SMTP bounce codes explained
A bounce carries two codes: a three-digit reply code and, usually, an enhanced status code such as 5.1.1. The first digit says whether to retry. The enhanced code says why. The column that matters most is the last one: some permanent rejections are about you, not the recipient.
Basic reply codes (RFC 5321)
| Code | Type | Meaning | What to do |
|---|---|---|---|
421 | soft bounce | Service not available, closing the connection. | Retry with backoff. Suppress only if it keeps failing for days. Source |
450 | soft bounce | Mailbox unavailable right now, for example busy or temporarily blocked. | Retry with backoff. Suppress only if it keeps failing for days. Source |
451 | soft bounce | Local error in processing. The action was aborted. | Retry with backoff. Suppress only if it keeps failing for days. Source |
452 | soft bounce | Insufficient system storage. | Retry with backoff. Suppress only if it keeps failing for days. Source |
550 | hard bounce | Mailbox unavailable: not found, no access, or rejected for policy reasons. The enhanced code says which. | Read the enhanced code. 5.1.x means suppress, 5.7.x means fix the sender. Source |
551 | hard bounce | User not local. | Suppress the address. Retrying hurts your reputation. Source |
552 | hard bounce | Exceeded storage allocation. | Treat as a full mailbox. Suppress if it repeats. Source |
553 | hard bounce | Mailbox name not allowed, for example invalid syntax. | Suppress the address. Retrying hurts your reputation. Source |
554 | hard bounce | Transaction failed. A generic permanent rejection, often for policy. | Read the enhanced code and the text before suppressing. Source |
Enhanced status codes (RFC 3463 and later)
| Code | Type | Meaning | What to do |
|---|---|---|---|
4.2.2 | soft bounce | Mailbox full. | Retry with backoff. Suppress only if it keeps failing for days. Source |
4.4.1 | soft bounce | No answer from the receiving host. | Retry with backoff. Suppress only if it keeps failing for days. Source |
4.4.2 | soft bounce | Bad connection: the connection dropped during the transaction. | Retry with backoff. Suppress only if it keeps failing for days. Source |
4.7.0 | soft bounce | Other or undefined security status. Receivers use it for temporary blocks. | Retry with backoff and read the text: it often names a rate or reputation limit. Source |
5.1.1 | hard bounce | Bad destination mailbox address: the mailbox does not exist. | Suppress the address. Retrying hurts your reputation. Source |
5.1.2 | hard bounce | Bad destination system address: the domain does not exist or accepts no mail. | Suppress the address. Retrying hurts your reputation. Source |
5.1.3 | hard bounce | Bad destination mailbox address syntax. | Suppress the address. Retrying hurts your reputation. Source |
5.2.1 | hard bounce | Mailbox disabled, not accepting messages. | Suppress the address. Retrying hurts your reputation. Source |
5.2.2 | soft bounce | Mailbox full, reported as permanent. | Retry later. Suppress if it repeats over several days. Source |
5.2.3 | sender problem | Message length exceeds an administrative limit. | Send a smaller message, for example a link instead of an attachment. Source |
5.3.4 | sender problem | Message too big for the system. | Send a smaller message. Source |
5.7.1 | sender problem | Delivery not authorized, message refused. | Do not suppress the recipient. Fix your sending setup, then resend. Source |
5.7.20 | sender problem | No passing DKIM signature found. | Do not suppress the recipient. Fix your sending setup, then resend. Source |
5.7.21 | sender problem | No acceptable DKIM signature found. | Do not suppress the recipient. Fix your sending setup, then resend. Source |
5.7.22 | sender problem | No valid author-matched DKIM signature found. | Do not suppress the recipient. Fix your sending setup, then resend. Source |
5.7.23 | sender problem | SPF validation failed. | Do not suppress the recipient. Fix your sending setup, then resend. Source |
5.7.24 | sender problem | SPF validation error, for example too many DNS lookups. | Do not suppress the recipient. Fix your sending setup, then resend. Source |
5.7.25 | sender problem | Reverse DNS validation failed. | Do not suppress the recipient. Fix your sending setup, then resend. Source |
5.7.26 | sender problem | Multiple authentication checks failed. | Do not suppress the recipient. Fix your sending setup, then resend. Source |
5.1.10 | hard bounce | Recipient address has a null MX: its domain accepts no mail. | Suppress the address. Retrying hurts your reputation. Source |
5.7.27 | sender problem | Sender address has a null MX, so it cannot receive replies or bounces. | Do not suppress the recipient. Fix your sending setup, then resend. Source |
Provider-specific codes
| Code | Type | Meaning | What to do |
|---|---|---|---|
550 5.1.1 (Gmail) | hard bounce | The email account does not exist. | Suppress the address. Retrying hurts your reputation. Source |
452 4.2.2 (Gmail) | soft bounce | The account is over its storage quota. | Retry with backoff. Suppress only if it keeps failing for days. Source |
421 4.7.28 (Gmail) | soft bounce | Gmail detected an unusual rate of email from your IP, netblock or domain and is rate-limiting it. | Slow down and retry. Check spam rates in Postmaster Tools. Source |
550 5.7.1 (Gmail) | sender problem | The message was blocked as likely unsolicited. | Do not suppress the recipient. Fix your sending setup, then resend. Source |
550 5.7.26 (Gmail) | sender problem | The sender is unauthenticated: the message failed SPF and DKIM or failed DMARC. | Do not suppress the recipient. Fix your sending setup, then resend. Source |
TS* errors (Yahoo) | soft bounce | Message temporarily deferred: complaints from Yahoo users, spam-like content, a poorly rated IP or subnet, or unusual traffic. | Let your server retry, and fix the cause before volume goes back up. Source |
5.7.606–649 (Microsoft) | sender problem | Access denied, banned sending IP. | Check the IP for compromise or bad traffic, then request removal through Microsoft’s delist portal. Source |
The difference between the three types, and why a 5.7 rejection should never land an address on your suppression list, is in hard bounce vs soft bounce. If a code points at authentication, run the domain health check.
Questions
Is every 5xx code a hard bounce?
No. A 5xx code means the receiver will not accept the message as sent. When the enhanced code is in the 5.7 class, the rejection is about the sender’s authentication or reputation, so suppressing the recipient fixes nothing. Fix the sending setup and the same address accepts mail.
What is the difference between 550 and 5.1.1?
550 is the basic reply code from RFC 5321. 5.1.1 is the enhanced status code from RFC 3463 that follows it and says why: the mailbox does not exist.
Sources
- https://www.rfc-editor.org/rfc/rfc5321#section-4.2.3
- https://www.rfc-editor.org/rfc/rfc3463
- https://www.rfc-editor.org/rfc/rfc7372
- https://www.rfc-editor.org/rfc/rfc7505
- https://support.google.com/a/answer/3726730
- https://senders.yahooinc.com/smtp-error-codes/
- https://learn.microsoft.com/en-us/exchange/mail-flow-best-practices/non-delivery-reports-in-exchange-online/non-delivery-reports-in-exchange-online