Exchange OnlineTroubleshooting

NDR 550 5.7.520: fixing “Your organization does not allow external forwarding”

Why Exchange Online blocks automatic forwarding to external addresses with 5.7.520, and how to allow it only for the mailboxes that need it instead of for everyone.

A user sets up a rule to forward mail to an outside address, or you configure forwarding on a mailbox for a partner, and the bounces start quoting 5.7.520. It isn't a bug: the outbound spam policy is doing exactly what it was designed to do. In this post I'll explain where the block comes from, how to allow forwarding only for the mailboxes that genuinely need it, and how to confirm the fix.

How this guide is organised: Symptoms → Why it happens → How to fix it → Verify the fix → Prevent it next timeFlow diagram of the article's sections in reading order: 1. Symptoms. 2. Why it happens. 3. How to fix it. 4. Verify the fix. 5. Prevent it next time. Toolbox: Mail flow › Rules, Reports › Mail flow, AutoForwardEnabled, Threat policies › Anti-spam, Create policy › Outbound.1Symptoms2Why it happens3How to fix it4Verify the fix5Prevent it nexttimeTOOLBOXMail flow › RulesReports › Mail flowAutoForwardEnabledThreat policies › Anti-spamCreate policy › OutboundHow this guide is organised: Symptoms → Why it happens → How to fix it → Verify the fix → Prevent it next timeFlow diagram of the article's sections in reading order: 1. Symptoms. 2. Why it happens. 3. How to fix it. 4. Verify the fix. 5. Prevent it next time. Toolbox: Mail flow › Rules, Reports › Mail flow, AutoForwardEnabled, Threat policies › Anti-spam, Create policy › Outbound.1Symptoms2Why it happens3How to fix it4Verify the fix5Prevent it next timeTOOLBOXMail flow › RulesReports › Mail flowAutoForwardEnabledThreat policies › Anti-spamCreate policy › Outbound
At a glance: how this guide is organised · 5 sections · 5 key tools

Symptoms#

Messages that should be forwarded automatically to an external address never arrive, and a non-delivery report (NDR) like this comes back:

Text
550 5.7.520 Access denied, Your organization does not allow external forwarding.
Please contact your administrator for further assistance. AS(7555)
  • Forwarding between internal mailboxes keeps working.
  • Message trace shows the forwarded copy to the external recipient as Failed.
  • Not every blocked forward bounces. Microsoft documents that an NDR is generated for messages from external senders whatever the forwarding method, and for internal senders when the mailbox uses admin-configured forwarding. When an Inbox rule forwards a message from an internal sender, the forward is blocked without an NDR.

Why it happens#

Exchange Online has two kinds of automatic forwarding: Inbox rules that users create, and mailbox (SMTP) forwarding that admins configure. Both are governed by the Automatic forwarding rules setting in outbound spam policies:

  • Automatic - System-controlled is the default. Since 2021 it behaves like Off for new tenants and for tenants that weren't actively relying on it, but it can still mean On in some older tenants, so Microsoft recommends choosing On or Off explicitly.
  • On - Forwarding is enabled allows external automatic forwarding.
  • Off - Forwarding is disabled blocks it and returns the 5.7.520 NDR.

Blocking is the safe default for a reason. Attackers who compromise a mailbox often add a quiet forwarding rule to an outside address, and automatic forwarding is an easy way for data to leave unnoticed. Two other controls can also stop external forwarding, and when settings disagree, the block generally wins:

ControlWhere it livesWhat happens to the forward
Outbound spam policyMicrosoft Defender portalBlocked, NDR with 5.7.520
Remote domain (AutoForwardEnabled)Exchange admin center, Mail flow › Remote domainsSilently discarded, no NDR
Mail flow ruleExchange admin center, Mail flow › RulesDepends on the rule's action

How to fix it#

  1. Confirm the forward is legitimate. The Auto forwarded messages report under Reports › Mail flow in the Exchange admin center shows who forwards externally, by which method and to which domains. For a single mailbox, check both forwarding methods in Exchange Online PowerShell (the first block below). If nobody asked for a rule you find, treat it as a possible account compromise, not a forwarding request.
  2. Keep the default policy blocked, explicitly. In the Defender portal, go to Email & collaboration › Policies & rules › Threat policies › Anti-spam, open Anti-spam outbound policy (Default) and set Automatic forwarding rules to Off - Forwarding is disabled.
  3. Create a scoped policy for the exceptions. Select Create policy › Outbound and name it. On the Users, groups, and domains page, add the specific users or, better, a group you control. Under Forwarding rules, set Automatic forwarding rules to On - Forwarding is enabled, then create the policy. Only the first matching policy applies to a sender, so copy any message limits you customized in the default policy. The PowerShell equivalent is the second block below.
  4. Check remote domains. If the Default remote domain blocks automatic forwarding, forwards will now vanish silently instead of bouncing. To allow one partner domain only, create a remote domain for it (new remote domains allow automatic forwarding by default) and leave Default blocked. Remote domains apply to everyone, so the outbound policy stays your per-user gate.
  5. Check mail flow rules for anything that rejects or deletes auto-forwarded messages to recipients outside the organization, and add an exception for your allowed group if needed.
PowerShell
# 1. Forwarding configured on the mailbox and in Inbox rules
Get-Mailbox -Identity adele@contoso.com | Format-List ForwardingSmtpAddress, ForwardingAddress, DeliverToMailboxAndForward
Get-InboxRule -Mailbox adele@contoso.com |
    Where-Object { $_.ForwardTo -or $_.RedirectTo -or $_.ForwardAsAttachmentTo } |
    Format-List Name, Enabled, ForwardTo, RedirectTo, ForwardAsAttachmentTo
PowerShell
# 3. Scoped outbound policy that allows forwarding for one group
New-HostedOutboundSpamFilterPolicy -Name "Allow external forwarding" -AutoForwardingMode On
New-HostedOutboundSpamFilterRule -Name "Allow external forwarding" `
    -HostedOutboundSpamFilterPolicy "Allow external forwarding" -FromMemberOf "Forwarding-Allowed"

# 4. Remote domain settings
Get-RemoteDomain | Format-Table Name, DomainName, AutoForwardEnabled
New-RemoteDomain -Name "Fabrikam" -DomainName fabrikam.com

Verify the fix#

Give the policy change time to apply, send a test message from an external account to the forwarding mailbox, and trace the forwarded copy:

PowerShell
Get-MessageTraceV2 -RecipientAddress partner@fabrikam.com -StartDate (Get-Date).AddHours(-2) -EndDate (Get-Date) |
    Format-Table Received, SenderAddress, Subject, Status
  • Delivered: fixed.
  • Failed with 5.7.520 in the details: the mailbox isn't matched by your custom policy. Check group membership and that the policy is turned on.
  • Anything else, or no outbound record at all: look at remote domains, which discard forwards silently, and at any mail flow rules that act on auto-forwarded mail.

Prevent it next time#

  • Keep Off as the explicit default and grant exceptions through a group with a named owner and a documented reason.
  • Review the Auto forwarded messages report regularly. The New users forwarding email and New domains being forwarded email insights in the Exchange admin center flag changes early.
  • Before allowing a forward, check whether a shared mailbox or delegate access would do the job without mail leaving the tenant.
  • Remember the pattern: a 5.7.520 points to the outbound spam policy, while forwards that disappear without one usually point to remote domains or mail flow rules.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)