Skip to content
emailrules.today
In forceAuthIn force 5 May 2025Verified 2 Aug 2026

Outlook rejects unauthenticated mail from high-volume senders

What are Outlook's requirements for bulk senders?

Global · Microsoft

In one sentence

Microsoft will bounce mail that is not authenticated — often with error 550 5.7.515.

Emailrules interpretation

If you send about 5,000+ messages a day to Outlook.com, Hotmail or Live combined, Microsoft wants and , a record on your domain (even p=none counts for the requirement), and . Unlike Gmail’s quieter spam sorting, Microsoft often rejects bad auth with a bounce you can see in logs.

Why it matters. Bounces are visible. If your record is missing on the root domain, this is often the first provider that hurts loudly.

Dotted words open definitions. See how email actually works.

What to do

Your move — not a lecture

Part platform, part you

The platform covers the mechanical bit. The judgement is still yours.

Your sets up and when you configure a branded sending domain, and that covers most of it.

Your part: The record. It lives in your own domain's and no can publish it for you, which is exactly why this is the requirement people fail.

What to do first

Run `dig +short TXT _.yourdomain.com` in a terminal. If it returns nothing and you clear 5,000 a day to Microsoft, your mail is bouncing right now.

You can skip this if: You send under 5,000 messages a day to Microsoft consumer addresses.

Who this applies to

Any domain sending 5,000 or more messages a day to Microsoft consumer addresses. Outlook.com, Hotmail and Live count together, which catches people who assume their Microsoft volume is small.

Checklist

  • 01Publish a record if you have none. Even p=none satisfies the requirement.
  • 02Confirm , not just presence: or has to match your , not your 's.
  • 03Watch for 550 5.7.515 in your bounce logs. Unlike Gmail, Microsoft tells you when it rejects you.
  • 04Count Outlook.com, Hotmail and Live as one volume, because Microsoft does.

That’s enough to act. The exact wording, the enforcement record and every primary source sit under Proof & sources, for counsel, bosses, or AI tools that need a citation. Not legal advice.

Proof

Exact position, enforcement, sources

For records and people who will check you. Skip if Monday’s move is already clear.

Source fact

Microsoft requires domains sending 5,000 or more messages a day to Outlook.com, Hotmail and Live to pass both and , publish a record at minimum p=none, and align at least one of SPF or DKIM with the domain in the . Microsoft first announced routing non-compliant mail to Junk from 5 May 2025, then moved to outright rejection with SMTP error 550 5.7.515.

What happens if you do not

Enforced by hard rejection rather than silent filtering, which is unusually helpful: the bounce names the reason. Worth noting that Microsoft's own support page for the error carries no publication date, so the timeline comes from its announcement blog rather than the documentation.

Sources

  • Microsoft, Fix NDR error 550 5.7.515 in Outlook.com
    No publisher dateRead primary source
  • Microsoft, Strengthening Email Ecosystem: Outlook's New Requirements for High-Volume Senders
    No publisher dateRead primary source

History of this page

  • Re-verified against primary sources (bulk/auth/consent core).
  • Added. Microsoft's requirement had been missing while Gmail and Yahoo were covered, which was a real gap.

Related

Take this with you

GET https://emailrules.today/rules/outlook-high-volume-sender-authentication?format=json

Same URL, same answer, every field including the ones behind the Proof tab. An Accept: application/json header on the plain URL does the same thing. All the endpoints.