What the bounce says
Exact wording as it appears in the rejection or NDR. Placeholders such as x.x.x.x and example.com stand for your own address and domain.
450 4.1.8 <user@example.com>: Sender address rejected: Domain not found 450 4.1.8 Sender address rejected: Domain not found
The receiving server verifies that the envelope sender’s domain exists before accepting mail, and yours did not resolve. The 450 code makes it temporary — the receiver assumes DNS might be briefly broken — but if the domain genuinely has no records, every retry fails.
Most common causes
- The envelope sender domain does not exist or has no MX/A record
- A typo or internal-only domain in the sender address
- DNS for the sender domain is temporarily failing
- A newly registered domain has no records yet
What to verify next
- Confirm the exact envelope sender domain from the rejection
- Look up MX and A records for it from an external resolver
- Fix the sender address or publish records for the domain
- Retry after DNS resolves; 450 is temporary
What is checked
The domain in MAIL FROM must have an MX or A record. Servers that send from internal-only domains, from a subdomain that was never published, or from a misspelled domain fail this check. Some applications use the machine’s hostname as the sender domain, which rarely resolves publicly.
Because the check is on the envelope sender, the visible From address can be perfectly valid while the envelope domain is not.
- MAIL FROM domain needs MX or A.
- Application hostnames as sender domains are the usual cause.
- Envelope sender, not From, is checked.
Fix the sender
Configure the application or server to use an envelope sender on a real domain — ideally one with SPF authorizing the sending IP. If a dedicated bounce subdomain is used, publish an MX or A record for it.
Temporary DNS failures
If the domain does exist, check its nameservers from outside; one failing nameserver can cause intermittent 4.1.8 at receivers that hit it. The propagation checker shows whether resolvers agree.
Best diagnostic path
Mail Failure Doctor
Classify the complete rejection and preserve provider-specific diagnostic context.
Open analysis → Live analysisEmail Infrastructure Digital Twin
Map the domain’s public mail infrastructure and provider relationships before remediation.
Open analysis →Known limits
- Receivers retry 450 for a limited time before giving up.
- A domain with only a website A record passes the check but may fail other policies.
Common questions
The From address is on a real domain.
The envelope sender is what is checked. Read the rejection or your logs for the MAIL FROM value.
Does a Null MX fail this check?
Yes at strict receivers — Null MX declares the domain does not accept mail, and some treat that as an invalid sender domain.
Why intermittent?
One of the domain’s nameservers is probably failing. Test each from outside.
Why the exact message matters
The same status family can be triggered by different conditions, and providers frequently add diagnostic text that narrows the issue. Use the complete rejection text rather than treating the numeric code as a complete diagnosis.
Provider reference
For the provider-defined meaning and current requirements, review Postfix: reject_unknown_sender_domain.