostic path
Mail Failure Doctor
Classify the complete rejection and preserve provider-specific diagnostic context.
Open analysis → Live analysisEmail Infrastructure Digital Twin
Map the domain’s public mail infrastructure and provider relationships before remediation.
Open analysis →Known limits
- Recipient rate limits are Microsoft’s and vary by license.
- The block may recur if the underlying automation or compromise is not addressed.
Common questions
Is this a blacklist?
No. It is an internal restriction on one user, managed by your tenant administrator.
How fast is recovery after removal?
Usually within an hour. If it recurs, the account is still sending abusive traffic.
Should the user just create a new account?
No. Secure the existing account; a new account with the same compromised device or credentials will be restricted again.
Why the exact message matters
The same status family can be triggered by different conditions, and providers frequently add diagnostic text that narrows the issue. Use the complete rejection text rather than treating the numeric code as a complete diagnosis.
Provider reference
For the provider-defined meaning and current requirements, review Microsoft NDR 550 5.1.8 reference.