WarmHawk
Bounce codes · Permanent

5.4.1: Relay access denied / recipient address rejected

Exchange Online returns 5.4.1 in two cases: "Recipient address rejected: Access denied" means the address does not exist and Directory Based Edge Blocking rejected it; "Relay Access Denied" means the server does not accept mail for that domain, usually from an MX or DNS misconfiguration.

The exact messages

Microsoft 365 / Exchange Online

5.4.1 Recipient address rejected: Access denied

Microsoft 365 / Exchange Online

5.4.1 Relay Access Denied

Why it happens

How to fix it

  1. "Recipient address rejected": remove the address; it is a hard bounce.
  2. "Relay Access Denied" on your own domain: check the MX record and accepted domains in Microsoft 365.

If you send cold email

For outreach, "Recipient address rejected: Access denied" is the most common Microsoft 365 hard bounce. Treat it exactly like 5.1.1.

How WarmHawk handles it

A hard bounce marks that lead as bounced and stops its sequence, and every bounce counts toward the mailbox’s bounce-rate breaker: at 5% over at least 20 sends, WarmHawk pauses the mailbox before a stale list can damage the domain. How WarmHawk works →

Check your domain now

These free checkers read your live DNS: no account, up to 15 domains at once.

Related bounce codes

Sources, checked 2026-09-29: Microsoft Learn: NDRs and SMTP errors in Exchange Online. Have a different bounce? Paste it into the decoder →

Questions

5.4.1 questions

What does 5.4.1 mean?+

Exchange Online returns 5.4.1 in two cases: "Recipient address rejected: Access denied" means the address does not exist and Directory Based Edge Blocking rejected it; "Relay Access Denied" means the server does not accept mail for that domain, usually from an MX or DNS misconfiguration.

Is 5.4.1 a temporary or permanent error?+

Permanent. The message will not be retried, and sending it again unchanged will fail the same way until the cause is fixed.

How do I fix 5.4.1?+

"Recipient address rejected": remove the address; it is a hard bounce. "Relay Access Denied" on your own domain: check the MX record and accepted domains in Microsoft 365.