Fix it now
The recipient resolved but the mailbox behind it will not take the message. RFC 3463 defines this class as a mailbox that exists but is not accepting messages, permanently if it will never be re-enabled and transiently if it is only switched off for now. In practice there are three states to tell apart.
Get-Mailbox user@contoso.com | Format-List Name,RecipientTypeDetails,PrimarySmtpAddress,ExchangeUserAccountControl
Get-MessageTrackingLog -Recipients user@contoso.com -Start (Get-Date).AddHours(-2) | Format-Table Timestamp,EventId,Source,Recipients
- If
Get-Mailboxcannot find the identity at all, the mailbox is disabled or deleted rather than merely blocked – go looking for it as a disconnected or soft-deleted mailbox. - If it returns a mailbox and
ExchangeUserAccountControlreports the account as disabled, the directory account was switched off with the mailbox left in place. - In Microsoft 365, open the admin centre, go to Users then Active users, select the person and check both the sign-in status and the Licences and apps tab.
- If the licence is missing, reassign one. Microsoft holds the Exchange Online data for 30 days after a licence is removed, and within that window the same mailbox comes back with its contents.
- Send one test message and confirm a DELIVER event for that recipient in the tracking log.
550 5.7.13 is not part of this. Microsoft publishes it as Sender was not authenticated for public folder – the recipient is a public folder set to reject external senders – so it points at the recipient’s configuration, not the sender’s account.
If the mailbox now accepts mail, you are done. If it is a licence or a subscription that lapsed, the next section covers what is recoverable and for how long.
Why it happens
A mailbox is two things joined together: a directory object that owns the address, and a store that holds the items. This class of failure is what you get when the first half is intact and the second is not available. The address resolves, the categoriser hands the message to the store, and the store declines. Nothing is lost in transit and nothing about the sending path is at fault.
Microsoft does not publish an Exchange-specific gloss for 5.2.1 in its Exchange Online non-delivery report reference, so treat the RFC definition as the reliable one: the mailbox exists but is not accepting messages, and the code can be permanent or transient depending on whether it will ever be re-enabled. The neighbouring 5.2.0 is the same family with nothing more specific to say – the mailbox exists and something about it caused the report.
On premises, the commonest cause is an Active Directory account disabled while the mailbox was left in place, which is exactly what happens when someone leaves and HR disables the account before IT has decided what to do with the mail. In Microsoft 365 the commonest cause is a licence: removing one leaves the mailbox unlicensed and undeliverable, and the clock starts on a 30-day retention window after which the data is deleted and cannot be recovered.
The fourth item people arrive with, Event ID 9548, is worth a word of caution. Microsoft publishes no current description for it, so do not act on a remembered meaning. Read the event’s own text in Event Viewer, which names the objects involved, and confirm the state with Get-Mailbox and Get-User before you change anything.
The Active Directory account has been disabled
You have this one if On premises, the mailbox is present and ExchangeUserAccountControl reports the account as disabled.
- Decide deliberately what the mailbox is for. If the person has left and mail must still arrive, convert it to a shared mailbox rather than leaving a disabled account with a live mailbox.
- If the account was disabled in error, re-enable it in Active Directory Users and Computers and allow replication to complete.
- For a linked mailbox in a resource forest, confirm the master account association points at a live account in the accounts forest.
- Retest delivery and confirm the tracking log shows a DELIVER event.
The mailbox was disabled or removed
You have this one if Get-Mailbox cannot find the identity at all, but the address still resolves as a recipient.
- List disconnected mailboxes still held in the database:
Get-MailboxStatistics -Database DB01 | Where-Object {$_.DisconnectReason -ne $null} | Format-List DisplayName,DisconnectReason,MailboxGuid - Reconnect it to its user account with
Connect-Mailboxrather than creating a new one, so the item history survives. - In Exchange Online, look for it as soft-deleted:
Get-Mailbox -SoftDeletedMailbox -Identity user@contoso.com - Restore or reassign, then confirm the address resolves to a UserMailbox again.
A disconnected mailbox is retained only for the deleted mailbox retention period configured on the database. Once that passes, reconnection is no longer possible.
The Microsoft 365 licence was removed or the subscription lapsed
You have this one if The mailbox exists in the tenant, the admin centre shows no licence assigned, and delivery stopped on the day the renewal failed or the seat was reassigned.
- Confirm the licence state under Users, Active users, Licences and apps for that person.
- Check the subscription itself under Billing and Your products. An expired or disabled subscription removes service from every seat on it, not just one.
- Assign a licence that includes the Exchange Online service plan. Within the 30-day window the existing mailbox comes back with its contents intact.
- Allow a short period for reprovisioning, then retest delivery.
The recipient is a public folder rejecting external senders
You have this one if 550 5.7.13 or 5.7.135, and the recipient address belongs to a mail-enabled public folder rather than a mailbox.
- In the Exchange admin centre, open Public folders, then the folder’s Mail flow settings, then Accept messages from.
- Clear Require that all senders are authenticated and choose All senders, or keep the requirement and add the specific external senders to the allowed list.
- Save, then retest from the sending address that was refused.
This is a recipient-side restriction. Nothing about the sender’s account, licence or password is involved, which is why chasing the sender wastes the afternoon.
Full reference
Telling the states apart
| What you find | What it means |
|---|---|
Get-Mailbox fails for the identity |
The mailbox is disabled or deleted, not blocked |
Get-Mailbox succeeds, ExchangeUserAccountControl shows the account disabled |
The directory account is off while the mailbox is still present |
| Mailbox exists, no licence assigned in the admin centre | The subscription that paid for the mailbox is gone |
| The recipient is a mail-enabled public folder | A 5.7.13 restriction on the folder, not a mailbox problem |
| Event ID 9548 on the mailbox server | Read the event’s own text; Microsoft publishes no current description for this ID |
What each code in this group actually says
| Code | Source | Meaning |
|---|---|---|
| 550 5.2.1 | RFC 3463 | The mailbox exists but is not accepting messages; permanent if it will never be re-enabled, transient if only temporarily disabled |
| 550 5.7.13 | Microsoft Learn | Sender was not authenticated for public folder – the folder rejects senders from outside the organisation |
| 550 5.2.0 | RFC 3463 | The mailbox exists, but something about the destination mailbox caused this report |
| Event ID 9548 | Not published | Read the event text in Event Viewer and confirm the state with Get-Mailbox and Get-User |
Disable-Mailbox and Remove-Mailbox both detach live user data, and Remove-Mailbox can delete the account with it. Never run either to clear a bounce. Establish what state the mailbox is in first, and export or back up before you change anything holding mail.
Licensing, in the detail that decides the outcome
- Removing a licence holds the Exchange Online data for 30 days. After that it is deleted and cannot be recovered, though content matching retention labels is retained for discovery.
- When the licence is removed the mailbox is no longer searchable with Content Search or eDiscovery, so the discovery route disappears before the data does.
- A shared mailbox stores up to 50 GB without a licence. Above that it needs an Exchange Online Plan 2 licence, which raises the cap to 100 GB.
- A shared mailbox on litigation hold, or with in-place archiving enabled, needs Exchange Online Plan 2, or Plan 1 with the Exchange Online Archiving add-on.
- To access a shared mailbox a user needs their own licensed Exchange Online mailbox; the shared mailbox itself does not need one for ordinary use.
That last group is the reason a shared mailbox that has worked for two years suddenly starts refusing mail. Nobody changed anything: it crossed 50 GB, or somebody put it on hold as part of an unrelated matter.
Where to look when none of the three fits
- Check whether the recipient is a mail user or a mail contact pointing at an external address that is itself failing.
- Check delivery restrictions on the recipient, which produce their own codes rather than this one but look identical to the sender.
- In a hybrid organisation, confirm the recipient object exists on the side that actually holds the mailbox and that the remote routing address is correct.
- Confirm the sender is not being refused by a rule rather than by the mailbox – the tracking log shows which.
- For a linked mailbox, confirm the master account association still points at an enabled account in the accounts forest.
When a licence is the actual fix
If the mailbox stopped accepting mail because its licence was removed or the subscription lapsed, no configuration change brings it back. The mailbox is unlicensed and Exchange Online is behaving as designed. Assigning a licence that includes the Exchange Online service plan restores the same mailbox with its contents, provided you act inside the 30-day window that starts when the licence is removed – after that the data is deleted and cannot be recovered. Arco supplies Microsoft 365 Business Standard subscriptions and can check whether the plan you already hold includes the Exchange Online service plan the mailbox needs, which is the detail people most often get wrong in a tenant running a mixture of plans. If the account is simply disabled in Active Directory, or the mailbox is disconnected, nothing needs buying.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
550 5.2.1 |
The mailbox exists but is not accepting messages. Microsoft does not publish an Exchange-specific gloss; this is the RFC 3463 class definition | RFC 3463 |
550 5.7.13 |
Sender was not authenticated for public folder: the recipient is a public folder configured to reject messages from senders outside the organisation | Microsoft Learn |
550 5.2.0 |
The mailbox exists, but something about the destination mailbox caused this report. The general form with nothing more specific to say | RFC 3463 |
Event ID 9548 |
Microsoft publishes no current description for this event. Read its own text in Event Viewer and confirm the mailbox and account state with Get-Mailbox and Get-User | not published by the vendor |
Confirm the fix worked
Get-Mailbox user@contoso.comreturns a UserMailbox with the expected primary address.- The admin centre shows an assigned licence that includes Exchange Online, and sign-in is not blocked.
- A test message appears with a DELIVER event in
Get-MessageTrackingLogfor that recipient. - The affected user can both receive and send.
- For a public folder recipient, a message from the external address that was refused is now accepted.
Questions people ask about this
Do I have to buy a licence to fix this?
Only if the licence is genuinely the cause. If the mailbox is unlicensed or the subscription has lapsed, a licence is the fix and nothing else will do. If the account is disabled in Active Directory, or the mailbox is disconnected, re-enabling or reconnecting costs nothing.
Can a shared mailbox receive mail without a licence?
Yes, up to 50 GB. Above that it needs an Exchange Online Plan 2 licence, which also raises the cap to 100 GB. Litigation hold or in-place archiving need Plan 2, or Plan 1 with the Exchange Online Archiving add-on.
How long do I have before the data is gone?
After a licence is removed, Microsoft holds the Exchange Online data for 30 days and then deletes it. Do not treat that as a plan; restore the licence as soon as you have identified the cause.
I got 550 5.7.13 – is my account disabled?
No. Microsoft publishes 5.7.13 as Sender was not authenticated for public folder. The recipient is a public folder set to reject messages from outside the organisation, and only the recipient’s administrator or the folder’s owner can change that.
Why did only some senders get a bounce?
Internal and external senders take different paths. External mail can be refused during the SMTP conversation at the edge, while internal mail is bounced by the store after acceptance – same cause, different timing and different wording.
