Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

License Error 550 5.1.1

550 5.1.1 and 550 5.1.10: Exchange Online cannot find the recipient

11 min read Updated October 5, 2026 Microsoft 365 & Entra ID

Fix it now

550 5.1.1 is “Bad destination mailbox address” and 550 5.1.10 is “Recipient not found”: Exchange Online looked the address up and found nothing it will deliver to. Sometimes a typo. More often a leaver whose licence was pulled, taking the mailbox with it.

Run in Exchange Online PowerShell to see whether the address resolves at all

Get-Recipient -Identity leaver@contoso.com -ErrorAction SilentlyContinue
Get-Recipient -Identity leaver@contoso.com | Select Name,RecipientTypeDetails,EmailAddresses
  1. Copy the exact address out of the bounce. A single wrong character is still the commonest cause and the easiest to dismiss.
  2. If Get-Recipient returns nothing and the person has left, decide what the address should do now: a shared mailbox, an extra address on a colleague, or a clean retirement.
  3. To keep a leaver’s mailbox as a shared mailbox, the account must still hold a licence. Restore the account if it was deleted, licence it, wait for the mailbox to be re-created, then convert it – and leave the account in place afterwards.
  4. If only one internal sender fails, have them delete the suggestion from Outlook’s AutoComplete list and pick the recipient fresh from the address book.
  5. Read the diagnostic line. RESOLVER.ADR.ExRecipNotFound and 5.1.20 are different faults with different fixes – see the table below.

Deleting the user account after converting to a shared mailbox breaks the shared mailbox. The account anchors it.

If mail is being delivered again you can stop here. If not, the next section covers the several different failures that all arrive as 550.

Why it happens

When mail arrives for one of your domains, Exchange Online resolves the address against the directory. If the domain is authoritative – your tenant is the final destination for it – an address that does not exist is rejected immediately rather than forwarded anywhere. That is deliberate: it stops your tenant accepting and then bouncing mail for addresses that were never real, which is exactly what spammers exploit.

Microsoft’s own text for the two headline codes is worth having in front of you. 550 5.1.1 is “Bad destination mailbox address”, with four listed conditions: the sender mistyped it, the address does not exist in the destination system, the mailbox was moved and the sender’s Outlook cache did not update, or the recipient has an invalid legacy domain name. 550 5.1.10 is “Recipient not found”: SMTP address lookup did not find the address.

The leaver case generates most of these tickets. Remove a user’s licence and the mailbox enters a grace period, then is disabled and removed. Delete the account and it sits recoverable for around thirty days, then it is gone. Neither path leaves anything behind that will accept mail, so customers writing to that address start bouncing, usually without telling you.

Two of the codes here are not recipient-resolution failures at all, and reading them as such wastes an afternoon. 550 5.1.20 is “Multiple From addresses are not allowed without Sender address” – a message-format rejection to be fixed in the sending application. 550 5.7.504 is “Recipient address rejected: Access denied”, an authorisation refusal most usefully read as a delivery restriction on the recipient or group.

The mailbox belonged to a leaver and no longer exists

You have this one if The address worked historically, the person has left, and Get-Recipient returns nothing.

  1. Decide first whether the address should still receive mail at all.
  2. If the account was deleted, restore it from the admin centre, assign a Microsoft 365 licence, reset the password and allow up to 24 hours for the mailbox to be re-created.
  3. Convert it: Users, Active users, select the user, Mail tab, Convert to shared mailbox – or Set-Mailbox -Identity user@contoso.com -Type Shared. The mailbox must be licensed at the moment you convert.
  4. Remove the licence afterwards, and leave the user account in place: it anchors the shared mailbox.

An unlicensed shared mailbox is capped at 50 GB. If the content is larger than that, the licence that raises it to 100 GB is Exchange Online Plan 2, not Plan 1.

The user is unlicensed and the mailbox has lapsed

You have this one if The account still exists in the directory but holds no licence, and delivery started failing some weeks after the licence was removed.

  1. Check the licence assignment in the Microsoft 365 admin centre.
  2. If the mailbox is still within its retention window, assigning a licence again restores it with its contents.
  3. If the person has gone but the mailbox is needed, licence it, convert it to a shared mailbox and then remove the licence.
  4. Fix the offboarding process so licences are only removed once a decision about the mailbox has been recorded.

Outlook is holding a stale internal address

You have this one if RESOLVER.ADR.ExRecipNotFound in the bounce; only internal senders who have mailed the recipient before fail, and the address on screen looks correct.

  1. Have the sender start typing the address and remove the suggestion with the cross beside it, then pick the recipient fresh from the address book.
  2. If the mailbox was recreated or migrated, add its previous legacyExchangeDN to it as an X500 proxy address so old entries resolve again.
  3. Check the offline address book is downloading correctly, which Microsoft names as a third cause of this code.
  4. After a PST or third-party migration, add the X500 addresses in bulk rather than asking hundreds of users to clear entries by hand.

Microsoft attributes this specifically to migrations that do not correctly carry the X.500 distinguished name of the original recipients. PST migrations are the usual culprit.

Hybrid routing is missing the target address

You have this one if RESOLVER.ADR.RecipNotFound after a mailbox move to Exchange Online, generated by the on-premises Exchange server.

  1. Confirm the on-premises mail-enabled user representing the moved mailbox is stamped with the target routing address, in the form alias@contoso.mail.onmicrosoft.com.
  2. Add it through the Exchange admin centre, the Exchange Management Console or ADSI Edit, then allow directory synchronisation to run.
  3. Retest from an on-premises sender, which is the direction that fails.

This one is generated by the Exchange server, not by Outlook. The RESOLVER prefix comes from the transport categorizer, which is why clearing a client cache does nothing for it.

The message has more than one From address

You have this one if 550 5.1.20, usually from a mail-merge tool, a scanner or an application that builds its own headers.

  1. Fix the sending application so the message carries a single address in the From header, or add a single address in the Sender header.
  2. Stop looking for a deleted mailbox: this code says nothing about the recipient.

Full reference

Reading the bounce before you change anything

Code or diagnostic What Microsoft publishes Where the fix is
550 5.1.1 Bad destination mailbox address The recipient address or mailbox
550 5.1.10 Recipient not found – SMTP address lookup failed The recipient address or mailbox
550 5.1.20 Multiple From addresses are not allowed without Sender address The sending application’s headers
550 5.7.504 Recipient address rejected: Access denied Delivery restrictions on the recipient or group
RESOLVER.ADR.RecipNotFound The Exchange server could not resolve the recipient in the directory targetAddress on the on-premises mail-enabled user
RESOLVER.ADR.ExRecipNotFound The X.500 / legacyExchangeDN address could not be resolved An X500 proxy address, or the sender’s AutoComplete entry

Keeping a leaver’s address alive, properly

  1. Restore the user account from the admin centre if it has been deleted.
  2. Assign a Microsoft 365 licence and reset the password.
  3. Wait for the mailbox to be re-created – Microsoft allows up to 24 hours.
  4. Convert to a shared mailbox from the Mail tab, or with Set-Mailbox -Type Shared.
  5. Remove the licence from the account once the conversion has completed.
  6. Add the people who should read it as members of the shared mailbox.
  7. Leave the user account in place. Deleting it breaks the shared mailbox that depends on it.

Existing mail, calendar items and inbox rules are retained through the conversion. Microsoft also notes that the original username and password keep working against the shared mailbox unless you reset the password, which is a good reason to reset it as part of offboarding.

When it is a whole domain rather than one address

  • List the accepted domains on the tenant and check each one’s type against the way mail is meant to flow.
  • An authoritative domain rejects unknown recipients outright. A domain that relays on to another system must be configured as such, not left authoritative.
  • In hybrid, confirm the recipients exist in the directory the cloud can see, not only on-premises.
  • Retest from outside the organisation after any change. Internal resolution can succeed while external delivery still fails.

Checks that save the most time

  • Get-Recipient against the exact string from the bounce, not against what you think the address is.
  • Whether the failure is external-only, internal-only, or both. Internal-only points at a client cache or an X.500 address; external-only points at accepted domains or DNS.
  • Whether the recipient is a group. Groups have their own delivery restrictions, and “require that all senders are authenticated” is the commonest reason an external sender gets 5.7.504.
  • Message trace in the Exchange admin centre for the failed message, which shows the refusal from the service’s side rather than the sender’s.

When a licence is the actual fix

Most of the time this costs nothing. A leaver’s address kept as a shared mailbox needs no licence at all while it stays within the free 50 GB allowance, and that covers the large majority of cases – so try it before you buy anything. Two situations do need a licence. If the mailbox content is larger than 50 GB, the licence that raises a shared mailbox to 100 GB is Exchange Online Plan 2; Plan 1 is itself a 50 GB mailbox and would leave you exactly where you started. If somebody genuinely needs to sign in to the mailbox as a user in its own right, that is a user mailbox and Exchange Online Plan 1 is the smallest licence that provides one. Arco supplies single mailbox licences and will check which of the two your case actually is before you commit.

Every code this article covers

Code What it points at Source
550 5.1.1 “Bad destination mailbox address” – mistyped address, address absent from the destination system, a moved mailbox with a stale Outlook cache, or an invalid legacy domain name Microsoft Learn
550 5.1.10 “Recipient not found” – SMTP address lookup did not find the recipient’s address Microsoft Learn
550 5.7.504 “Recipient address rejected: Access denied” – an authorisation refusal. Verify the address, then check delivery restrictions on the recipient or group Microsoft Learn
550 5.1.20 “Multiple From addresses are not allowed without Sender address” – the message has more than one address in the From field and no Sender address. Not a recipient problem Microsoft Learn
RESOLVER.ADR.RecipNotFound Generated by the Exchange server: the recipient could not be resolved in the directory. In hybrid it usually means the on-premises mail-enabled user is missing its targetAddress Microsoft Learn
RESOLVER.ADR.ExRecipNotFound A 550 5.1.1 where the X.500 / legacyExchangeDN address cannot be resolved – typically replies to PST-migrated mail, a stale AutoComplete entry, or an offline address book that has not updated Microsoft Learn

Confirm the fix worked

  1. Get-Recipient against the address now returns the object you expect.
  2. A test message from an external account is delivered.
  3. The internal sender who was failing succeeds after clearing their AutoComplete entry.
  4. If you added an X500 address, a reply to an old message from that recipient now goes through.
  5. The user account behind a converted shared mailbox is still present and unlicensed, not deleted.

Questions people ask about this

Do I have to pay to keep a leaver’s address working?

Usually not. Converting the mailbox to a shared mailbox keeps the address receiving with no licence, within the free 50 GB allowance. You need a licence only if the mailbox must exceed that size – in which case it is Exchange Online Plan 2 – or if somebody has to sign in to it as a user mailbox.

Can I convert a mailbox whose licence I have already removed?

Not directly. Microsoft requires a licence on the mailbox for the conversion, and a deleted account has to be restored, licensed and given up to 24 hours to re-create the mailbox first. Remove the licence after the conversion, not before.

Why does only one colleague get the bounce?

Their Outlook is holding a saved AutoComplete entry pointing at an internal X.500 address that no longer exists. Everyone else picks the recipient fresh from the directory. Removing the saved entry fixes it for that person; an X500 proxy address fixes it for everyone.

I am getting 5.1.20 – which mailbox is missing?

None. 5.1.20 means the message itself has multiple From addresses and no Sender address. Fix the application or mail-merge that built the headers; the recipient is fine.

Will the message be delivered once the mailbox is restored?

No. These are permanent rejections, so the sending system has already returned the message. Once the address resolves again, senders have to send it a second time.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

License Error Autopilot 0x801c03f3 and 8018000A: device record missing or already claimed Free Fix Error 80090016 in Teams and Outlook: the TPM keyset does not exist License Error Authorization_RequestDenied: the admin centre refuses your change Free Fix AADSTS7000215 and AADSTS700016: bad client secret or missing app registration
โ† Back to Knowledge Base