What the bounce says
Exact wording as it appears in the rejection or NDR. Placeholders such as x.x.x.x and example.com stand for your own address and domain.
550 SC-002 Mail rejected by Outlook.com for policy reasons. The mail server IP connecting to Outlook.com has exhibited namespace mining behavior. If you are not an email/network admin please contact your Email/Internet Service Provider for help.
SC-002 is triggered by sending behaviour rather than content: Microsoft saw the IP attempting delivery to many addresses in a way that resembles guessing or harvesting mailboxes. Legitimate senders usually hit it through bad list hygiene or a compromised system.
Most common causes
- A burst of mail to many recipients in a short time
- Repeated sends to non-existent addresses
- A compromised account or script sending in a loop
- Traffic shaped like a spam run
What to verify next
- Look for a compromise or misbehaving automation on the sending host
- Review bounce rates and remove invalid recipients
- Reduce rate and spread sends over time
- Request review through Microsoft sender support once the pattern stops
What namespace mining looks like
A burst of RCPT TO commands for addresses that do not exist, or sends to large numbers of addresses in alphabetical or generated patterns. Microsoft interprets it as an attempt to discover valid mailboxes.
Real causes on legitimate infrastructure: an old list full of dead addresses, an application retrying invalid recipients, or a compromised account sending to a harvested list.
- Many attempts to invalid addresses.
- Compromise or list decay are the usual causes.
- Behaviour-based, so content changes do not help.
Stop the behaviour
Suppress addresses that bounced, validate lists before sending, and inspect the sending system for compromise. Reduce volume to Outlook.com until the pattern is gone.
Then request review
Submit the rejection to sender support after the cause is fixed. Requests made while the behaviour continues are declined.
Best diagnostic path
Mail Failure Doctor
Classify the complete rejection and preserve provider-specific diagnostic context.
Open analysis → Live analysisEmail Infrastructure Digital Twin
Map the domain’s public mail infrastructure and provider relationships before remediation.
Open analysis →Known limits
- Microsoft’s thresholds for this pattern are not published.
- A shared IP can be penalized for another tenant’s behaviour.
Common questions
We only send to opted-in users.
Then look for a compromised account or an application sending to invalid addresses on your IP.
How do I see bounce rates?
From your sending platform or mail logs; the rate of 5.1.1 responses is the relevant signal.
Will authentication fix it?
Authentication is necessary but this block is behavioural; the sending pattern must change.
Why the exact message matters
The same status family can be triggered by different conditions, and providers frequently add diagnostic text that narrows the issue. Use the complete rejection text rather than treating the numeric code as a complete diagnosis.
Provider reference
For the provider-defined meaning and current requirements, review Microsoft Outlook.com sender troubleshooting.