outlook error

Outlook.com 550 SC-003 — Open Relay or Malware Host

Outlook.com rejected the connection because the sending IP appears to be an open relay, or is hosting malware or a compromised system.

What the bounce says

Exact wording as it appears in the rejection or NDR. Placeholders such as x.x.x.x and example.com stand for your own address and domain.

550 SC-003 Mail rejected by Outlook.com for policy reasons. Reasons for rejection may be related to IP/domain reputation problems, or the sending IP being an open relay or proxy. If you are not an email/network admin please contact your Email/Internet Service Provider for help.

SC-003 means Microsoft believes the sending IP is relaying mail for others or acting as a proxy — typically because abuse traversed it. Legitimate servers hit it after misconfiguration or compromise.

Reviewed 2026-09-08. Provider wording and requirements change; the provider reference below is authoritative.

Most common causes

  • The mail server accepts relay from anyone
  • A host on the IP is infected and sending spam
  • A web application is being abused to send mail
  • Proxy or VPN endpoint on the same IP used for abuse

What to verify next

  1. Test the server for open relay and close it
  2. Scan hosts on the IP for malware and compromised web apps
  3. Rotate credentials and secure the server
  4. Request delisting after the host is clean

Check for open relay

Test whether the server accepts mail from arbitrary senders to arbitrary recipients without authentication. Misconfigured relay restrictions, a wide trusted-network setting, or a web application form that sends to any address are the usual openings.

Also check for compromised web applications, outdated CMS plugins and weak SMTP credentials; attackers use them to send through your server without needing open relay.

  • Test relay restrictions from outside.
  • Audit web applications that can send mail.
  • Rotate SMTP credentials.

Clean and secure

Close the relay, patch or remove the abused application, rotate credentials, and confirm outbound queues are empty of abuse. Then verify PTR and HELO.

Delisting

Request review through sender support with evidence of the fix. Microsoft typically re-evaluates within days.

Best diagnostic path

Known limits

  • A proxy or VPN endpoint sharing the IP can cause the classification.
  • Microsoft’s scan results are not shared.

Common questions

How do I test for open relay?

From an external network, try sending to an external recipient without authenticating. A correct server refuses with relay access denied.

Nothing is open. Why SC-003?

Something on the IP sent abuse — a compromised app or account is the usual explanation.

Is a shared hosting IP affected?

Yes. Another customer’s compromise can list the shared IP.

Why the exact message matters

The same status family can be triggered by different conditions, and providers frequently add diagnostic text that narrows the issue. Use the complete rejection text rather than treating the numeric code as a complete diagnosis.

Provider reference

For the provider-defined meaning and current requirements, review Microsoft Outlook.com sender troubleshooting.