When an email cannot be delivered, the receiving server explains why with a numeric code and a short message. These email bounce codes come straight from the SMTP protocol, and while the wording varies between providers, the numbers follow a fixed pattern. Learning to read them turns a vague "message not delivered" into a clear next step.
Where to find the code
A bounce usually arrives as a message from "Mail Delivery Subsystem" or "Postmaster". Near the top it names the failed recipient; further down, often under "Technical details" or "Diagnostic-Code", you will find a line like this:
Remote server returned: 550 5.1.1 <sales@example.com>: Recipient address rejected: User unknown
There are two codes in that line. 550 is the basic SMTP reply code. 5.1.1 is the enhanced status code, which is more specific. Both start with the same digit, and that first digit tells you the most important thing.
The first digit: temporary or permanent
- 4xx (for example 421, 450, 451, 452): a temporary failure, often called a soft bounce. The sending server keeps the message and retries, typically for one to five days. You often never see these unless the retries run out.
- 5xx (for example 550, 552, 553, 554): a permanent failure, or hard bounce. The server will not retry. Something must change before the message can be delivered.
The second and third parts of the enhanced code narrow it down. In 5.1.1, the middle 1 means an addressing problem; 5.7.x means a security or policy problem, which is where most authentication and spam rejections live.
Common codes and what to do
| Code | Meaning | What to do |
|---|---|---|
| 421 4.7.0 | Service unavailable or rate limited; try later | Usually nothing. If it persists, slow your sending rate and check your reputation. |
| 450 / 451 4.7.1 | Mailbox busy, greylisting, or temporary policy block | Let your server retry. Greylisting clears after the first retry. |
| 452 4.2.2 | Recipient mailbox full | Retry later or contact the recipient another way. |
| 550 5.1.1 | Mailbox does not exist | Check the spelling; remove the address from your lists. |
| 550 5.7.1 | Rejected by policy: spam filter, blocklist or relay denied | Read the text that follows; check blocklists and authentication. |
| 550 5.7.26 | Failed authentication (Gmail: unauthenticated or DMARC fail) | Fix SPF, DKIM and DMARC for your sending domain. |
| 552 5.3.4 | Message too large | Send a link to the file instead of attaching it. |
| 553 5.1.2 | Invalid address syntax or domain | Correct the address; check the domain has MX records. |
| 554 5.7.1 | Transaction failed, often a blocklisted IP or content rejection | Check whether your server's IP is listed and request removal. |
Providers add their own wording and sometimes a link to an explanation page. That text matters: 550 5.7.1 from one provider may mean "your IP is on our blocklist" and from another "this message looks like spam". Always read the full line, not just the number.
Authentication bounces
Since major mailbox providers tightened their sender rules, bounces that mention SPF, DKIM or DMARC have become far more common. Typical messages include "SPF check failed", "message not authenticated" or "rejected due to DMARC policy". They mean the receiving server could not confirm that your server is allowed to send for your domain.
Check your domain's records with the SPF, DKIM and DMARC checker. The usual culprits are a new sending service (a CRM, helpdesk or newsletter tool) that was never added to SPF, DKIM that signs with the provider's domain instead of yours, or two SPF records published at the same time.
Bounces that are not your fault
Some bounces come from the recipient's side: a misconfigured mail server, an expired domain, or a mailbox that was closed when someone left the company. If the recipient's domain no longer has MX records, delivery is impossible until they fix it. A quick DNS lookup of the recipient domain's MX records tells you whether the problem is at their end.
Why hard bounces matter for your reputation
Mailbox providers watch how many of your messages go to addresses that do not exist. A high hard-bounce rate looks like a sender using an old or purchased list, and it drags down delivery for everyone else you email. For marketing and transactional mail:
- Remove addresses after the first hard bounce for "user unknown".
- Suppress addresses that soft-bounce repeatedly over several weeks.
- Use confirmed opt-in for sign-up forms so typos never enter the list.
- Keep the overall bounce rate well under 2%.
Key takeaways
- 4xx codes are temporary and retried automatically; 5xx codes are permanent.
- The enhanced code (such as 5.1.1 or 5.7.1) and the text after it explain the real cause.
- 5.7.x rejections usually point to authentication, blocklists or spam filtering.
- Clean hard bounces from your lists promptly to protect your sending reputation.