How to Fix Microsoft 365 Relay Access Denied (Error 554 5.7.1) and Update MX Records
Question details
Users are experiencing complete mail-flow failure and receiving the error code 554 5.7.1 Relay access denied when attempting to send or receive emails.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- A business is completely unable to send or receive messages because incoming and outgoing emails are being rejected by the mail server.
- Observed behavior
- The system returns an error stating '554 5.7.1 Relay access denied', which usually indicates the domain's MX record is incorrectly pointing to a third-party mail service rather than Microsoft 365.
Ensure you have global administrator access to your Microsoft 365 admin center and the login credentials for your domain's DNS hosting provider (such as GoDaddy, Cloudflare, or Namecheap).
Verify and Update Your Domain's MX Record
Use this solution to ensure your domain's DNS settings route incoming emails to Microsoft 365 rather than an expired or third-party email host.
The most common cause of the 'Relay access denied' error is an incorrect or outdated MX (Mail Exchanger) record. If your MX record points to a previous host (like mx1.titan.email), Microsoft 365 will fail to process the mail flow.
Navigate to the website of the company where you registered your domain or where your DNS is hosted, and log into your account dashboard.
Find the section labeled 'DNS Management', 'Advanced DNS', or 'Name Server Settings' for the specific domain experiencing the issue.
Look through your list of DNS records for any entries of the type 'MX'. Identify if they are pointing to third-party services instead of Microsoft.
Edit the MX record to point to your specific Microsoft 365 mail server (usually formatted as yourdomain-com.mail.protection.outlook.com) with a priority of 0. Save the changes.

Check Domain Registration and Expiration Status
Verify that your domain name has not expired, as an expired domain will drop its active DNS records and break your mail flow.
Open a Service Request in the Microsoft 365 Admin Center
If your DNS records are correct and the issue persists, contact Microsoft Support to inspect your tenant's internal routing configuration.
Looking for a Lightweight Alternative to Microsoft 365?
While you troubleshoot complex domain and email routing issues in Microsoft 365, consider WPS Office as a free, lightweight, and easy-to-use alternative for your daily document productivity. It offers robust tools without requiring complicated administrative setups.
- 1. Download the installer: Visit the official WPS Office website and click the free download button.
- 2. Install the suite: Run the downloaded file and follow the simple on-screen instructions to install WPS Office on your computer.
- 3. Start creating documents: Open WPS Writer, Spreadsheet, or Presentation and immediately begin working with your existing Microsoft Office files.

Frequently Asked Questions
What does error 554 5.7.1 Relay Access Denied mean?
This error means the receiving email server refuses to accept and deliver the email. In a Microsoft 365 environment, this typically happens when the domain's MX records point to a server that does not recognize your tenant, or when your domain isn't fully configured in the Admin Center.
Where can I find the correct MX record value for my Microsoft 365 domain?
You can find your specific MX record value by logging into the Microsoft 365 Admin Center, navigating to Settings > Domains, selecting your domain, and clicking on the 'DNS records' tab to view the required Exchange Online settings.
Will fixing the MX record immediately restore my email flow?
Not always immediately. While you update the MX record instantly on your host's side, DNS changes require propagation time. It can take anywhere from a few minutes to up to 48 hours for the rest of the internet to recognize the new routing instructions.
What should I do if my domain was purchased through a reseller?
If you purchased your Microsoft 365 subscription or domain through a third-party reseller (like GoDaddy or AppRiver), you may not have direct access to standard Microsoft support. You should contact your reseller's technical support team directly to help adjust your mail flow configuration.




