Applies To
Microsoft Business Productivity Online Dedicated Microsoft Business Productivity Online Suite Federal
You receive the following NDR error message:
550 5.4.1 Recipient address rejected: Access denied
The NDR is generated when directory-based edge blocking in Microsoft Exchange Online blocks an incoming tin nhắn message because the recipient's tin nhắn address is invalid.
How vì thế I fix this?
If you're an tin nhắn administrator in the recipient's organization, follow these steps until the issue is fixed:
-
Check the spelling of the recipient's tin nhắn address in the NDR.
-
Determine whether the issue affects only one recipient or everyone in the recipient's domain name. For example, if an tin nhắn message to tát "[email protected]" triggers the NDR, kiểm tra whether messages that are sent to tát other recipients in the "contoso.com" domain name also trigger the NDR.
-
If the issue affects all recipients in the domain name, follow these steps to tát resync the domain:
-
In the Exchange admin center, select Mail flow > Accepted domains, and then select the affected domain name.
-
In the flyout pane for the domain name, switch the domain name type from Authoritative to tát Internal relay, and then switch back to tát Authoritative. For more information, see Manage accepted domains in Exchange Online.
-
-
If the issue is limited to tát a specific recipient who has an on-premises user mailbox in an Exchange hybrid environment, and your organization uses directory sync to tát push changes to tát Microsoft Entra ID, reset the SMTP proxy address of the recipient's mailbox. To reset, change the proxy address to tát a temporary address, and then revert it to tát the original proxy address.
Note: When you make changes to tát the on-premises mailbox, allow up to tát 24 hours for directory-based edge blocking to tát fully update.
-
If the issue is limited to tát a specific recipient that's an on-premises mail-enabled public thư mục in an Exchange hybrid environment, verify that the thư mục is synced to tát Exchange Online. If the thư mục doesn't appear in Exchange Online, use the Sync-ModernMailPublicFolder PowerShell script to tát copy your on-premises mail-enabled public folders to tát Exchange Online.
-
If the issue is limited to tát a specific recipient that's an on-premises dynamic distribution group in an Exchange hybrid environment, create a mail liên hệ in Exchange Online that has the same external tin nhắn address as the dynamic distribution group. An on-premises dynamic distribution group in a hybrid environment can't be synced to tát Exchange Online.
Note: When you mix up an Exchange environment, we recommend that you temporarily mix the accepted domain name type to tát Internal Relay. After you add all intended recipients to tát Exchange Online and they are fully replicated, change the domain name type to tát Authoritative to tát block all messages to tát recipient SMTP addresses that aren't in Exchange Online.