exchange-online error

Exchange Online 550 5.7.705 — Tenant Exceeded Threshold

Exchange Online blocked outbound mail because the tenant exceeded an abuse or bulk-mail threshold.

5.7.705 means Microsoft has restricted outbound mail for the entire tenant because it crossed an abuse or bulk-sending threshold. It is a tenant-wide protective block, and the usual trigger is a compromised account or system, not a configuration mistake.

Reviewed 2026-09-02. Provider wording and requirements change; the provider reference below is authoritative.

Most common causes

  • A compromised account or system is generating abusive traffic
  • Unexpected bulk traffic crossed Microsoft enforcement thresholds
  • A connector or routing path is being abused
  • A recently renewed or changed tenant state may need administrative review

What to verify next

  1. Treat unexpected volume as a potential security incident
  2. Review compromised accounts, connectors and recent volume changes
  3. Stop abusive traffic before requesting remediation
  4. Follow the provider’s administrative recovery path

Treat it as a security incident first

Microsoft applies this restriction when outbound traffic from the tenant resembles abuse: a sudden burst, a high rate of undeliverable recipients, complaint signals, or patterns associated with spam. In most cases one account or one connected application has been compromised and is sending on its own.

Before requesting any remediation, find the source. Look at outbound message trace for unusual volume by sender, review recent sign-ins for the accounts involved, and check connectors and applications that hold send permissions.

Stop the traffic, then recover

Reset credentials and revoke sessions for any compromised account, remove mailbox rules the attacker created, and disable any application or connector that was abused. Microsoft will not lift a restriction while abusive traffic continues.

Once the source is contained, an administrator can review the restriction in the Defender portal. Some restrictions clear automatically after traffic normalizes; others require a request.

  • Identify the sending account or system before anything else.
  • Contain: credentials, sessions, rules, connectors.
  • Only then follow Microsoft’s administrative recovery path.

Preventing a repeat

Enforce multi-factor authentication, alert on unusual outbound volume, and inventory every application with mailbox send permissions. Compromised accounts are the primary cause, and the restriction is Microsoft protecting the rest of the internet from your tenant.

Legitimate bulk campaigns should not go through mailbox accounts. Use a sending platform with its own reputation and authenticate it properly.

Best diagnostic path

Known limits

  • Threshold values are not published and adapt to the tenant’s history.
  • Recovery timing depends on Microsoft’s review once the abusive traffic has stopped.

Common questions

Does this affect every user in the tenant?

Yes. The restriction applies at tenant level, which is why a single compromised account can stop outbound mail for everyone.

Can I just request removal?

You can, but the restriction returns if the traffic continues. Contain the source first.

Is legitimate bulk mail the cause?

Occasionally. Marketing mail sent from mailboxes can trigger it. Move campaigns to a dedicated, authenticated platform.

Why the exact message matters

The same status family can be triggered by different conditions, and providers frequently add diagnostic text that narrows the issue. Use the complete rejection text rather than treating the numeric code as a complete diagnosis.

Provider reference

For the provider-defined meaning and current requirements, review Microsoft Exchange Online NDR reference.