oeltayeb.com · Exchange Online Toolkit

Checklist

NDR 550 5.7.520: fixing “Your organization does not allow external forwarding”

Based on the article: NDR 550 5.7.520: fixing “Your organization does not allow external forwarding” · 4 min read

A user sets up a rule to forward mail to an outside address, or you configure forwarding on a mailbox for a partner, and the bounces start quoting 5.7.520. It isn't a bug: the outbound spam policy is doing exactly what it was designed to do. In this post I'll explain where the block comes from, how to allow forwarding only for the mailboxes that genuinely need it, and how to confirm the fix.

Symptoms to confirm

Messages that should be forwarded automatically to an external address never arrive, and a non-delivery report (NDR) like this comes back:

550 5.7.520 Access denied, Your organization does not allow external forwarding.
Please contact your administrator for further assistance. AS(7555)
  • Forwarding between internal mailboxes keeps working.
  • Message trace shows the forwarded copy to the external recipient as Failed.
  • Not every blocked forward bounces. Microsoft documents that an NDR is generated for messages from external senders whatever the forwarding method, and for internal senders when the mailbox uses admin-configured forwarding. When an Inbox rule forwards a message from an internal sender, the forward is blocked without an NDR.

Likely causes

Exchange Online has two kinds of automatic forwarding: Inbox rules that users create, and mailbox (SMTP) forwarding that admins configure.

  • Automatic - System-controlled is the default. Since 2021 it behaves like Off for new tenants and for tenants that weren't actively relying on it, but it can still mean On in some older tenants, so Microsoft recommends choosing On or Off explicitly.
  • On - Forwarding is enabled allows external automatic forwarding.
  • Off - Forwarding is disabled blocks it and returns the 5.7.520 NDR.
ControlWhere it livesWhat happens to the forward
Outbound spam policyMicrosoft Defender portalBlocked, NDR with 5.7.520
Remote domain (AutoForwardEnabled)Exchange admin center, Mail flow › Remote domainsSilently discarded, no NDR
Mail flow ruleExchange admin center, Mail flow › RulesDepends on the rule's action

Checklist

  1. 1

    Confirm the forward is legitimate

    The Auto forwarded messages report under Reports › Mail flow in the Exchange admin center shows who forwards externally, by which method and to which domains. For a single mailbox, check both forwarding methods in Exchange Online PowerShell (the first block below).

  2. 2

    Keep the default policy blocked, explicitly

    In the Defender portal, go to Email & collaboration › Policies & rules › Threat policies › Anti-spam, open Anti-spam outbound policy (Default) and set Automatic forwarding rules to Off - Forwarding is disabled.

  3. 3

    Create a scoped policy for the exceptions

    Select Create policy › Outbound and name it. On the Users, groups, and domains page, add the specific users or, better, a group you control.

  4. 4

    Check remote domains

    If the Default remote domain blocks automatic forwarding, forwards will now vanish silently instead of bouncing. To allow one partner domain only, create a remote domain for it (new remote domains allow automatic forwarding by default) and leave Default blocked.

  5. 5

    Check mail flow rules

    for anything that rejects or deletes auto-forwarded messages to recipients outside the organization, and add an exception for your allowed group if needed.

Verify

Give the policy change time to apply, send a test message from an external account to the forwarding mailbox, and trace the forwarded copy:

powershell
Get-MessageTraceV2 -RecipientAddress partner@fabrikam.com -StartDate (Get-Date).AddHours(-2) -EndDate (Get-Date) |
    Format-Table Received, SenderAddress, Subject, Status
  • Delivered: fixed.
  • Failed with 5.7.520 in the details: the mailbox isn't matched by your custom policy. Check group membership and that the policy is turned on.
  • Anything else, or no outbound record at all: look at remote domains, which discard forwards silently, and at any mail flow rules that act on auto-forwarded mail.

Prevent it next time

  • Keep Off as the explicit default and grant exceptions through a group with a named owner and a documented reason.
  • Review the Auto forwarded messages report regularly. The New users forwarding email and New domains being forwarded email insights in the Exchange admin center flag changes early.
  • Before allowing a forward, check whether a shared mailbox or delegate access would do the job without mail leaving the tenant.
  • Remember the pattern: a 5.7.520 points to the outbound spam policy, while forwards that disappear without one usually point to remote domains or mail flow rules.

Microsoft Learn references