5.1.8: Access denied, bad outbound sender
Microsoft 365 returns 5.1.8 when your account has been blocked from sending because it sent too much spam. Microsoft says this usually means the account was compromised by phishing or malware. Secure the account first, then an admin must release it from the restricted entities list.
The exact message
Microsoft 365 / Exchange Online
5.1.8 Access denied, bad outbound sender
Why it happens
- Compromised credentials used to send spam.
- The account exceeded outbound spam thresholds from legitimate but unsolicited volume.
How to fix it
- Reset the password, revoke sessions and enable MFA.
- Remove any forwarding or inbox rules you did not create.
- Have an admin release the user in the Microsoft Defender portal (Restricted entities).
If you send cold email
Outreach volume from one Microsoft 365 mailbox can trip outbound spam limits without any compromise. Keep per-mailbox daily sends low and spread volume across mailboxes and domains.
How WarmHawk handles it
WarmHawk sends through your own Google Workspace or Microsoft 365 mailboxes. When the provider stops accepting a mailbox’s sign-in (approval removed, password reset, no Exchange Online license), WarmHawk marks that mailbox as needing a reconnect and says why, instead of showing it as connected while every send fails. How WarmHawk works →
Check your domain now
These free checkers read your live DNS: no account, up to 15 domains at once.
Related bounce codes
- 5.7.501Access denied, spam abuse detected (banned sender)
- 5.1.90Daily recipient limit reached
- 5.2.2Mailbox full, or submission quota exceeded
Sources, checked 2026-09-29: Microsoft Learn: NDRs and SMTP errors in Exchange Online. Have a different bounce? Paste it into the decoder →
Questions
5.1.8 questions
What does 5.1.8 mean?+
Microsoft 365 returns 5.1.8 when your account has been blocked from sending because it sent too much spam. Microsoft says this usually means the account was compromised by phishing or malware. Secure the account first, then an admin must release it from the restricted entities list.
Is 5.1.8 a temporary or permanent error?+
Permanent. The message will not be retried, and sending it again unchanged will fail the same way until the cause is fixed.
How do I fix 5.1.8?+
Reset the password, revoke sessions and enable MFA. Remove any forwarding or inbox rules you did not create. Have an admin release the user in the Microsoft Defender portal (Restricted entities).