5.7.23: Rejected for an SPF violation (Microsoft)
Exchange Online returns 5.7.23 when the receiving organization validates SPF and your message failed it. In practice the server that sent your mail is not authorized in your domain’s SPF record, or the record is broken. Fix SPF on the sending domain; the recipient cannot fix this for you.
The exact message
Microsoft 365 / Exchange Online
5.7.23 The message was rejected because of Sender Policy Framework violation
Why it happens
- The sending server is not listed in the SPF record.
- The SPF record uses -all and the message came from an unlisted source.
- Duplicate SPF records or too many DNS lookups make SPF evaluation fail.
How to fix it
- Check the domain’s SPF record and add the missing sender.
- Keep a single SPF record and 10 or fewer DNS lookups.
- Make sure DKIM also passes, so DMARC can still pass if SPF breaks on forwarding.
If you send cold email
When one prospect’s Microsoft 365 tenant rejects you with 5.7.23 and others do not, the recipient has a stricter SPF rule. Your record is still the thing to fix.
How WarmHawk handles it
WarmHawk checks SPF, DKIM and DMARC for each sending domain against live DNS and keeps "could not check" separate from "failed", so a flaky resolver never looks like a broken record. New mailboxes warm up by sending to partner inboxes and recording where each email landed, so an authentication problem shows up in the warmup results before the mailbox graduates to campaigns. How WarmHawk works →
Check your domain now
These free checkers read your live DNS: no account, up to 15 domains at once.
Related bounce codes
Sources, checked 2026-09-29: Microsoft Learn: NDRs and SMTP errors in Exchange Online. Have a different bounce? Paste it into the decoder →
Questions
5.7.23 questions
What does 5.7.23 mean?+
Exchange Online returns 5.7.23 when the receiving organization validates SPF and your message failed it. In practice the server that sent your mail is not authorized in your domain’s SPF record, or the record is broken. Fix SPF on the sending domain; the recipient cannot fix this for you.
Is 5.7.23 a temporary or permanent error?+
Permanent. The message will not be retried, and sending it again unchanged will fail the same way until the cause is fixed.
How do I fix 5.7.23?+
Check the domain’s SPF record and add the missing sender. Keep a single SPF record and 10 or fewer DNS lookups. Make sure DKIM also passes, so DMARC can still pass if SPF breaks on forwarding.