550 5.7.515: High-volume sender fails Outlook.com authentication requirements
Outlook.com returns 5.7.515 when a domain sending 5,000 or more messages to Microsoft consumer mailboxes does not meet its authentication bar: SPF and DKIM must both pass, a DMARC record must exist, and at least one of SPF or DKIM must align with the From: domain.
The exact message
Outlook.com / Hotmail
550 5.7.515 Access denied, sending domain <domain> does not meet the required authentication level.
Why it happens
- DKIM is missing or failing while SPF passes; Outlook.com requires both to pass.
- No DMARC record, or a DMARC record without a valid p= policy.
- Neither SPF nor DKIM aligns with the domain in the From: address.
How to fix it
- Publish SPF and DKIM, and confirm both pass in a test message header.
- Publish a DMARC record with at least p=none.
- Make sure DKIM signs with the From: domain, or the return-path uses it.
If you send cold email
The 5,000-message threshold counts all mail to Hotmail, Outlook.com and Live addresses from the same From: domain. Spreading volume across several properly authenticated domains is normal; spreading it across unauthenticated ones is not a workaround.
How WarmHawk handles it
WarmHawk checks SPF, DKIM and DMARC for each sending domain against live DNS and keeps "could not check" separate from "failed", so a flaky resolver never looks like a broken record. New mailboxes warm up by sending to partner inboxes and recording where each email landed, so an authentication problem shows up in the warmup results before the mailbox graduates to campaigns. How WarmHawk works →
Check your domain now
These free checkers read your live DNS: no account, up to 15 domains at once.
Related bounce codes
- 5.7.509DMARC failed and the policy is reject (Microsoft)
- 5.7.40No DMARC record, or no DMARC policy
- 5.7.26Unauthenticated sender (no SPF or DKIM pass)
Sources, checked 2026-09-29: Microsoft Support: Fix NDR error 550 5.7.515 in Outlook.com. Have a different bounce? Paste it into the decoder →
Questions
5.7.515 questions
What does 5.7.515 mean?+
Outlook.com returns 5.7.515 when a domain sending 5,000 or more messages to Microsoft consumer mailboxes does not meet its authentication bar: SPF and DKIM must both pass, a DMARC record must exist, and at least one of SPF or DKIM must align with the From: domain.
Is 5.7.515 a temporary or permanent error?+
Permanent. The message will not be retried, and sending it again unchanged will fail the same way until the cause is fixed.
How do I fix 5.7.515?+
Publish SPF and DKIM, and confirm both pass in a test message header. Publish a DMARC record with at least p=none. Make sure DKIM signs with the From: domain, or the return-path uses it.