# Enhanced status codes

> RFC 3463 enhanced status codes such as 5.1.1, 4.7.0 and 5.7.26 explained, with the usual cause behind each and what to change before you send again.

Enhanced status codes are the `x.y.z` codes that follow the three-digit reply in most SMTP responses. They're more precise than the [reply code](/docs/dictionary/smtp-reply-codes/), so they're the fastest way to understand why an email bounced or was deferred.

## How the code is built

An enhanced status code has three parts, `class.subject.detail`:

```text
550 5.1.1 The email account that you tried to reach does not exist.
    │ │ └─ detail: bad destination mailbox address
    │ └─── subject: addressing
    └───── class: permanent failure
```

| Class | Meaning |
|---|---|
| `2` | Success. |
| `4` | Persistent transient failure. The message might be delivered if it's sent again later. |
| `5` | Permanent failure. Sending the same message again won't work. |

| Subject | Area |
|---|---|
| `0` | Other or undefined. |
| `1` | Addressing: the sender or recipient address. |
| `2` | Mailbox: the recipient's mailbox, such as full or disabled. |
| `3` | Mail system: the receiving system, such as storage or size limits. |
| `4` | Network and routing: DNS, connections and timeouts. |
| `5` | Mail delivery protocol: SMTP commands and syntax. |
| `6` | Message content or media: encoding and conversion. |
| `7` | Security or policy: authentication, spam filtering and reputation. |

Emailit stores the enhanced code of every failed delivery. You see it with the full reply on the email's **Deliveries** tab, and as `smtp_enhanced_code` in `email.attempted` webhook events. Whether Emailit retries depends on the reply code and message, as described in [How Emailit handles replies](/docs/dictionary/smtp-reply-codes/#how-emailit-handles-replies-from-recipient-servers).

## Success codes

| Code | Meaning | Notes |
|---|---|---|
| `2.0.0` | Success. | Emailit's SMTP relay replies `250 2.0.0 OK: queued as em_...` when it accepts your message. |
| `2.1.5` | Destination address valid. | The recipient was accepted. |
| `2.6.0` | Message accepted. | Common in replies from Microsoft servers. |

## Temporary failures (4.x.x)

| Code | Meaning | Common cause | What to do |
|---|---|---|---|
| `4.2.1` | Mailbox temporarily unavailable. | The mailbox is receiving mail too quickly, or it's inactive. | Nothing for a single message. Emailit treats Gmail's "receiving mail at a rate" and "inactive mailbox" replies as permanent. |
| `4.2.2` | Mailbox full. | The recipient is over their storage quota. | Emailit treats common over-quota replies as hard bounces. Remove the address if it keeps happening. |
| `4.3.0` | Mail system problem. | A temporary fault on the receiving server. | Nothing. Emailit retries. |
| `4.4.1` | No answer from host. | The recipient's server didn't respond or the connection timed out. | Nothing for a single message. If a whole domain is affected, check that its MX records work. |
| `4.4.2` | Bad connection. | The connection dropped during the transaction. | Nothing. Emailit retries. |
| `4.4.5` | System congestion. | The receiving server is overloaded. Emailit's relay also uses this code when you exceed your per-second [sending limit](/docs/limits/). | Slow down. For Emailit's relay, keep under your per-second limit. |
| `4.5.3` | Too many recipients. | Too many recipients in one transaction. Emailit's relay also uses this code when you hit your daily sending limit. | For Emailit's relay, wait for the daily reset at 00:00 UTC or request a higher limit. |
| `4.7.0` | Temporary security or policy rejection. | Greylisting, or a provider throttling mail it considers suspicious, such as Gmail's "unusual rate of unsolicited mail". | Let Emailit retry. If it persists, check [sending health](/docs/deliverability/sending-health/), complaint rates and authentication. |
| `4.7.1` | Delivery temporarily not authorized. | Greylisting or a temporary policy block. | Let Emailit retry. |
| `4.7.28` | Rate limited (Gmail). | Gmail detected an unusual rate of unsolicited mail from your IP or domain. | Reduce volume to Gmail, clean your list and review complaints. |

## Permanent failures (5.x.x)

| Code | Meaning | Common cause | What to do |
|---|---|---|---|
| `5.0.0` | Permanent failure, no detail. | A generic rejection. | Read the message text for the reason. |
| `5.1.0` | Address error. | The address was rejected for an unspecified addressing reason. | Check the address for typos. |
| `5.1.1` | Bad destination mailbox. | The mailbox doesn't exist. | Remove the address. Emailit suppresses it if it hard bounces again within 24 hours. |
| `5.1.2` | Bad destination system. | The recipient's domain doesn't exist or has no mail server. | Check the domain for typos, such as `gmial.com`. |
| `5.1.3` | Bad destination address syntax. | The address isn't valid. | Fix the address, or [verify](/docs/email-verification/) your list before sending. |
| `5.1.8` | Bad sender's system address. | The receiving server couldn't resolve the envelope sender's domain. | Check that your return-path MX and SPF records on `emailit.yourdomain.com` are published. See [DNS records](/docs/domains/dns-records/). |
| `5.1.10` | Recipient has a null MX, or recipient not found. | RFC 7505 null MX. Microsoft also uses this code when the recipient doesn't exist. | Remove the address. |
| `5.2.1` | Mailbox disabled. | The account was closed or suspended. | Remove the address. |
| `5.2.2` | Mailbox full. | The recipient is over quota. | Try again much later, or remove the address if it keeps happening. |
| `5.2.3` | Message too long for the mailbox. | The message exceeds the recipient's size limit. | Reduce the message size. |
| `5.3.4` | Message too big for the system. | The message exceeds the receiving server's size limit. | Send smaller attachments, or link to files instead. |
| `5.4.1` | No answer from host, or access denied. | Microsoft uses it when a recipient is rejected at the edge, often because the address doesn't exist. | Check the address and remove it if it's invalid. |
| `5.4.4` | Unable to route. | The recipient's domain has no usable MX or A record. | Check the domain. |
| `5.5.0` | Protocol error. | The server rejected an SMTP command. | Contact support if it affects many recipients. |
| `5.7.0` | Security or policy rejection. | A generic policy block, often for spam or reputation. | Read the message text, and review content and list quality. |
| `5.7.1` | Delivery not authorized, message refused. | The recipient's server blocked the message or your IP: spam filtering, a blocklist, or the recipient only accepts mail from certain senders. | Read the message text. For blocklists, see [best practices](/docs/deliverability/best-practices/). Emailit pauses that IP-to-domain route for an hour on non-content blocks. |
| `5.7.8` | Authentication credentials invalid. | Wrong username or password, typically seen when your app logs in to an SMTP server. | For Emailit's relay, use an API key as the password. |
| `5.7.9` | Authentication mechanism too weak. | The server requires a stronger login method. | Use `PLAIN` or `LOGIN` over TLS with Emailit's relay. |
| `5.7.23` | SPF validation failed. | The sending IP isn't allowed by the SPF record of the envelope sender's domain. | Make sure the TXT record on `emailit.yourdomain.com` contains `include:_spf.emailit.com`. |
| `5.7.25` | Reverse DNS validation failed. | The sending IP has no matching PTR record. | Contact support. Emailit manages reverse DNS for its IPs. |
| `5.7.26` | Multiple authentication checks failed, or DMARC failed. | The message failed SPF and DKIM alignment, and the domain's DMARC policy says to reject. Gmail also uses it for unauthenticated mail. | [Verify your domain](/docs/domains/verification/) so DKIM passes, and check other services that send as your domain with [DMARC reports](/docs/dmarc/reports/). |
| `5.7.27` | Sender address has a null MX. | RFC 7505 null MX on the sender's domain. Gmail also uses it when SPF doesn't pass. | Check your return-path and SPF records. |
| `5.7.509` | Access denied, DMARC failed (Microsoft). | Outlook.com rejected the message because it failed DMARC and your policy is `reject`. | Fix SPF and DKIM for the sending service, then review your [DMARC policy](/docs/dmarc/set-up/). |
| `5.7.515` | Access denied, authentication level not met (Microsoft). | Outlook.com requires SPF, DKIM and DMARC to pass for high-volume senders. | Publish a DMARC record and make sure your domain is verified in Emailit. |
| `5.7.606` | Access denied, banned sending IP (Microsoft). | The sending IP is on Microsoft's block list. | Contact support with the full reply. |

> **Providers use codes differently:** The RFCs define the general meaning, but mailbox providers often reuse codes for their own reasons. The message text after the code is usually more specific, so read it before you decide what to change.

## Related

- [SMTP reply codes](/docs/dictionary/smtp-reply-codes/)
- [Bounce categories](/docs/dictionary/bounce-categories/)
- [Bounces and complaints](/docs/deliverability/bounces-and-complaints/)
- [Email details](/docs/logs/email-details/)

---
Source: https://emailit.com/docs/dictionary/enhanced-status-codes/
