Skip to content
Docs

Troubleshooting

Every reply code the Emailit SMTP relay can return, with its cause and fix, plus blocked ports, TLS errors, timeouts and accepted mail that isn't delivered.

Updated Oct 1, 2026

Use this page when the SMTP relay rejects a message or your client can’t connect. Errors are grouped by the stage of the SMTP conversation where they happen, and each one lists its cause and fix.

Find the reply code

  • In your application. Mail libraries include the server’s reply in the error, for example Error: Invalid login: 535 Authentication failed in Nodemailer or SMTPAuthenticationError: (535, b'Authentication failed') in Python.
  • In Emailit. Email APILogs records each submitted message with the source SMTP and its reply code, as well as rate-limit rejections and failed logins for keys Emailit can identify. Filter by Status code or API key.
  • With a manual test. Run the cURL command from Send a test message with -v to see the whole conversation.

Codes that start with 4 are temporary: well-behaved clients retry them later. Codes that start with 5 are permanent: fix the cause before you send again.

Quick reference

Code and message Stage Section
535 Authentication failed AUTH Login errors
454 Temporary authentication failure AUTH Login errors
452 4.4.5 Messages per second limit exceeded MAIL FROM Rate limit errors
452 4.5.3 Daily message limit exceeded MAIL FROM Rate limit errors
451 Temporary local error in processing Any Temporary errors
501 Invalid RCPT TO RCPT TO Recipient errors
530 Authentication required RCPT TO Recipient errors
535 Mail server has been suspended RCPT TO Recipient errors
550 Unverified workspaces can only send to… RCPT TO Recipient errors
552 Message too large DATA Message errors
530 From/Sender domain is not verified for this workspace DATA Message errors
530 API key is restricted to sending domain DATA Message errors
550 Sending from this domain is paused DATA Message errors
550 Loop detected DATA Message errors
550 Message processing failed DATA Message errors
452 Insufficient credits to receive inbound email DATA Inbound errors

Login errors

These happen when your client sends AUTH.

535 Authentication failed

Cause. The password isn’t a valid API key for any workspace. The key may have a typo or extra whitespace, may have been deleted or regenerated, or may be an old key you replaced.

Fix. Copy the key again from where you stored it when you created it. Emailit shows keys only once, so if you no longer have it, create a new key in Email APIAPI Keys. Use emailit as the username and the full key, starting with secret_, as the password. See Why does SMTP return 535 Authentication failed?.

454 Temporary authentication failure

Cause. Emailit couldn’t check the key because of an internal error.

Fix. Retry after a short wait. If it continues for more than a few minutes, check status.emailit.com and contact support.

Rate limit errors

These happen when your client sends MAIL FROM to start a message.

452 4.4.5 Messages per second limit exceeded

Cause. Your workspace sent more messages in the last second than its per-second limit, which is 2 by default. The limit is shared with the API and counts each SMTP transaction as one message. The numbers in parentheses show the current count and the limit.

Fix. Most clients retry 452 automatically. To avoid it, send through a queue with limited concurrency, or reuse one connection and send messages one after another. If you need a higher rate, use Request Increase on the Sending Limits card of the dashboard home page. See Limits.

452 4.5.3 Daily message limit exceeded

Cause. The workspace reached its daily limit, which is 5,000 messages by default and shared with the API.

Fix. Sending resumes after midnight UTC. Request a higher daily limit from the Sending Limits card on the dashboard home page. Pro and Business workspaces also get automatic increases when their sending health is good.

Temporary errors

451 Temporary local error in processing

Cause. Emailit hit an internal error while handling the command. It can happen at any stage.

Fix. Retry later. Mail servers and most libraries do this automatically for 4xx replies. If it persists, contact support with the time of the attempt.

Recipient errors

These happen when your client sends RCPT TO for each recipient.

501 Invalid RCPT TO

Cause. The recipient address is malformed, for example it has no @ or nothing before or after it. The full message is Invalid RCPT TO format or Invalid RCPT TO.

Fix. Validate addresses before you send. Check for empty values and for display names passed where only an address is expected.

530 Authentication required

Cause. The client didn’t log in, or its login failed and it carried on anyway. Without a login, the relay only accepts mail for Emailit’s own inbound and bounce addresses.

Fix. Turn on SMTP authentication in your client and set the username and password. Check for an earlier 535 in the same session.

535 Mail server has been suspended

Cause. The workspace is suspended, usually because of a high bounce rate. See Sending health.

Fix. Contact support at support@emailit.com. Sending resumes after the suspension is lifted.

550 Unverified workspaces can only send to workspace members’ account emails

Cause. The workspace is in sandbox mode, and the recipient isn’t the account email of a workspace member. The message ends with the blocked address.

Fix. Test with a member’s account email, or request production access. See How do I test sending before my workspace is verified?.

Message errors

These happen after your client sends the message with DATA.

552 Message too large (maximum size 40MB)

Cause. The message, including encoded attachments, is larger than 40 MB. Base64 encoding makes attachments about a third larger than the files.

Fix. Send smaller attachments, or upload large files to your own storage and include a link.

530 From/Sender domain is not verified for this workspace

Cause. An address in the From header isn’t on a verified sending domain of the workspace that owns the key. Common reasons: the domain isn’t verified yet or is awaiting review, the From address is on a subdomain you didn’t add, the key belongs to a different workspace, or the message has no From header. The MAIL FROM envelope address doesn’t matter.

Fix. Check the domain’s status in Email APIDomains, make the From address match a verified domain exactly, and use a key from the same workspace. See Why does SMTP return 530 From domain not verified?.

530 API key is restricted to sending domain

Cause. The key is a Sending Only key restricted to one domain, and the From address is on another domain. The message names the allowed domain.

Fix. Send from the allowed domain, or use a key without a domain restriction.

550 Sending from this domain is paused

Cause. Emailit paused the From domain because its bounce rate went over 5%.

Fix. Find the source of the bounces and clean your list. See Sending health and Bounces and complaints.

550 Loop detected

Cause. The message has already passed through the Emailit relay more than four times, usually because forwarding rules send it back and forth.

Fix. Find and break the forwarding loop between your systems or mailboxes.

550 Message processing failed

Cause. Emailit accepted the data but couldn’t store the message.

Fix. Retry the message. If it fails again, contact support with the time of the attempt and the From and To addresses.

Inbound errors

452 Insufficient credits to receive inbound email

Cause. A message was sent to one of your inbound addresses, but the workspace has no credits left. Receiving an email costs 1 credit. The sending server gets this temporary error and retries later.

Fix. Top up your credits or turn on auto-refill. Mail that the sender retries arrives once credits are available.

Connection problems

Symptom Likely cause Fix
Connection times out or is refused Your ISP, hosting or cloud provider blocks the port. Port 25 is blocked on most cloud platforms, and some block 587. Use 587, then 2525 or 2587. See Why does my SMTP connection time out?.
wrong version number, or the connection hangs after connecting The TLS mode doesn’t match the port: implicit TLS on 587, or STARTTLS on 465. Use STARTTLS on 587, 2525, 2587 and 25, and implicit TLS only on 465.
Certificate name mismatch You connect by IP address or through your own host name. Connect to smtp.emailit.com.
Handshake fails on an old system The client can’t negotiate a modern TLS version, or its CA certificates are out of date. Update the runtime, OpenSSL and CA bundle.

See Why do I get TLS errors when connecting to SMTP? for more detail.

Accepted but not delivered

A 250 reply means Emailit accepted the message, not that it reached the inbox. Open the email in Email APIEmails using the ID from the reply and check its status:

  • Held: the workspace ran out of credits, the domain was paused, or the message scored 7 or more in spam checks. Fix the cause, then retry. See Why is my email held?.
  • Suppressed: the recipient is on your suppression list.
  • Attempted: the recipient’s server returned a temporary error. Emailit retries for about 21 hours.
  • Bounced or Failed: the delivery details show the receiving server’s response. See Bounces and complaints.

For a full checklist, see Why didn’t my email arrive?.

Still stuck?

Email support@emailit.com or ask in Discord. Include the time of the attempt, the port, your mail library, and the full reply from the server.

Was this page helpful?

Thanks for the feedback.

Thanks, we read every message.