Outlook.com bounced your mail because your domain doesn’t meet Microsoft’s sender authentication rules. Check your SPF, DKIM and DMARC records below, then fix whatever is missing with the steps for your mail provider.
Last verified 29 September 2026.
The bounce reads:
550 5.7.515 Access denied, sending domain [domain] does not meet the required authentication level.
It comes from Microsoft’s consumer inboxes: Outlook.com, Hotmail, Live and MSN addresses. Since May 5, 2025, Microsoft rejects mail from domains that send 5,000 or more messages a day to those inboxes when the mail doesn’t pass its authentication checks. The domain it names is the one in your From: address. A 5xx code is a permanent rejection: resending the same message without fixing the records gets the same bounce.
Enter the domain in your From: address. The lookups run in your browser against public DNS.
What this can and can’t tell you: it reads the records your domain publishes. It can’t prove that a particular message passed, because SPF depends on the server that sent it and alignment depends on the domains in that message. DKIM keys can’t be listed from DNS, only probed by selector name, so the checker tries common selectors and can’t see which one your mail actually uses. If it finds no key, look for s= in the DKIM-Signature header of a message you sent: that’s your selector. For the full A–F grade with MTA-STS, BIMI and DNSSEC, use the DMARC checker.
Microsoft’s high-volume sender announcement and its support page for this error set three conditions for domains over the threshold:
p=none is enough; Microsoft’s own example is v=DMARC1; p=none.That is stricter than Gmail, which requires every sender to pass SPF or DKIM and requires bulk senders to set up both. Microsoft says both must pass, so don’t rely on DMARC passing through DKIM alone.
SPF is one TXT record on your domain, starting v=spf1, that lists every service allowed to send for it. Keep exactly one SPF record; two is a permerror and SPF fails for everything. The whole record, includes and all, may need at most 10 DNS lookups. Past that it also fails (see fixing “too many DNS lookups”).
include:spf.protection.outlook.com.include:_spf.google.com.For a domain that sends with both Microsoft 365 and Google Workspace, one record covers both: v=spf1 include:spf.protection.outlook.com include:_spf.google.com -all.
DKIM must sign with your domain (d=yourdomain.com in the signature), not your provider’s. A message signed only with the provider’s shared domain can pass DKIM but doesn’t align with your From: address.
selector1._domainkey and selector2._domainkey), then turn on “Sign messages for this domain with DKIM signatures”.google, so the name is google._domainkey), then click Start authentication.s1._domainkey and s2._domainkey) and verify.k2._domainkey and k3._domainkey).Any other service that sends as your domain (your CRM, help desk, invoicing tool) needs the same: its own DKIM record under your domain.
Add one TXT record at _dmarc.yourdomain.com:
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
p=none satisfies Microsoft, Gmail and Yahoo. The rua address receives daily aggregate reports showing which servers send as your domain and whether they pass, which is how you find the service you forgot. Publish only one DMARC record; with two, receivers ignore DMARC. Once the reports show all your mail passing, move to p=quarantine and then p=reject.
Microsoft’s threshold is 5,000 or more messages a day to its consumer inboxes, counted per From: domain. Senders on Microsoft Q&A report domains that kept getting 5.7.515 after their volume dropped below it, apparently because they had crossed the threshold before. Microsoft hasn’t confirmed this. Either way the fix is the same: make your mail pass SPF, DKIM and DMARC.
Gmail rejects the same authentication failures with its own codes (wording shortened from Google’s SMTP error reference):
550 5.7.26 | Three variants. “The sender is unauthenticated”: neither SPF nor DKIM passed. “The MAIL FROM domain has an SPF record with a hard fail policy (-all)”: the sending IP isn’t in an SPF record that ends in -all. “Not accepted due to domain’s DMARC policy”: DMARC failed and the policy is quarantine or reject. |
|---|---|
550 5.7.27 | The message didn’t pass SPF authentication. |
550 5.7.30 | The message didn’t pass DKIM authentication. |
4.7.32 / 5.7.32 | The From: domain isn’t aligned with the domain SPF or DKIM authenticated. Google lists it as 421 4.7.32, a temporary deferral (rate limiting), and as 550 5.7.32, a block. |
550 5.7.40 | The sending domain has no DMARC record, or its record has no policy (p=). |
See Gmail, Yahoo and Microsoft bulk sender requirements for the full side-by-side list, including one-click unsubscribe and spam-rate limits.
| February 2024 | Gmail and Yahoo start enforcing their bulk sender rules: SPF, DKIM and DMARC for senders of about 5,000 messages a day. |
|---|---|
| May 5, 2025 | Microsoft starts enforcing SPF, DKIM and DMARC for high-volume senders to Outlook.com, Hotmail and Live, rejecting non-compliant mail with 550 5.7.515. |
| November 2025 | Gmail ramps up enforcement on non-compliant traffic, including temporary and permanent rejections. |
| May 2026 | The IETF publishes the updated DMARC standard as RFC 9989, with RFC 9990 (aggregate reports) and RFC 9991 (failure reports), replacing RFC 7489. Existing v=DMARC1 records keep working. |
p=none enough for Outlook.com?Yes. Microsoft’s own example record is v=DMARC1; p=none. The record needs a valid p= tag (none, quarantine or reject), and your messages must pass DMARC, which means SPF or DKIM has to pass for a domain that aligns with your From: address. SPF and DKIM must both pass as well.
A DNS check shows the records are published, not that a given message passed. The usual causes: one of your sending services isn’t in your SPF record or signs DKIM with its own domain instead of yours, so nothing aligns with your From: address; your SPF record goes over 10 DNS lookups and fails with a permerror; or DKIM fails on some messages. Open the headers of a message delivered to an Outlook.com or Gmail address and read the Authentication-Results line: spf, dkim and dmarc should all say pass.
Microsoft’s requirement covers its consumer services: Outlook.com, Hotmail.com, Live.com and MSN. Mail to a company that hosts its mailboxes on Microsoft 365 goes through that organisation’s own filtering settings instead.
Once the new records are visible in public DNS, usually within minutes to a few hours depending on the record’s TTL. Receivers check authentication on every message, so the next message you send is judged on the new records. Run the checker on this page again before you resend.
If you manage sending domains for clients or brands, Email Security Signals runs the same checks on a whole list and returns one row per domain with SPF, DKIM, DMARC, an A–F grade and a bulkSenderCompliant field, ready to export as CSV. $0.02 per graded domain ($20 per 1,000); invalid inputs, domains that don’t exist, DNS lookup failures and duplicates are free.