What the bounce says
Exact wording as it appears in the rejection or NDR. Placeholders such as x.x.x.x and example.com stand for your own address and domain.
554 5.7.1 <mail>: Helo command rejected: need fully-qualified hostname 504 5.5.2 <mail>: Helo command rejected: need fully-qualified hostname 550 5.7.1 <localhost>: Helo command rejected: You are not localhost
The receiver checked the name your server presented in HELO or EHLO and refused to continue because it was not a fully-qualified domain name. RFC 5321 requires an FQDN, and receivers that enforce it reject bare hostnames, IP literals without brackets and names that do not resolve.
Most common causes
- The mail server’s hostname is a bare label such as "mail" or "localhost"
- An application library sends an IP literal or an invalid name
- A copied configuration uses the wrong hostname
- The HELO name does not resolve in DNS
What to verify next
- Set the server’s HELO to a fully-qualified hostname under your domain
- Make sure that hostname resolves to the sending IP
- Verify with the reverse DNS and HELO auditor
- Capture the SMTP session to confirm the greeting sent
What a valid HELO is
A hostname with at least one dot that resolves in public DNS, ideally to the sending IP: mail.example.com. Not "mail", not "localhost", not "server1", and not the recipient’s own hostname. Strict receivers also reject names that resolve to a different address than the one connecting.
The name comes from the mail server’s configured hostname or an explicit HELO setting; applications with built-in SMTP often default to the machine name.
- Must contain a dot and resolve.
- Must not be localhost or the receiver’s name.
- Should resolve to the connecting IP.
Fix the sending system
Set the mail server hostname or HELO override to a fully-qualified name under your domain, publish an A record for it pointing at the sending IP, and arrange a matching PTR. Restart the service and verify with the reverse DNS and HELO auditor.
Applications and appliances
Look for a hostname or HELO field in the SMTP settings. If there is none, route the device through a properly configured relay rather than letting it speak SMTP directly.
Best diagnostic path
Mail Failure Doctor
Classify the complete rejection and preserve provider-specific diagnostic context.
Open analysis → Live analysisReverse DNS & HELO Auditor
Check reverse identity, forward confirmation and SMTP greeting consistency.
Open analysis → Live analysisEmail Infrastructure Digital Twin
Map the domain’s public mail infrastructure and provider relationships before remediation.
Open analysis →Known limits
- Enforcement varies; many receivers accept poor HELOs and score them instead.
- The rejection may cite 504 5.5.2 instead of 554 5.7.1 depending on the MTA.
Common questions
Does HELO need to equal the PTR name?
Not required, but matching HELO, PTR and forward DNS is what receivers reward.
Can I use an IP address in HELO?
Only as a bracketed address literal, and many receivers still reject it. Use a hostname.
Why only some receivers reject?
Strictness is a receiver choice. Fixing HELO improves acceptance everywhere.
Why the exact message matters
The same status family can be triggered by different conditions, and providers frequently add diagnostic text that narrows the issue. Use the complete rejection text rather than treating the numeric code as a complete diagnosis.
Provider reference
For the provider-defined meaning and current requirements, review RFC 5321 §4.1.1.1 — HELO/EHLO.