5.7.509: DMARC failed and the policy is reject (Microsoft)
Microsoft returns 5.7.509 when the domain in your From: address fails DMARC and that domain publishes p=reject, so Microsoft honours the policy and rejects the message. Either SPF or DKIM must pass and align with the From: domain. Fix alignment; do not loosen the policy as the fix.
The exact message
Microsoft 365 / Exchange Online
5.7.509 Access denied, sending domain [$SenderDomain] does not pass DMARC verification and has a DMARC policy of reject.
Why it happens
- A third-party sending tool sends as your domain without DKIM signing for your domain.
- SPF passes only for the tool’s own bounce domain, so it does not align with your From: domain.
- Someone else is spoofing your domain, and DMARC is correctly stopping them.
How to fix it
- Set up DKIM for your domain in every service that sends as you.
- Confirm in a message header that dkim=pass header.d= matches your From: domain.
- Read your DMARC aggregate reports to find which sources are failing.
If you send cold email
Setting p=reject on a new outreach domain before DKIM is working will bounce every Microsoft-hosted prospect. Start at p=none, confirm alignment, then tighten.
How WarmHawk handles it
WarmHawk checks SPF, DKIM and DMARC for each sending domain against live DNS and keeps "could not check" separate from "failed", so a flaky resolver never looks like a broken record. New mailboxes warm up by sending to partner inboxes and recording where each email landed, so an authentication problem shows up in the warmup results before the mailbox graduates to campaigns. How WarmHawk works →
Check your domain now
These free checkers read your live DNS: no account, up to 15 domains at once.
Related bounce codes
- 5.7.32From: domain not aligned with SPF or DKIM
- 5.7.40No DMARC record, or no DMARC policy
- 5.7.515High-volume sender fails Outlook.com authentication requirements
Sources, checked 2026-09-29: Microsoft Learn: NDRs and SMTP errors in Exchange Online. Have a different bounce? Paste it into the decoder →
Questions
5.7.509 questions
What does 5.7.509 mean?+
Microsoft returns 5.7.509 when the domain in your From: address fails DMARC and that domain publishes p=reject, so Microsoft honours the policy and rejects the message. Either SPF or DKIM must pass and align with the From: domain. Fix alignment; do not loosen the policy as the fix.
Is 5.7.509 a temporary or permanent error?+
Permanent. The message will not be retried, and sending it again unchanged will fail the same way until the cause is fixed.
How do I fix 5.7.509?+
Set up DKIM for your domain in every service that sends as you. Confirm in a message header that dkim=pass header.d= matches your From: domain. Read your DMARC aggregate reports to find which sources are failing.