Error codes

550 5.7.515 Microsoft: "Access denied, sending domain does not meet the required authentication level"

Last updated 2026-10-09

What Microsoft says

550 5.7.515 Access denied, sending domain <domain> does not meet the required authentication level.

Cause, as Microsoft states it:

The sender's domain in the 5322.From address doesn't meet the authentication requirements defined for the sender.

Microsoft applies this to senders of 5,000 or more messages to its consumer mail services from the same From domain, and lists three requirements: both SPF and DKIM must pass; a DMARC record must exist at _dmarc with p=reject, p=quarantine or p=none; and the message must pass DMARC, meaning SPF or DKIM aligns with the From domain.

Source: Microsoft, Fix NDR error 550 5.7.515 in Outlook.com, fetched 2026-10-08.

What it means, in plain words

The From domain of the rejected message failed at least one of the three: SPF pass, DKIM pass, DMARC pass with alignment. Unlike Gmail's codes, Microsoft names one error for all three, so you check all three.

Check your own domain

SPF:

dig +short TXT yourdomain.com | grep v=spf1

DKIM (selector from the message's DKIM-Signature s= value):

dig +short TXT selector._domainkey.yourdomain.com

DMARC:

dig +short TXT _dmarc.yourdomain.com

Then paste the rejected message's headers into the header analyzer and read which of spf, dkim and dmarc did not pass.

The fix

  • Both SPF and DKIM have to pass, so a domain that relies on one of them fails this check.
  • Publish a DMARC record with a p= tag if none exists; v=DMARC1; p=none meets the requirement.
  • Alignment: the domain that passed SPF (envelope sender) or DKIM (d= in the signature) must match the From domain, or be a subdomain of it under relaxed alignment. A sending service signing with its own domain does not align; use the service's custom DKIM for your domain.

This error is live on your domain right now. If you need it gone today, the Humerly Emergency Fix is the direct route: your DNS, every change on your approval, verified before we call it done. Details and the price are on the Emergency Fix page.

Request the fix

What this page covers: the authentication records the receiver checked and how to correct them. It does not predict where a message lands once accepted; authentication and inbox placement are separate questions.

FAQ

I send fewer than 5,000. Why did I get 5.7.515?

Microsoft's page states the threshold at which the requirement applies. If your volume is below it, check whether another sender shares your From domain, since the count is per domain, not per tool.

My DMARC is p=none. Is that the problem?

No. Microsoft's page lists p=none as acceptable. The requirement is that the record exists and that the message passes DMARC.

SPF passes and DKIM fails. Is that enough?

Not for this error. Microsoft requires both to pass.

Related