5.7.705: Access denied, tenant has exceeded threshold
Microsoft 365 returns 5.7.705 when most of your tenant’s outbound traffic has been detected as suspicious and the tenant has crossed Microsoft’s threshold, so sending is banned tenant-wide. Microsoft documents it alongside 5.7.708 with the same fix: clean up any compromise, then contact Microsoft support.
The exact message
Microsoft 365 / Exchange Online
5.7.705 Access denied, tenant has exceeded threshold
Why it happens
- Outbound spam from compromised accounts in the tenant.
- Bulk or outreach volume from a tenant with no sending history.
How to fix it
- Secure every account: reset passwords, enable MFA, review mailbox forwarding rules.
- Stop bulk sending from the tenant until the ban is lifted.
- Contact Microsoft support through your normal support channel.
If you send cold email
Same root cause as 5.7.708: too much external mail from a tenant Microsoft does not yet trust. Spreading outreach across more mailboxes in the same tenant does not help, because the threshold is per tenant.
How WarmHawk handles it
WarmHawk pauses a mailbox on its own once its hard-bounce rate passes 5% over at least 20 sends, and pauses a campaign at that campaign’s own bounce threshold, so a bad list stops before it drags the domain down. Every sending domain is re-checked against DNS blocklists hourly, and a mailbox only reaches campaign volume after at least 14 days of warmup with a 90% inbox rate. A mailbox whose inbox rate falls below 70% goes back to warmup. How WarmHawk works →
Check your domain now
These free checkers read your live DNS: no account, up to 15 domains at once.
Related bounce codes
- 5.7.708Access denied, traffic not accepted from this IP
- 5.7.750Blocked from sending from unregistered domains
- 5.1.8Access denied, bad outbound sender
Sources, checked 2026-09-29: Microsoft Learn: NDRs and SMTP errors in Exchange Online. Have a different bounce? Paste it into the decoder →
Questions
5.7.705 questions
What does 5.7.705 mean?+
Microsoft 365 returns 5.7.705 when most of your tenant’s outbound traffic has been detected as suspicious and the tenant has crossed Microsoft’s threshold, so sending is banned tenant-wide. Microsoft documents it alongside 5.7.708 with the same fix: clean up any compromise, then contact Microsoft support.
Is 5.7.705 a temporary or permanent error?+
Permanent. The message will not be retried, and sending it again unchanged will fail the same way until the cause is fixed.
How do I fix 5.7.705?+
Secure every account: reset passwords, enable MFA, review mailbox forwarding rules. Stop bulk sending from the tenant until the ban is lifted. Contact Microsoft support through your normal support channel.