How to Fix iCloud Rejecting Microsoft 365 SMTP Messages With Error 550 5.7.1
Question details
Users are unable to successfully deliver emails to iCloud addresses (@icloud.com or @me.com) via Microsoft 365 SMTP, as messages are returned with an Error 550 5.7.1 citing security or policy settings.

- Product
- Microsoft 365 SMTP
- Device & OS
- not provided
- Scenario
- Sending outbound emails from a Microsoft 365 tenant to Apple iCloud email addresses.
- Observed behavior
- Emails are delivered correctly to other domains, but messages to iCloud recipients bounce back with a 550 5.7.1 rejection error caused by Apple's strict policy filtering.
Ensure you have access to your domain's DNS control panel and administrator credentials for the Microsoft 365 Defender portal to review email authentication settings.
Verify Email Authentication Records (SPF, DKIM, and DMARC)
Apple's iCloud servers strictly enforce domain authentication. Incorrectly configured DNS records will cause immediate 550 5.7.1 delivery rejections.
Major email providers have recently tightened their security requirements. If your Microsoft 365 tenant lacks proper domain alignment, Apple will reject the messages to protect users from potential spam or spoofing.
Log in to your DNS hosting provider and verify that your domain's TXT record for SPF includes the required Microsoft 365 value: 'v=spf1 include:spf.protection.outlook.com -all'.
Open the Microsoft 365 Defender portal, navigate to Policies & rules > Threat policies > Email authentication settings > DKIM. Ensure DKIM is enabled and actively signing messages for your custom domain.
Ensure your domain has a published DMARC record. Create a TXT record for '_dmarc.yourdomain.com' with the value 'v=DMARC1; p=quarantine;' (or p=reject) to satisfy Apple's inbound mail requirements.

Isolate Content-Based Filtering Triggers
If domain authentication is correct, iCloud may be rejecting the message based on its internal contents, links, or attachments.
Try WPS Office for Your Daily Document Needs
While Microsoft 365 handles your email routing, you don't have to rely on expensive subscriptions for document creation. WPS Office provides a lightweight, highly compatible, and free alternative to Word, Excel, and PowerPoint.
- 1. Download the installer: Visit the official WPS Office website and click the free download button for your operating system.
- 2. Install the software: Run the downloaded installation file and follow the on-screen prompts to set up the software.
- 3. Open and edit your files: Launch WPS Office and directly open any existing Microsoft Word, Excel, or PowerPoint documents to begin editing immediately.

Frequently Asked Questions
Why am I getting Error 550 5.7.1 only when sending to iCloud addresses?
Error 550 5.7.1 indicates a security or policy rejection by the receiving server. Apple's iCloud servers use highly aggressive anti-spam and authentication checks. If your Microsoft 365 setup triggers these checks, Apple blocks the message, while other email providers with looser policies might let it through.
Do I absolutely need a DMARC record to send emails to Apple users?
Yes. Most major email providers, including Apple, Google, and Yahoo, now require senders to have a valid DMARC policy published in their DNS records alongside SPF and DKIM to verify the sender's identity and prevent spoofing.
How can I tell if my email content is causing the Apple policy rejection?
You can isolate the issue by sending a plain-text email with no links, attachments, or complex HTML formatting to the target iCloud address. If the simple email is delivered but the original email fails, Apple's automated filters are rejecting the specific content, links, or attachments inside your message.




