What the bounce says
Exact wording as it appears in the rejection or NDR. Placeholders such as x.x.x.x and example.com stand for your own address and domain.
550 5.2.1 Mailbox cannot be accessed 550 5.2.1 RESOLVER.RST.NotAuthorized; not authorized
The recipient exists but Exchange will not deliver to the mailbox: it is disabled, unlicensed, on hold in a state that blocks delivery, or restricted. The recipient organization’s administrator has to change the mailbox state.
Most common causes
- The mailbox is disabled or the account is blocked
- The license was removed and the mailbox is in a soft-deleted state
- The mailbox is a shared or resource mailbox with delivery restrictions
- A hold or migration state prevents delivery temporarily
What to verify next
- Confirm the mailbox state with the recipient organization
- Check licensing and whether the account is enabled
- Review delivery restrictions on the mailbox
- Retry after the administrator restores access
States that block delivery
A disabled or blocked account, a mailbox whose license was removed (it enters a grace period and then soft deletion), a mailbox with delivery restrictions that exclude the sender, or a resource mailbox that only accepts certain senders. Each produces this code with slightly different trailing text.
RESOLVER.RST.NotAuthorized indicates a delivery restriction: the mailbox accepts mail only from specific people or groups, and the sender is not among them.
- Disabled or unlicensed mailbox.
- Delivery restrictions on the recipient.
- Resource mailboxes with sender limits.
For the recipient administrator
Check the account is enabled and licensed, review message delivery restrictions on the mailbox, and confirm the object is not in a soft-deleted state. Restoring a license within the retention window reconnects the mailbox.
For the sender
There is nothing to change on your side. Confirm with the recipient organization whether the mailbox is meant to receive external mail, and use another contact if the person has left.
Best diagnostic path
Mail Failure Doctor
Classify the complete rejection and preserve provider-specific diagnostic context.
Open analysis → Live analysisEmail Infrastructure Digital Twin
Map the domain’s public mail infrastructure and provider relationships before remediation.
Open analysis →Known limits
- Mailbox state is visible only to the recipient tenant.
- Trailing text varies; NotAuthorized specifically means a restriction.
Common questions
Is the person gone?
Possibly. Disabled and unlicensed mailboxes often belong to departed users. Confirm with the organization.
Why can colleagues mail this address?
A delivery restriction can allow internal senders and block external ones.
Difference from 5.1.1?
5.1.1 means the address does not exist. 5.2.1 means it exists but cannot be delivered to.
Why the exact message matters
The same status family can be triggered by different conditions, and providers frequently add diagnostic text that narrows the issue. Use the complete rejection text rather than treating the numeric code as a complete diagnosis.
Provider reference
For the provider-defined meaning and current requirements, review Microsoft Exchange Online NDR reference.