5.4.1: Relay access denied / recipient address rejected
Exchange Online returns 5.4.1 in two cases: "Recipient address rejected: Access denied" means the address does not exist and Directory Based Edge Blocking rejected it; "Relay Access Denied" means the server does not accept mail for that domain, usually from an MX or DNS misconfiguration.
The exact messages
Microsoft 365 / Exchange Online
5.4.1 Recipient address rejected: Access denied
Microsoft 365 / Exchange Online
5.4.1 Relay Access Denied
Why it happens
- The recipient address does not exist in the Microsoft 365 organization.
- The domain’s MX record points to Microsoft 365, but the domain is not set up there.
How to fix it
- "Recipient address rejected": remove the address; it is a hard bounce.
- "Relay Access Denied" on your own domain: check the MX record and accepted domains in Microsoft 365.
If you send cold email
For outreach, "Recipient address rejected: Access denied" is the most common Microsoft 365 hard bounce. Treat it exactly like 5.1.1.
How WarmHawk handles it
A hard bounce marks that lead as bounced and stops its sequence, and every bounce counts toward the mailbox’s bounce-rate breaker: at 5% over at least 20 sends, WarmHawk pauses the mailbox before a stale list can damage the domain. How WarmHawk works →
Check your domain now
These free checkers read your live DNS: no account, up to 15 domains at once.
Related bounce codes
Sources, checked 2026-09-29: Microsoft Learn: NDRs and SMTP errors in Exchange Online. Have a different bounce? Paste it into the decoder →
Questions
5.4.1 questions
What does 5.4.1 mean?+
Exchange Online returns 5.4.1 in two cases: "Recipient address rejected: Access denied" means the address does not exist and Directory Based Edge Blocking rejected it; "Relay Access Denied" means the server does not accept mail for that domain, usually from an MX or DNS misconfiguration.
Is 5.4.1 a temporary or permanent error?+
Permanent. The message will not be retried, and sending it again unchanged will fail the same way until the cause is fixed.
How do I fix 5.4.1?+
"Recipient address rejected": remove the address; it is a hard bounce. "Relay Access Denied" on your own domain: check the MX record and accepted domains in Microsoft 365.