What the bounce says
Exact wording as it appears in the rejection or NDR. Placeholders such as x.x.x.x and example.com stand for your own address and domain.
550 5.7.134 RESOLVER.RST.SenderNotAuthenticatedForGroup; authentication required; Delivery restriction check failed because the sender was not authenticated when sending to this group You can't send to this group because the group doesn't accept messages from external senders
The group is configured not to accept mail from outside the organization. The NDR says so directly and is usually accompanied by a plain-language sentence to the same effect.
Most common causes
- The group’s external-sender setting is off
- The sender’s domain is not treated as internal by the tenant
- A partner that should be internal is arriving through an external route
What to verify next
- Enable external senders on the group if intended
- Add specific external addresses to the group’s allowed senders
- Verify accepted domains and connectors if a partner domain should be internal
Why groups reject external mail
The default for many group types is internal-only, which prevents outsiders from mailing every member at once. Organizations enable external delivery deliberately for groups that serve as public contact points.
Partner domains that should count as internal can arrive externally if they are not configured as accepted domains or if their mail is not routed through an internal connector.
- Internal-only is the default for many groups.
- Public-facing groups need the setting changed.
- Partner domains may need accepted-domain or connector configuration.
Change the setting or the route
For a group that should be reachable from outside, enable external senders on the group. For a specific partner, add their addresses to the group’s allowed senders. For a partner organization that is effectively internal, configure it as an accepted domain with an appropriate connector so its mail is treated as internal.
Alternatives to opening the group
A shared mailbox or a mail-enabled contact can receive external mail and forward internally, which keeps the group closed while still giving outsiders a way in.
Best diagnostic path
Mail Failure Doctor
Classify the complete rejection and preserve provider-specific diagnostic context.
Open analysis → Live analysisEmail Infrastructure Digital Twin
Map the domain’s public mail infrastructure and provider relationships before remediation.
Open analysis →Known limits
- Only the recipient tenant can change group settings.
- The exact wording differs between Exchange versions.
Common questions
How is this different from 5.7.133?
5.7.133 is about authentication of the sender; 5.7.134 is specifically about external senders. Both are group delivery restrictions.
Can the sender work around it?
No. The recipient organization must allow external delivery or the specific sender.
Does this affect internal senders?
Not unless their mail arrives through an external route.
Why the exact message matters
The same status family can be triggered by different conditions, and providers frequently add diagnostic text that narrows the issue. Use the complete rejection text rather than treating the numeric code as a complete diagnosis.
Provider reference
For the provider-defined meaning and current requirements, review Microsoft Exchange Online NDR reference.