Microsoft 365: “550 5.7.520 Access denied, Your organization does not allow external forwarding. AS(7555)” NDR Error.
End users start reporting that when people send them emails, the sender gets a bounce back with an error message “550 5.7.520 Access denied, Your organization does not allow external forwarding. AS(7555)” However, they (end users) receive these emails without any issues, which can be confusing. Microsoft 365 tenant outbound spam policy blocks external forwarding by default.
Root Cause: A mailbox has automatic forwarding to an external address while the tenant outbound spam policy blocks external forwarding.
Environment: MS Outlook, O365, Exchange Online
Error: 550 5.7.520 Access denied, Your organization does not allow external forwarding. AS(7555)
Fix: Remove the forward in Exchange Admin Center under Recipients → Mailboxes → Mail flow settings, or allow forwarding in the anti spam outbound policy if the forward is business approved.
Time: about 10 minutes
The Situation
A client called because senders were getting bounce backs when emailing one of their staff. The strange part was that nothing seemed broken from the inside. The mailbox received every message, the user could reply normally, and nobody in the org had changed anything recently. In this case, the mailbox in question had an automatic forwarding rule set up to send a copy of everything to a personal Gmail account. Microsoft 365 blocks that kind of external forwarding by default through the tenant outbound spam policy. So, Exchange Online was doing two things with every inbound message. 1) It delivered the message to the primary mailbox successfully, 2) then it attempted to send the same email to the external email(Gmail) too, but the policy rejected the forward, and Exchange generated an NDR tied to the original message. The sender got a scary bounce back for an email that was actually delivered to the primary mailbox but not the external Gmail. Once you know that, the error message reads completely differently. It is not saying your email was rejected. It is saying the external forward was rejected.
The Fix
There are two paths depending on what the client actually wants.
Fix A, allow external forwarding in the policy
Use this when the forward is legitimate and business approved. Go to the Microsoft Defender portal at security.microsoft.com Navigate to Email & collaboration → Policies & rules → Threat policies Under Policies, select Anti spam Open the outbound policy, typically named Anti spam outbound policy (Default) Find the Automatic forwarding rules setting and change it to On, forwarding is enabled Save
NOTE: Keep in mind this opens forwarding for the whole policy scope, not just one user. If only one mailbox needs it, create a custom outbound policy scoped to that user instead of changing the default.
Fix B, remove the forward
Use this when the forward should not exist, which was my situation, the client wanted the policy left disabled. Access the Exchange Admin Center Navigate to Recipients → Mailboxes Select the affected mailbox Open Mail flow settings → Forwarding Remove the external address and disable forwarding Save changes
Why Microsoft does this
Automatic forwarding to an external mailbox is one of the classic moves in a business email compromise. An attacker who gets into a mailbox quietly sets a forward rule to an address they control, then reads everything. Blocking external forwarding by default cuts that exfiltration path off. So the policy that generated this confusing bounce is actually protecting the tenant, which is worth explaining to the client before you go turning it off/on.
Prevention
Avoid external auto forwarding unless it is business approved. When someone just needs another person to read a mailbox, shared mailbox access is the better answer. Review the outbound spam policy before enabling any forwarding and prefer a scoped custom policy over changing the tenant’s default.