WarmHawk
Bounce codes · Permanent

5.1.8: Access denied, bad outbound sender

Microsoft 365 returns 5.1.8 when your account has been blocked from sending because it sent too much spam. Microsoft says this usually means the account was compromised by phishing or malware. Secure the account first, then an admin must release it from the restricted entities list.

The exact message

Microsoft 365 / Exchange Online

5.1.8 Access denied, bad outbound sender

Why it happens

How to fix it

  1. Reset the password, revoke sessions and enable MFA.
  2. Remove any forwarding or inbox rules you did not create.
  3. Have an admin release the user in the Microsoft Defender portal (Restricted entities).

If you send cold email

Outreach volume from one Microsoft 365 mailbox can trip outbound spam limits without any compromise. Keep per-mailbox daily sends low and spread volume across mailboxes and domains.

How WarmHawk handles it

WarmHawk sends through your own Google Workspace or Microsoft 365 mailboxes. When the provider stops accepting a mailbox’s sign-in (approval removed, password reset, no Exchange Online license), WarmHawk marks that mailbox as needing a reconnect and says why, instead of showing it as connected while every send fails. How WarmHawk works →

Check your domain now

These free checkers read your live DNS: no account, up to 15 domains at once.

Related bounce codes

Sources, checked 2026-09-29: Microsoft Learn: NDRs and SMTP errors in Exchange Online. Have a different bounce? Paste it into the decoder →

Questions

5.1.8 questions

What does 5.1.8 mean?+

Microsoft 365 returns 5.1.8 when your account has been blocked from sending because it sent too much spam. Microsoft says this usually means the account was compromised by phishing or malware. Secure the account first, then an admin must release it from the restricted entities list.

Is 5.1.8 a temporary or permanent error?+

Permanent. The message will not be retried, and sending it again unchanged will fail the same way until the cause is fixed.

How do I fix 5.1.8?+

Reset the password, revoke sessions and enable MFA. Remove any forwarding or inbox rules you did not create. Have an admin release the user in the Microsoft Defender portal (Restricted entities).