554 5.7.1 message rejected: blocklists, reverse DNS and relay errors

A policy rejection with four usual reasons: a blocklisted IP, missing reverse DNS, failed authentication or relay denied. How to tell which and fix it.

· 4 min read · By the Spot Downtime team

554 5.7.1 (and its cousin 550 5.7.1) is a mail server refusing your message on policy. The address exists, and the server is working; it just decided not to accept mail from you. The text after the code is the important part, because it says which policy:

text
554 5.7.1 Service unavailable; Client host [203.0.113.25] blocked using zen.spamhaus.org
550 5.7.1 Message rejected as spam by Content Filtering
554 5.7.1 <[email protected]>: Relay access denied
550 5.7.1 Unfortunately, messages from [203.0.113.25] weren't sent... part of their network is on our block list (S3150)

The four usual reasons

1. Your sending IP is on a blocklist

The message names a list such as Spamhaus, or Microsoft's S3150. It happens when a compromised account or website on your server sent spam, or when a shared IP inherited a bad reputation.

  • Find and stop the source of spam first: a hacked mailbox, a contact form being abused, malware on a web server.
  • Then request delisting on the blocklist's own site. Most remove clean IPs quickly once the problem is fixed.
IP & reverse DNS lookupCheck your mail server IP's reverse DNS (PTR) and which network owns it.

2. Missing or mismatched reverse DNS

Many servers reject mail from IPs without a PTR record, or whose PTR name doesn't resolve back to the same IP. Set the PTR record with your hosting provider (it's on their side, not in your domain's DNS) to a hostname that resolves to the IP.

3. Authentication failures

Failing SPF, DKIM or DMARC can also come back as 5.7.1 on some servers. Check all three records, and that every service sending as your domain is set up.

SPF, DKIM & DMARC checkerCheck a domain's email authentication records and find out what's broken.

4. Relay access denied

A different problem: your mail client or app is trying to send through a server that won't relay for it. Usually SMTP authentication is off, or the app connects to the wrong server or port. Turn on SMTP auth with a username and password, on port 587.

Content filtering

“Rejected as spam” without a blocklist means the message itself scored badly: link shorteners, a domain with poor reputation in a link, misleading subject lines, or an attachment type the server blocks. Test with a plain message to see whether the content or the sender is the problem.

Check the receiving side too

If you are the one rejecting legitimate mail with 5.7.1, look at your own spam filter's logs and allowlists. The MX lookup shows which provider or filter is receiving for your domain.

Related: 550 5.7.26 (unauthenticated email) and SPF, DKIM and DMARC explained.

Keep reading