WarmHawk
Bounce codes · Permanent

5.7.708: Access denied, traffic not accepted from this IP

Microsoft 365 returns 5.7.708 when most of the outbound traffic from your tenant has been classified as suspicious, so Microsoft bans the tenant from sending. It is common on new tenants that send cold email at volume. Resolve any compromised accounts or open relays, then contact Microsoft support to lift the ban.

The exact message

Microsoft 365 / Exchange Online

5.7.708 Access denied, traffic not accepted from this IP

Why it happens

How to fix it

  1. Check every mailbox in the tenant for compromise; reset credentials and enable MFA.
  2. Stop all bulk and outreach sending from the tenant.
  3. Open a support request with Microsoft through the admin center and ask for an IP address exception; the block is lifted on their side.
  4. When sending resumes, start low and ramp slowly.

Real experience

We hit 5.7.708 ourselves

In September 2026 our own warmup started bouncing. A mailbox on a brand-new Microsoft 365 tenant, on a paid Exchange Online license and not a trial, was warming up with a Google Workspace mailbox. Some of its sends came back with 550 5.7.708 Access denied, traffic not accepted from this IP. Others, sent the same day to the same Google-hosted recipients, landed in the inbox.

Nothing on our side was wrong: SPF passed, DKIM was signed and DMARC was published. Microsoft’s message trace showed the failed sends had left through different Microsoft outbound servers than the delivered ones, which matches Microsoft’s own explanation that 5.7.708 comes from low-reputation IP addresses and mostly hits new customers. No DNS change fixes that. The only route is a support ticket asking for an IP address exception, which we opened.

It also exposed a gap in WarmHawk. The bounce notice lands in the sender’s mailbox, but warmup only looked in the recipient’s inbox and spam folders, so it logged those emails as missing. Warmup now reads the sender’s mailbox for the bounce notice, so a 5.7.708 shows up as bounced, with Microsoft’s reason, within about two hours of the send.

If you send cold email

Buying a fresh Microsoft 365 tenant and loading dozens of mailboxes into a cold email tool on day one is a common path to 5.7.708. The ban is tenant-wide, so every mailbox in that tenant stops at once.

How WarmHawk handles it

WarmHawk pauses a mailbox on its own once its hard-bounce rate passes 5% over at least 20 sends, and pauses a campaign at that campaign’s own bounce threshold, so a bad list stops before it drags the domain down. Every sending domain is re-checked against DNS blocklists hourly, and a mailbox only reaches campaign volume after at least 14 days of warmup with a 90% inbox rate. A mailbox whose inbox rate falls below 70% goes back to warmup. How WarmHawk works →

Check your domain now

These free checkers read your live DNS: no account, up to 15 domains at once.

Related bounce codes

Sources, checked 2026-09-29: Microsoft Learn: NDRs and SMTP errors in Exchange Online · Microsoft Learn: Fix error codes 5.7.700 through 5.7.750. Have a different bounce? Paste it into the decoder →

Questions

5.7.708 questions

What does 5.7.708 mean?+

Microsoft 365 returns 5.7.708 when most of the outbound traffic from your tenant has been classified as suspicious, so Microsoft bans the tenant from sending. It is common on new tenants that send cold email at volume. Resolve any compromised accounts or open relays, then contact Microsoft support to lift the ban.

Is 5.7.708 a temporary or permanent error?+

Permanent. The message will not be retried, and sending it again unchanged will fail the same way until the cause is fixed.

How do I fix 5.7.708?+

Check every mailbox in the tenant for compromise; reset credentials and enable MFA. Stop all bulk and outreach sending from the tenant. Open a support request with Microsoft through the admin center and ask for an IP address exception; the block is lifted on their side. When sending resumes, start low and ramp slowly.