What the bounce says
Exact wording as it appears in the rejection or NDR. Placeholders such as x.x.x.x and example.com stand for your own address and domain.
550 5.1.1 <user@example.com>: Recipient address rejected: User unknown in virtual mailbox table 550 5.1.1 <user@example.com>: Recipient address rejected: User unknown 550 5.1.1 No such user here
User unknown is the generic form of "no such mailbox". Postfix says "User unknown in virtual mailbox table", others say "No such user here" or "Recipient address rejected". The server hosts the domain and has never heard of that local part.
Most common causes
- A typo in the address
- The mailbox was deleted
- The domain moved providers and the new server does not know the address
- A catch-all was removed
What to verify next
- Verify the address with the recipient
- Remove the address from lists and CRMs
- If you host the domain, confirm the mailbox exists in the virtual mailbox table or directory
- Check for a recent migration that dropped addresses
Where the lookup failed
The server owns the domain — otherwise it would say relay denied — and looked the address up in its mailbox table, directory or virtual map. Nothing matched. A typo, a deleted mailbox, or a domain migration that did not carry all addresses across are the causes.
After a provider migration, this appears for addresses that existed on the old server but were never created on the new one — aliases, distribution addresses, service accounts.
- Domain is hosted; local part is unknown.
- Migrations drop aliases and service addresses.
- A removed catch-all exposes previously silent typos.
For the sender
Verify the address independently and suppress it from lists. Repeated sends to unknown users damage reputation.
For the hosting administrator
Check the virtual mailbox or alias maps for the exact address, rebuild lookup tables after edits, and compare the address inventory against the previous system if you recently migrated.
Best diagnostic path
Mail Failure Doctor
Classify the complete rejection and preserve provider-specific diagnostic context.
Open analysis → Live analysisEmail Infrastructure Digital Twin
Map the domain’s public mail infrastructure and provider relationships before remediation.
Open analysis →Known limits
- Wording varies by MTA and hosting panel.
- Catch-all configurations change whether unknown addresses bounce.
Common questions
Difference from 5.1.10?
5.1.10 is Exchange’s wording for the same fact. 5.1.1 is the generic code most MTAs use.
Should I set up a catch-all?
Only if you want every typo delivered somewhere. It also attracts spam. Usually no.
Why after migration?
Address inventories are rarely complete. Compare old and new systems for aliases and forwards.
Why the exact message matters
The same status family can be triggered by different conditions, and providers frequently add diagnostic text that narrows the issue. Use the complete rejection text rather than treating the numeric code as a complete diagnosis.
Provider reference
For the provider-defined meaning and current requirements, review RFC 3463 — Enhanced Mail System Status Codes.