WarmHawk
Bounce codes · Permanent

5.7.23: Rejected for an SPF violation (Microsoft)

Exchange Online returns 5.7.23 when the receiving organization validates SPF and your message failed it. In practice the server that sent your mail is not authorized in your domain’s SPF record, or the record is broken. Fix SPF on the sending domain; the recipient cannot fix this for you.

The exact message

Microsoft 365 / Exchange Online

5.7.23 The message was rejected because of Sender Policy Framework violation

Why it happens

How to fix it

  1. Check the domain’s SPF record and add the missing sender.
  2. Keep a single SPF record and 10 or fewer DNS lookups.
  3. Make sure DKIM also passes, so DMARC can still pass if SPF breaks on forwarding.

If you send cold email

When one prospect’s Microsoft 365 tenant rejects you with 5.7.23 and others do not, the recipient has a stricter SPF rule. Your record is still the thing to fix.

How WarmHawk handles it

WarmHawk checks SPF, DKIM and DMARC for each sending domain against live DNS and keeps "could not check" separate from "failed", so a flaky resolver never looks like a broken record. New mailboxes warm up by sending to partner inboxes and recording where each email landed, so an authentication problem shows up in the warmup results before the mailbox graduates to campaigns. How WarmHawk works →

Check your domain now

These free checkers read your live DNS: no account, up to 15 domains at once.

Related bounce codes

Sources, checked 2026-09-29: Microsoft Learn: NDRs and SMTP errors in Exchange Online. Have a different bounce? Paste it into the decoder →

Questions

5.7.23 questions

What does 5.7.23 mean?+

Exchange Online returns 5.7.23 when the receiving organization validates SPF and your message failed it. In practice the server that sent your mail is not authorized in your domain’s SPF record, or the record is broken. Fix SPF on the sending domain; the recipient cannot fix this for you.

Is 5.7.23 a temporary or permanent error?+

Permanent. The message will not be retried, and sending it again unchanged will fail the same way until the cause is fixed.

How do I fix 5.7.23?+

Check the domain’s SPF record and add the missing sender. Keep a single SPF record and 10 or fewer DNS lookups. Make sure DKIM also passes, so DMARC can still pass if SPF breaks on forwarding.