Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

License Error 550 5.7.708

550 5.7.708: Microsoft 365 will not accept traffic from your sending IP

11 min read Updated October 5, 2026 Exchange Server

Fix it now

Microsoft publishes 5.7.708 as access denied, traffic not accepted from this IP, and names the cause as sending from an address with low reputation – which particularly affects new customers on trial subscriptions. It is a decision about where the mail came from, not about the message.

Run these in Exchange Online PowerShell to establish where your mail is leaving from

Get-AcceptedDomain | Format-List DomainName,DomainType
Get-Mailbox sender@contoso.com | Format-List PrimarySmtpAddress,RecipientTypeDetails
Get-InboundConnector | Format-List Name,SenderIPAddresses,SenderDomains,Enabled
  1. Establish which address is being refused. It is the public address your mail leaves from – the tenant’s outbound infrastructure if you send through Microsoft 365, or your own gateway if you relay through a connector.
  2. Check the subscription. In the Microsoft 365 admin centre, under Billing and Your products, confirm whether the tenant is on a trial or a paid subscription and whether that subscription is active.
  3. Check the domains under Settings and Domains. Every domain you send from must be listed and verified in the tenant.
  4. Open the Microsoft Defender portal and look at Restricted entities. An account restricted after a suspected compromise produces refusals that look like an infrastructure problem.
  5. Assign Exchange Online licences to the mailboxes that send, then contact Microsoft Support to request an IP exception. That is the documented route for 5.7.708.

5.7.703 does not belong in this group. Microsoft publishes it as a block your own organisation configured in the Tenant Allow/Block List, and an email admin can lift it without contacting anyone.

If mail leaves after the licences and the exception, you are done. If a single account is refused while the rest of the tenant sends normally, the next section covers restricted senders.

Why it happens

Outbound mail from a large service is a shared reputation. Every tenant sending through it affects the addresses everyone else’s mail leaves from, so the service applies restrictions long before a message is examined for content. Microsoft’s published cause for 5.7.708 is that the mail was sent from an IP address with low reputation, and it names new customers with trial subscriptions as the group this particularly affects. Its published fix is equally specific: assign Exchange Online licences, then contact Microsoft Support to request an exception for the address.

5.7.705 sits alongside it, and Microsoft pairs the two in its own reference: most of the traffic from this tenant is detected as suspicious, so a ban is placed on the tenant’s ability to send. The published remedy is to make sure any compromises or open relays are resolved, and then to contact support through your normal channel. The support conversation is not optional in either case; it is the documented step.

5.7.750 is a different judgement. The published text is that the client is blocked from sending from unregistered domains, and the published cause is a suspicious number of messages coming from unprovisioned domains, or misconfigured connectors. The fix is to add and validate every domain you send from, use certificate-based connectors with accepted domains, and audit for suspicious connectors or compromised accounts before asking support to remove the block.

5.7.703 is the odd one out and is worth separating clearly. Microsoft publishes it as Your message can't be delivered because messages to <recipients> are blocked by your organization using Tenant Allow Block List – somebody in your organisation sent mail to an address or domain your own tenant has blocked, and the whole message is blocked for every recipient even if only one of them matched a block entry. Nothing about reputation, thresholds or subscriptions is involved, and only an email admin can change it.

The tenant is on a trial or the subscription has lapsed

You have this one if Internal mail flows, outbound mail to the internet is refused with 5.7.708, and the admin centre shows a trial or expired subscription.

  1. Confirm the subscription state under Billing and Your products.
  2. Move the tenant to a paid subscription and assign licences to the mailboxes that send.
  3. Verify every sending domain in the tenant, including any subdomain an application uses.
  4. Contact Microsoft Support to request an IP exception, which is the documented route out of this restriction.

Most of the tenant’s traffic looks suspicious

You have this one if 5.7.705 rather than 5.7.708, and the tenant’s sending has been banned rather than throttled.

  1. Investigate for compromised accounts before anything else, and reset their credentials.
  2. Check for an on-premises server or connector relaying mail into the tenant that has itself been compromised.
  3. Enable multifactor authentication and review the tenant’s security posture, which Microsoft names explicitly as a step here.
  4. Then contact support through your regular channel to have the block removed.

You are sending from a domain the tenant has not registered

You have this one if 5.7.750, and the refusal mentions the domain rather than the address.

  1. Add and validate every domain you use to send email from the tenant.
  2. Use certificate-based connectors with accepted domains rather than address-based ones where you can.
  3. Audit for connectors nobody recognises and for compromised accounts creating them.
  4. Then ask support to remove the block.

Sending as a domain the tenant has not verified is precisely the behaviour this restriction exists to prevent, so treat a refusal here as the system working correctly.

Your own tenant blocked the recipient

You have this one if 5.7.703, naming the recipient addresses or domains rather than your infrastructure.

  1. Open the Tenant Allow/Block List and look for a block entry matching the recipient address or its domain.
  2. Remove the entry if the block is no longer wanted. Only an email admin can do this.
  3. Remember that one blocked recipient blocks the whole message for everyone on it, so a single stale entry can look like a general outbound failure.

One account has been restricted after a compromise

You have this one if One account is refused while the rest of the tenant sends normally, and it appears on the Restricted entities page.

  1. Reset the password and revoke active sessions before anything else.
  2. Review inbox rules and forwarding for changes the attacker made: Get-InboxRule -Mailbox user and Get-Mailbox user | Format-List ForwardingSmtpAddress,DeliverToMailboxAndForward
  3. In the Defender portal, go to Email & collaboration, Review, Restricted entities, select the mailbox and choose Unblock.
  4. Enable multifactor authentication on the account before returning it to normal use.

Full reference

The four codes, and who can lift each block

Code Published text Who lifts it
550 5.7.708 Access denied, traffic not accepted from this IP Microsoft Support, after licences are assigned
550 5.7.705 Access denied, tenant has exceeded threshold Microsoft Support, after the compromise or relay is fixed
550 5.7.750 Client blocked from sending from unregistered domains Microsoft Support, after every sending domain is added and validated
550 5.7.703 Messages to the named recipients are blocked by your organisation using Tenant Allow Block List Your own email admin

Where the refusal is coming from

Situation What is being refused
Trial tenant, only internal mail works Outbound sending from a low-reputation address
Sending from a domain not listed in the tenant An unregistered sending domain
Relaying an on-premises server through a connector The reputation or configuration of your own public sending address
Sudden failure on an established tenant A reputation event, often a compromised account sending in volume
One account fails while others succeed That account is restricted, not the tenant
The refusal names the recipients Your own Tenant Allow/Block List

Restricted senders, and what the user sees

When an account is restricted from sending, the message it gets back is 5.1.8, and Microsoft publishes the wording: the sender was not recognised as a valid sender, most commonly because the address is suspected of sending spam and is no longer allowed to send. The account is cleared from the Restricted entities page at the Defender portal, under Email & collaboration, Review, Restricted entities, with the Unblock action. Microsoft’s stated timing is that restrictions should be removed within an hour under most circumstances, and within 24 hours at most.

  1. Reset the password and revoke sessions first. Unblocking a still-compromised account simply restarts the incident.
  2. Remove any inbox rules or forwarding the attacker created.
  3. Unblock the mailbox from Restricted entities, enabling multifactor authentication and resetting the password from the flyout if you have not already.
  4. Watch outbound volume for that account over the next day.

What Microsoft says users are restricted for

  • Exceeding the outbound sending limits of the service.
  • Exceeding the limits in the tenant’s outbound spam policies.
  • Both of which, in Microsoft’s own words, typically result from account compromise rather than from unusual but legitimate use.

Moving the same traffic to a different sending address does not solve a reputation problem; it spreads it. Relaying business mail through an unrelated third party to get around a block also creates authentication and compliance problems of its own, and the original block stays where it is.

Before you contact support

  1. Have the exact NDR text, including the code and the sending IP address.
  2. Confirm the subscription is paid and active, and that the sending mailboxes have Exchange Online licences.
  3. Confirm every sending domain is added and verified in the tenant.
  4. Confirm no account remains on the Restricted entities page and no compromise is still active.
  5. Then open the case. Microsoft’s documented fixes for 5.7.705, 5.7.708 and 5.7.750 all end with contacting support, and the case moves faster when the preceding steps are already done.

When a licence is the actual fix

For 5.7.708 specifically, this is not a configuration fault and there is no setting that clears it. Microsoft’s published cause is a low-reputation sending address, with new customers on trial subscriptions particularly affected, and its published fix is to assign Exchange Online licences to the mailboxes that send and then contact Microsoft Support to request an exception for the address. So the subscription is a necessary step rather than the whole answer – expect the support request as well, and expect nothing to move until any compromise or open relay is dealt with. Arco supplies Microsoft 365 Business Standard subscriptions and can check whether the plan you are looking at includes the Exchange Online service plan your sending mailboxes need, which matters when a tenant is running a mix of plans and the accounts sending automated mail turn out to be the unlicensed ones.

Every code this article covers

Code What it points at Source
550 5.7.708 Access denied, traffic not accepted from this IP. Sent from an address with low reputation, which particularly affects new customers on trial subscriptions Microsoft Support
550 5.7.705 Access denied, tenant has exceeded threshold. Most of the tenant’s traffic is detected as suspicious, so its sending is banned Microsoft Support
550 5.7.750 Client blocked from sending from unregistered domains, after a suspicious volume of messages from unprovisioned domains or misconfigured connectors Microsoft Support
550 5.7.703 Messages to the named recipients are blocked by your own organisation using the Tenant Allow/Block List. One blocked recipient blocks the whole message Microsoft Support

Confirm the fix worked

  1. A test message from a licensed mailbox on a verified domain reaches an external recipient.
  2. The admin centre shows an active paid subscription and every sending domain verified.
  3. No account remains on the Restricted entities page in the Defender portal.
  4. The Tenant Allow/Block List contains no stale entry for the recipients that were being refused.
  5. Automated senders have been checked individually, since they usually run as the accounts nobody thinks to license.

Questions people ask about this

Will paying for a subscription definitely fix it?

Not on its own. Microsoft’s documented fix for 5.7.708 is to assign Exchange Online licences and then contact support to request an IP exception. It also does not repair reputation damaged by unwanted mail, and it does not unblock an account restricted after a compromise.

How long does it take to clear after I change something?

Reputation is evaluated continuously, so a change in tenant state takes effect over time rather than instantly. For a restricted account, Microsoft says restrictions should be removed within an hour under most circumstances and within 24 hours at most.

I got 5.7.703. Do I need to contact Microsoft?

No. That one is a block your own organisation configured in the Tenant Allow/Block List. An email admin can remove the entry, and no support case is needed.

Can I work around it by relaying through another provider?

Sending the same traffic from a different address moves the reputation problem rather than solving it, and relaying business mail through an unrelated third party creates its own authentication and compliance problems.

Does every mailbox that sends need a licence?

Check each one. Microsoft’s documented fix for 5.7.708 involves assigning Exchange Online licences to the sending mailboxes, and automated senders are usually the accounts nobody thought to license – so establish what identity each application actually signs in as.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Free Fix 552 5.3.4: the message is larger than the Exchange size limit allows Free Fix 0x8004010F: Outlook cannot download the offline address book from Exchange License Error Event ID 9518 with error -1808: the log volume filled and the store dismounted Free Fix 0x80090322 in the Exchange Management Shell: WinRM cannot authenticate
โ† Back to Knowledge Base