EXO: 550 5.4.1 Recipient address rejected: Access denied to Distribution List (Only newer ones)

%3CLINGO-SUB%20id%3D%22lingo-sub-1179432%22%20slang%3D%22en-US%22%3EEXO%3A%20550%205.4.1%20Recipient%20address%20rejected%3A%20Access%20denied%20to%20Distribution%20List%20(Only%20newer%20ones)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1179432%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20set%20up%20a%20DistributionGroup%20so%20that%20it%20can%20also%20receive%20external%20emails.%3CBR%20%2F%3EIf%20I%20test%20it%20from%20different%20(external)%20tenants%20I%20get%20the%20following%20error%20message%3A%3C%2FP%3E%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%3E550%205.4.1%20Recipient%20address%20rejected%3A%20Access%20denied.%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%3E%3CP%3EI%20adjusted%20this%20about%208%20days%20ago.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAfter%20I%20kept%20getting%20this%20error%20message%20I%20also%20tested%20it%20in%20other%20tenants%20and%20here%20I%20got%20the%20same%20error%20message.%3C%2FP%3E%3CP%3EThese%20are%20tenants%20with%20different%20domain%20names%20and%20different%20domain%20registrars.%3C%2FP%3E%3CP%3EWhen%20I%20compare%20the%20properties%20via%20PowerShell%20they're%20the%20same.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20I%20do%20a%20MessageTrace%20I%20don't%20see%20the%20emails%20sent%20to%20the%20DistributionGroup%20at%20all.%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20the%20message%20is%20dropped%20before%20it%20arrives%20at%20EXO%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAs%20soon%20as%20I%20change%20the%20Accepted%20Domain%20from%20Authoritive%20to%20Internal%20relay%20the%20messages%20do%20arrive!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20I%20search%20for%20the%20error%20message%20I%20find%20the%20following%20docs%3A%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fmail-flow-best-practices%2Fnon-delivery-reports-in-exchange-online%2Ffix-error-code-550-5-4-1-in-exchange-online%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fmail-flow-best-practices%2Fnon-delivery-reports-in-exchange-online%2Ffix-error-code-550-5-4-1-in-exchange-online%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENone%20of%20the%20steps%20under%20'I'm%20an%20email%20admin.%20How%20can%20I%20fix%20this%3F'%20is%20the%20solution.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI've%20tried%20changing%20the%20PrimarySmtpAddress%20or%20add%20an%20Alias%2C%20but%20none%20of%20this%20worked%20either.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESince%20I%20have%20this%20issue%20in%20more%20tenants%20I%20think%20that%20it%20is%20a%20global%20issue%20at%20Microsoft.%3C%2FP%3E%3CP%3ECan%20someone%20please%20confirm%3F%20Or%20tell%20me%20what%20I%20do%20wrong.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1179432%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%20Online%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1179922%22%20slang%3D%22en-US%22%3ERe%3A%20EXO%3A%20550%205.4.1%20Recipient%20address%20rejected%3A%20Access%20denied%20to%20Distribution%20List%20(Only%20newer%20ones)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1179922%22%20slang%3D%22en-US%22%3E%3CP%3EIf%20you%20are%20not%20getting%20any%20results%20in%20the%20message%20trace%20and%20it%20works%20when%20switching%20to%20InternalRelay%2C%20this%20is%20most%20likely%20caused%20by%20issue%20with%20the%20Directory%20Based%20Edge%20Blocking%20feature.%20You%20can%20try%20to%20trigger%20the%20replication%20by%20changing%20the%20primary%20SMTP%20address%20of%20the%20DG%20(and%20changing%20it%20back%20if%20needed)%2C%20or%20you%20can%20open%20a%20support%20case%20and%20have%20the%20engineer%20look%20at%20it.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Contributor

Hi all,

 

I have set up a DistributionGroup so that it can also receive external emails.
If I test it from different (external) tenants I get the following error message:

 
550 5.4.1 Recipient address rejected: Access denied.
 

I adjusted this about 8 days ago.

 

After I kept getting this error message I also tested it in other tenants and got the same error message. These are tenants with different domain names and different domain registrars.

 

  • When I compare the properties via PowerShell they're the same.
  • When I do a MessageTrace I don't see the emails sent to the DistributionGroup at all.
    So the message is dropped before it arrives at EXO?
  • I've tried changing the PrimarySmtpAddress or add an Alias, but none of this worked either. 
  • As soon as I change the Accepted Domain from Authoritive to Internal relay the messages do arrive!

 

When I search for the error message I find the following docs:

https://docs.microsoft.com/en-us/exchange/mail-flow-best-practices/non-delivery-reports-in-exchange-...

 

None of the steps under 'I'm an email admin. How can I fix this?' is the solution.

 

Since I have this issue in more tenants I think that it is a global issue at Microsoft.

Can someone please confirm? Or tell me what I do wrong.

 

 

1 Reply
Highlighted

If you are not getting any results in the message trace and it works when switching to InternalRelay, this is most likely caused by issue with the Directory Based Edge Blocking feature. You can try to trigger the replication by changing the primary SMTP address of the DG (and changing it back if needed), or you can open a support case and have the engineer look at it.