Fix Exchange Hybrid Server Error 554 5.4.1 Recipient Address Rejected
Question details
Mail sent from an on-premises Exchange server in a hybrid setup is rejected with a 554 5.4.1 Access denied error.

- Product
- Microsoft Exchange Hybrid
- Device & OS
- not provided
- Scenario
- Attempting to send email from an on-premises Exchange server to external or cloud mailboxes within a hybrid environment.
- Observed behavior
- Message delivery fails, returning a Non-Delivery Report (NDR) stating '554 5.4.1 Recipient address rejected: Access denied', even though Exchange Online mail routes correctly.
Verify that your Exchange Online environment is fully synced with your on-premises Active Directory and that you have administrative access to both the Exchange Admin Center (EAC) and Microsoft 365 Admin Center.
Verify Directory Based Edge Blocking (DBEB) Settings
DBEB might be rejecting emails if the recipient address is not recognized in Azure AD. Ensuring your domain is set correctly resolves this access denial.
In an Exchange Hybrid environment, if Directory Based Edge Blocking (DBEB) is enabled for a domain, Exchange Online will reject messages for addresses not present in Azure Active Directory.
To fix this, you must ensure directory synchronization is healthy and verify your Accepted Domain type.
Log in to the Microsoft 365 Exchange Admin Center (EAC) using your administrator credentials.
In the left-hand navigation menu, go to Mail flow and then select Accepted domains.
Select the domain returning the error. If it is set to 'Authoritative', change it to 'Internal Relay' to ensure unknown recipients are routed to your on-premises environment instead of being dropped by DBEB.
Open PowerShell on your AD Connect server and run 'Start-ADSyncSyncCycle -PolicyType Delta' to ensure all recipient objects are fully synchronized with the cloud.

Consult the Microsoft Exchange Hybrid Management Forum
Because hybrid mail flow configurations are highly complex, engaging Microsoft support engineers ensures a tailored solution without breaking existing routing.
Try WPS Office for a Lightweight, Cost-Free Alternative
Managing complex Exchange hybrid environments can be stressful. For your daily document creation and IT reporting needs, switch to WPS Office. It provides a lightweight, entirely free, and highly compatible alternative to Microsoft Office, avoiding the hassle of enterprise licensing deployments.
- 1. Download the Installer: Visit the official WPS Office website and download the free installation package for your operating system.
- 2. Install the Software: Run the downloaded executable file and follow the on-screen prompts to complete the installation.
- 3. Start Creating: Launch WPS Office to instantly begin working on your documents, spreadsheets, and presentations.

Frequently Asked Questions
What causes the 554 5.4.1 Recipient address rejected error in Exchange?
This error typically occurs when Directory Based Edge Blocking (DBEB) is active in Microsoft 365, and it rejects the email because the recipient's email address is not recognized as a valid object in your synchronized Azure Active Directory.
Why does email work perfectly from Exchange Online but fail from on-premises?
Exchange Online already has the correct routing and directory mapping for cloud mailboxes. In contrast, the on-premises server relies on an outbound connector to the cloud; if the cloud treats the domain as Authoritative but the user hasn't synced, the cloud rejects the inbound on-premises handoff.
How do I run a message trace for this 5.4.1 error?
Log into the Exchange Admin Center, navigate to Mail flow > Message trace. Enter the sender and recipient addresses, set the appropriate date range, and click search to view the exact transport layer where the rejection occurred.
Is it safe to change my Accepted Domain to Internal Relay?
Yes, changing the domain to Internal Relay is standard practice in many hybrid configurations. It tells Exchange Online that if a mailbox isn't found in the cloud, it should route the message back to your on-premises servers rather than dropping it with an access denied error.




