554 5.7.1 message rejected: blocklists, reverse DNS and relay errors
A policy rejection with four usual reasons: a blocklisted IP, missing reverse DNS, failed authentication or relay denied. How to tell which and fix it.
· 4 min read · By the Spot Downtime team
554 5.7.1 (and its cousin 550 5.7.1) is a mail server refusing your message on policy. The address exists, and the server is working; it just decided not to accept mail from you. The text after the code is the important part, because it says which policy:
554 5.7.1 Service unavailable; Client host [203.0.113.25] blocked using zen.spamhaus.org
550 5.7.1 Message rejected as spam by Content Filtering
554 5.7.1 <[email protected]>: Relay access denied
550 5.7.1 Unfortunately, messages from [203.0.113.25] weren't sent... part of their network is on our block list (S3150)The four usual reasons
1. Your sending IP is on a blocklist
The message names a list such as Spamhaus, or Microsoft's S3150. It happens when a compromised account or website on your server sent spam, or when a shared IP inherited a bad reputation.
- Find and stop the source of spam first: a hacked mailbox, a contact form being abused, malware on a web server.
- Then request delisting on the blocklist's own site. Most remove clean IPs quickly once the problem is fixed.
2. Missing or mismatched reverse DNS
Many servers reject mail from IPs without a PTR record, or whose PTR name doesn't resolve back to the same IP. Set the PTR record with your hosting provider (it's on their side, not in your domain's DNS) to a hostname that resolves to the IP.
3. Authentication failures
Failing SPF, DKIM or DMARC can also come back as 5.7.1 on some servers. Check all three records, and that every service sending as your domain is set up.
SPF, DKIM & DMARC checkerCheck a domain's email authentication records and find out what's broken.4. Relay access denied
A different problem: your mail client or app is trying to send through a server that won't relay for it. Usually SMTP authentication is off, or the app connects to the wrong server or port. Turn on SMTP auth with a username and password, on port 587.
Content filtering
“Rejected as spam” without a blocklist means the message itself scored badly: link shorteners, a domain with poor reputation in a link, misleading subject lines, or an attachment type the server blocks. Test with a plain message to see whether the content or the sender is the problem.
Check the receiving side too
Related: 550 5.7.26 (unauthenticated email) and SPF, DKIM and DMARC explained.
Keep reading
- Email errors · Email550 5.7.26: fix Gmail's 'unauthenticated email' bounceGmail rejects mail that fails SPF, DKIM or DMARC. How to find which check failed, the usual causes, and what Gmail, Yahoo and Outlook now require.October 5, 2026 · 4 min read
- Email errors · Email550 5.1.1 user unknown: why email bounces and what to doThe mailbox doesn't exist. How to read email error codes, what to check as the sender, and what to fix when real addresses on your domain bounce.October 5, 2026 · 3 min read