554 5.7.1 error: why your email was rejected
554 5.7.1 means the recipient’s server rejected the email because of a security rule. The cause is often in the sender’s DNS: check it here.
- Free, no sign-up
- Public DNS records only
- Result in seconds
Want the step-by-step fixes?We email you the full report on SPF, DKIM, DMARC and MX, with the values to copy.
Done: the report reaches your inbox in a few minutes. If you don’t see it, check spam or Promotions too.
What 554 5.7.1 means
554 is a permanent rejection, 5.7.1 points to a permission or policy problem. The text after the code gives the reason: for example Relay access denied, Message rejected due to SPF, rejected by DMARC policy or a blocklist reference.
Always read the full text of the bounce message: that’s where the server explains what’s wrong.
554Permanent rejection: retrying won’t help until the cause is fixed.5.7.1A sender permission or security problem.the text after itIt often says why: SPF, DMARC, a blocklist or relaying not allowed.The most common causes and what to do
Relay access denied
The SMTP server doesn’t recognize you: check the username, password and port in your mail software, or that sending goes through the right server.
SPF fail
The server sending the email isn’t in the domain’s SPF record: add its include.
DMARC set to reject
The domain asks receivers to reject unsigned or unaligned email: turn on DKIM and fix SPF.
Blocklist
The IP or domain is listed: check the blocklists and request removal after fixing the cause.
Frequently asked questions
Why does it happen only with some recipients?
Every provider has its own rules: Microsoft and Gmail, for example, check SPF, DKIM and DMARC more strictly than others.
Should I contact the recipient?
Usually not: the fix is almost always on the sender’s side (DNS, sending server, reputation). If the message mentions an internal policy, only the recipient can change it.
My hosting sends my website emails and I get 554: what now?
The hosting’s shared IP is often missing from your SPF or has a poor reputation. A dedicated SMTP relay with DKIM on your domain fixes it at the root.
How long until it’s resolved?
After fixing the DNS records, usually a few hours. For blocklists it depends on the removal process.
More free checks
SPF checker
A single record, its ending, DNS lookups under the limit of 10.
OpenDKIM checker
Key on the most common selectors or yours, length and revocation.
OpenDMARC checker
Policy, reports address, inherited record.
OpenMX lookup
Who receives the mail, priorities and spam filters.
OpenFull DNS check
SPF, DKIM, DMARC and MX at once, with the report by email.
OpenFree DNS check API
JSON, no key, CORS enabled.
OpenDo your website or app emails still leave from the hosting server?
SMTP Senpai is the MailSenpai SMTP relay: it signs your emails with DKIM on your own domain, gives you the DNS records to publish and checks them for you. Servers and data in the EU.