550 5.2.1 The email account that you tried to reach is inactive
Last updated 2026-09-03
The receiving server found the mailbox you wrote to, and then it refused the message.
The bounce reads 550 5.2.1.
RFC 3463 assigns those digits
to a mailbox that exists and is not accepting messages. Your DNS records did not cause
this, and editing them will not clear it. Someone who runs mail for that
address owns the fix. The last section of this page is the message to send that admin.
What it means. The destination mailbox exists, and the receiving server will not accept mail for it. Gmail's SMTP table prints 550 5.2.1 The email account that you tried to reach is inactive. RFC 3463 names the same digits Mailbox disabled, not accepting messages.
What to change. Read the words after 5.2.1. inactive or disabled is a mailbox state only their admin can reverse. A sentence about receiving email at a rate that prevents delivery is a receive-rate refusal. Text naming a content filter is a different job.
When it clears. The mailbox has to accept mail again before a new copy lands. Resend the same message and you get the same bounce. Write to the admin instead.
Gmail prints inactive; live NDRs still print disabled
Google's Gmail SMTP error table lists two rows under 550 5.2.1. The first is the inactive-account sentence.
Live bounces quoted on Google's own help community still print disabled in
place of inactive, with the same help URL. I copied this form from those
threads, with the NDR still attached.
A log that wraps the reply across two SMTP lines puts a hyphen on the first line. RFC 5321 defines that form. A hyphen after the code means more text follows. A space means the reply ends there.
The help parameter is DisabledUser on every variant. When I opened
that URL, Google served
the generic Fix bounced or rejected emails article. It does not document the inactive
account itself. The SMTP table is the page that names the cause.
Outlook wraps a Microsoft-side bounce under Your message couldn't be delivered. A Gmail bounce arrives from Mail Delivery Subsystem.
Gmail reuses 5.2.1 for a receive-rate refusal
The second 550 5.2.1 row in Google's table is a different refusal. It names the rate at which that mailbox is receiving mail, not the account's enabled state.
The temporary twin uses the same sentence with 450 4.2.1, and it tells you to resend later. The 550 form is permanent for the message you just sent. Neither string is a disabled mailbox. Slow down, or wait, rather than writing to their admin about a suspension that nobody ordered.
RFC 3463 gives 5.2.1 to a mailbox that exists
RFC 3463 section 3.3 prints the definition in two sentences: "The mailbox exists, but is not accepting messages. This may be a permanent error if the mailbox will never be re-enabled or a transient error if the mailbox is only temporarily disabled." The leading 5 or 4 is what tells your server which of those two the receiver chose.
The same section says mailbox issues "are assumed to be under the general control of the recipient." The person who can re-enable the mailbox sits inside the receiving organisation. You cannot do that from outside.
550 5.1.1 is the neighbouring code for a mailbox the server never found. 5.2.1 means it found one and then refused it. The two bounces feel the same from your inbox. The directory work on their side is not the same.
Exchange Online's public table has no 5.2.1 row
Microsoft's
Exchange Online NDR table
has no row for 5.2.1. Do not treat a Microsoft 365 bounce as 5.2.1 from
the digits alone if the words say something else. If the bounce is 5.2.121 or 5.2.122,
you are still on the right page for the prefix. Those two rows are documented.
-
5.2.121
Recipient's per hour message receive limit from specific sender exceeded. One sender hit the hourly cap to that one mailbox. -
5.2.122
Recipient's per hour message receive limit exceeded. The mailbox hit its hourly cap from all senders.
Both are receive-rate throttles, not a disabled mailbox. Microsoft's Mailboxes exceeding receiving limits report is the admin view for diagnosing them. Slow down and retry later. Do not write to their admin about a suspension.
On-premises Exchange documents a different 5.2.1.
Microsoft's Exchange Server NDR page
lists 5.2.1 as Content Filter agent quarantined this message.
That bounce is a spam quarantine. The mailbox is still enabled.
Email quarantined covers that family. If your
bounce names the Content Filter agent, work that page.
Live Exchange NDRs, mostly from on-premises threads, have quoted a store-driver line with 5.2.1 as the enhanced status code. The leading SMTP code on this live string is 554, not 550. The enhanced status code is still 5.2.1.
Support threads quote that string with the NDR still attached. Microsoft Learn does
not print it. Read the exception name if it is in your bounce:
AccountDisabledException and MapiExceptionMailboxDisabled are
the words that name a disabled mailbox.
Removing a Microsoft 365 license does disable the mailbox. Microsoft's license-removal article says Exchange Online "immediately disconnects (disables) the mailbox if the Exchange Online license for the user is removed or expires." That article never prints 5.2.1. Microsoft Q&A staff have pointed senders at 550 5.4.1 Recipient address rejected: Access denied instead. I cannot verify a single current Exchange Online bounce string for a delicensed mailbox, so I will not invent one.
What a sender can confirm, then stop
Copy the words after 5.2.1 before you close the bounce. inactive and
disabled are mailbox state. Receiving-at-a-rate is a limit. Content Filter
is a quarantine. 5.2.121 or 5.2.122 is an Exchange Online
hourly receive cap.
Compare the address in the bounce against the one you meant, letter by letter, the part after the @ included. Delete that person from Outlook Auto-Complete and type the address by hand. A retyped address that bounces the same way is not a cache problem.
Then use another channel. Phone the person, or ask a colleague. Mail is the one route that no longer reaches them. Ask whether the account was suspended, whether they still work there, and what address to use now.
One Microsoft 365 or Google Workspace domain bouncing, with every other domain going through, points at that mailbox. Every address at the domain bouncing the same way points at a domain-wide disable, a license batch, or a suspended tenant. After that, stop resending. 550 permanent failure covers what that leading 5 commits your own server to.
Receiving admins: re-enable the mailbox
A sender cannot switch a disabled mailbox back on. If you administer the domain in the bounce, the mailbox state is yours to reverse: restore the account, put the license back, or reconnect the store. Every sender writing to that address reads the same refusal, and the report goes to them instead of you.
- Google Workspace: you suspended the user. In the Admin console, open Directory > Users and find the account. An admin-initiated suspension blocks new mail, and Gmail answers 5.2.1. Restore the user if that suspension was a mistake. If the person left, give senders a live address rather than leaving the bounce in place.
- Google Workspace: Google suspended the account. Google's suspend-a-user page says a Google-initiated suspension (Terms of Service, a compromised account, or similar) might still deliver mail, depending on context. That case does not reliably produce a clean 5.2.1. Do not restore the user first. Follow Google's suspended-account guidance and resolve whatever triggered the suspension. Google's restore page says an admin cannot restore an account Google suspended for abuse or a Terms of Service breach.
- Microsoft 365: the license and the mailbox. Microsoft's steps for the neighbouring code 5.1.10 send an admin to Users and then Active users. Confirm the account exists and holds an Exchange Online license. Reassign the license within 30 days if it was removed, because Microsoft deletes the mailbox after that. A shared mailbox does not need a user license and still accepts mail.
-
On-premises Exchange: the mailbox is disabled, or the content filter ate
it.
Get-MailboxandGet-MailboxStatisticsshow a disconnected mailbox. Microsoft's disconnected-mailbox page is the reconnect path. If the bounce names the Content Filter agent, the mailbox is fine and the filter quarantined the message. -
Quota is a different code. RFC 3463 assigns mailbox-full to X.2.2,
and it says that code should be a persistent transient failure. Gmail's table prints
552 5.2.2 The recipient's inbox is out of storage space and inactive. Secondary pages fold quota into 5.2.1. Gmail's table and Exchange Online's table put storage on 5.2.2. If your bounce names storage or quota, work 5.2.2.
Postfix has no shipped 5.2.1 sentence for a disabled mailbox. An operator who wants
that code adds a check_recipient_access map and writes the reply by hand.
A default Postfix unknown-user rejection is still
550 5.1.1 User unknown.
Send the receiving admin this
Nobody who can re-enable that mailbox has seen your bounce. Paste this, with the address and the exact line filled in.
Keep inactive, disabled or
AccountDisabledException in the pasted line. An admin searching those
tokens opens the user account. Stripping the bounce down to 550 points them at
anti-spam instead.
The person who can restore that mailbox is rarely the one you wrote to. Call a colleague at the company, try a shared inbox that still answers, or ask the account manager on the contract. Forward the bounce itself; the exception name in it is what their admin will search for.
SPF, DKIM and DMARC did not cause this
The documented 5.2.1 check reads the destination mailbox. Gmail's SMTP table never mentions authentication on either 5.2.1 row. Publishing a DMARC record does not re-enable someone else's account, and tightening one does not disable it either.
Rejections that do come from your records name them in the text. 550 5.7.26 says the message is unauthenticated. 550 5.7.23 names SPF. Why an email bounces back covers reading any bounce, whichever system sent it.
550 5.2.1 against the codes it gets confused with
The digits collide with neighbouring codes. Match the sentence in the bounce, not only the 5.2.1 prefix.
| Code | Text in the bounce | What it means |
|---|---|---|
| 550 5.2.1 | The email account that you tried to reach is inactive / disabled | The receiving server found the mailbox and it is not accepting mail |
| 550 5.2.1 | receiving email at a rate that prevents additional messages | Gmail's receive-rate cap, not a disabled account |
| 5.2.121 / 5.2.122 | per hour message receive limit (from specific sender / exceeded) | Exchange Online hourly receive throttle; use the Mailboxes exceeding receiving limits report |
| 550 5.1.1 | The email account that you tried to reach does not exist | The server looked the address up and found no mailbox behind it |
| 550 5.4.1 | Recipient address rejected: Access denied (often with an AS suffix) | Directory-Based Edge Blocking refused the address at Exchange Online's perimeter |
| 552 5.2.2 | The recipient's inbox is out of storage space and inactive | Gmail found the mailbox and it is over quota |
| 5.2.1 | Content Filter agent quarantined this message | On-premises Exchange quarantined the message, mailbox still enabled |
Directory-Based Edge Blocking answers 5.4.1 at the perimeter when the address is not a recipient object. That is a missing address, not a disabled mailbox. 550 5.4.1 Recipient address rejected covers it. If the wording in your bounce is "Access denied" and the digits are 5.4.1, read that page instead of this one.
You fixed this sender. Tomorrow the reports name the other hosts still sending as you, and we turn a day of XML into one email with a verdict per sender. On the paid plans, the day a report first names a new sender failing, you hear about it. Get the weekly digest. The first domain is free.
Watch failing sources on your domain
DomainCanary is our product, and this paragraph sells the paid plan. A disabled mailbox never reaches our parser. Receivers already send aggregate reports about your own domain: which hosts sent as you, and which of them failed alignment. On a paid plan we mail you the day a report first names a failing source with no history on your domain. Pro costs $19 a month for 5 domains. One weekly digest covers every domain that shares a digest address. History on every plan, including free, runs 12 months or more. Free for your first domain.
Alert me on a new failing sourceNo card · 12+ months of history · The free plan does not expire
Questions
What does 550 5.2.1 mean?
The receiving server found the mailbox and refused to accept mail for it. RFC 3463 calls X.2.1 Mailbox disabled, not accepting messages. Gmail's SMTP table prints The email account that you tried to reach is inactive. The leading 5 makes that refusal permanent for the message you just sent.
Can the sender fix 550 5.2.1?
Usually not. A sender can confirm the address, can drop a stale Auto-Complete entry, and can ask the person by phone or through a colleague. Once the spelling checks out, only an admin at the receiving end can re-enable the mailbox, restore a license, or lift a suspension. Resending the same message draws the same bounce.
Does 550 5.2.1 mean my SPF or DMARC is broken?
No. The documented 5.2.1 check reads the state of the destination mailbox. It does not read a record you publish. Gmail's SMTP table never mentions those checks on either of its 5.2.1 rows. Rejections that do name a failed check use codes such as 550 5.7.26.
Why do I get 550 5.2.1 for an address that used to work?
The mailbox still exists, which is why this is not 5.1.1. The usual causes are an admin-initiated suspension, a removed Microsoft 365 license, or a mailbox disabled on purpose. A Google-initiated suspension is a different case, covered in the admin steps below. Ask the person by another channel what to use now.
Gmail said the user is receiving email at a rate that prevents delivery. Same page?
The digits match and the job does not. Gmail's SMTP table lists that sentence as a second 550 5.2.1, next to the inactive-account row. Treat it as a receive-rate refusal. The temporary twin is 450 4.2.1. Work the section below that quotes the rate string.