Reference
SMTP error lookup
The first digit is what matters. 4xx is temporary — the sender will retry, often for days. 5xx is permanent — the message bounces.
Paste a code or part of a message to find it.
Nothing matches that. The code may be specific to the receiving server — the text of its reply is usually the better clue.
Codes Corsair returns#
| Code | Meaning | What to do |
|---|---|---|
| 421 | Too many errors, or too many failed logins from this address | The IP is temporarily banned. Wait an hour. |
| 450 | Mailbox temporarily unavailable | Retry. |
| 451 | Daily sending limit reached | The account (or, for an agent mailbox, that one mailbox) is over its outbound allowance for the day. |
| 452 | Storage quota exceeded, or recipient's daily inbound limit reached | Free space or upgrade; the sender will retry. |
| 501 | Malformed address or syntax | The sending client has a bug. |
| 503 | Commands out of order | Usually a client that pipelined without checking for support. |
| 530 | Authentication required | Submission needs AUTH. Check the client is using 587 or 465, not 25. |
| 535 | Credentials invalid | Wrong mailbox password. Note this is not the panel password. |
| 538 | Encryption required | The client tried to authenticate before STARTTLS. |
| 550 | No such user, or relay denied | The address does not exist here, or the domain is not hosted here. |
| 550 | You are not allowed to send as … | On submission, the envelope sender or the From: header is not an address this login may send as. Check the client's identity settings. An agent mailbox may only send as itself, and only if sending is turned on for it. |
| 552 | Message too large | Over MAX_MESSAGE_BYTES. |
| 554 | No valid recipients | Every recipient was rejected. |
| 554 5.4.6 | Too many hops | The message carries more than 30 Received: headers, so it is in a mail loop — usually a forward that points back at itself. |
Codes you will see from others#
| Code | Usually means |
|---|---|
| 421 4.7.0 | Rate-limited by the receiver. Slow down; this is not an error in your configuration. |
| 450 4.2.0 | Greylisting. The first attempt is always refused; the retry is accepted. Nothing to fix. |
| 550 5.7.1 | Blocked on policy — reputation, SPF, or DMARC. The text usually names which. |
| 550 5.7.26 | Unauthenticated: no aligned SPF or DKIM. Your DNS is wrong or incomplete. |
| 554 5.7.1 | Listed on a blocklist. The text usually names it. |
Reading a bounce#
A bounce carries three parts: a human-readable explanation, a machine-readable message/delivery-status report, and the original headers. The Diagnostic-Code line in the middle part is the remote server's verbatim reply — that is the one to act on, not the summary at the top.