550 5.7.515

Microsoft rejected your email because your domain is not authenticated. Here is the fix.

Since May 2025, Microsoft enforces sender authentication for mail to Outlook, Hotmail and Live addresses: senders over 5,000 messages a day must pass SPF, DKIM and DMARC, and non-compliant mail is rejected or junked. If you got this bounce, at least one of the three is missing or failing for your domain. The fix is in your DNS.

The bounce looks like this

550 5.7.515 Access denied, sending domain example.com does not
meet the required authentication level. The sender's domain in
the 5322.From address does not pass either SPF or DKIM validation.

Microsoft checks the domain in the From header your recipients see (RFC 5322.From) - not the technical envelope sender. That distinction is what trips up most senders using third-party platforms.

First: check what Microsoft sees for your domain

Run a free scan of your DMARC, SPF and DKIM records. It takes seconds and shows exactly which requirement you are failing.

Free. No signup. Checks DMARC, SPF, DKIM and MX in seconds.

How to fix it, step by step

  1. 1

    Publish SPF for every sending service

    Your SPF record must include every platform that sends mail as your domain. One missing include and mail from that platform fails. Keep exactly one SPF record and stay under the 10 DNS lookup limit - either mistake invalidates the whole record.

  2. 2

    Enable DKIM with your own domain

    Turn on DKIM in each sending service and publish the DNS records they give you, so messages are signed as your domain rather than the vendor's shared identity. Microsoft wants the signature to align with the From domain.

  3. 3

    Publish a DMARC record - p=none is enough to start

    Microsoft requires at least v=DMARC1; p=none with a rua reporting address. Without any DMARC record, compliant SPF and DKIM still fail the requirement. Collect reports at p=none first, then tighten to quarantine or reject.

  4. 4

    Check alignment, not just pass

    SPF or DKIM must pass for the same domain that appears in the From header. A newsletter platform passing SPF for its own bounce domain does nothing for you unless DKIM is signed with your domain. Alignment failures look like passes in vendor dashboards and still bounce at Microsoft.

Related guides

Managing this for multiple client domains?

If you are an MSP or agency, this bounce is now a recurring support ticket across your whole client base. DMARC Fleet is building continuous monitoring with per-client white-label reports - transparent pricing from $29/mo for 10 domains. Join the waitlist.