exchange-online error

Exchange Online 550 5.1.8 — Bad Outbound Sender

The sender is not currently recognized as a valid outbound sender, commonly after an account exceeds sending limits or is suspected of abusive sending.

5.1.8 "Access denied, bad outbound sender" means a specific user has been placed on the restricted-users list because their account sent traffic Microsoft classified as spam or exceeded sending limits. The block is per user, and the usual cause is a compromised account.

Reviewed 2026-09-02. Provider wording and requirements change; the provider reference below is authoritative.

Most common causes

  • The account exceeded outbound sending limits
  • The sender is suspected of spam or abusive activity
  • The account was compromised and subsequently restricted

What to verify next

  1. Review account security before attempting to restore sending
  2. Verify whether the sender exceeded limits or generated unexpected volume
  3. Have the organization’s email administrator follow the provider remediation process

Why an account is restricted

Microsoft limits how many recipients a mailbox can address per day and watches for spam-like patterns. When either is exceeded, the user is added to the restricted list and their outbound mail is rejected with this code. Colleagues in the same tenant are unaffected, which is how it differs from tenant-wide 5.7.705.

In practice the account has usually been compromised: credentials phished, a mailbox rule created to hide replies, and the account used to send thousands of messages overnight. Occasionally the cause is legitimate but ill-advised bulk mail from a mailbox.

Secure before unblocking

Reset the password and revoke active sessions, then inspect the mailbox for forwarding rules and inbox rules the attacker created, check for OAuth applications granted mailbox access, and review sign-in history for unfamiliar locations.

Only after the account is secured should an administrator remove the user from the restricted list. Unblocking a still-compromised account results in a repeat within hours.

  • Per-user block; the rest of the tenant sends normally.
  • Assume compromise until sign-in history proves otherwise.
  • Check mailbox rules — attackers hide their activity there.

Removing the restriction

A Microsoft 365 administrator removes the user from Restricted entities in the Defender portal. Delivery resumes shortly afterwards; there is no DNS propagation involved.

If the cause was legitimate bulk sending, move that workload to a proper sending platform. Mailboxes are not built for it, and the recipient limits exist precisely to catch abuse.

Best diagnostic path

Known limits

  • Recipient rate limits are Microsoft’s and vary by license.
  • The block may recur if the underlying automation or compromise is not addressed.

Common questions

Is this a blacklist?

No. It is an internal restriction on one user, managed by your tenant administrator.

How fast is recovery after removal?

Usually within an hour. If it recurs, the account is still sending abusive traffic.

Should the user just create a new account?

No. Secure the existing account; a new account with the same compromised device or credentials will be restricted again.

Why the exact message matters

The same status family can be triggered by different conditions, and providers frequently add diagnostic text that narrows the issue. Use the complete rejection text rather than treating the numeric code as a complete diagnosis.

Provider reference

For the provider-defined meaning and current requirements, review Microsoft NDR 550 5.1.8 reference.