550 5.7.520 Access denied — your organization does not allow external forwarding
What's actually happening
Your forwarding rule is fine. Microsoft 365's outbound spam policy blocks automatic forwarding to any address outside your tenant by default, so Exchange rejects the message at send time. It affects every external destination, not just the one you chose.
The fix — about two minutes as an admin
Open
security.microsoft.com→ Email & collaboration → Policies & rules → Threat policies → Anti-spam.Open Anti-spam outbound policy (Default) and choose Edit protection settings.
Set Automatic forwarding rules to On — Forwarding is enabled. Tighter option: leave the default off and create a new outbound policy scoped to just the one mailbox that forwards.
Save, then re-send a test email. Policy changes usually apply within the hour.
If it still fails
Run a message trace (admin.exchange.microsoft.com → Mail flow → Message
trace) and look at the failure reason. A remaining 5.7.520 means the policy
hasn't propagated or a different policy has higher priority. Also consider a
transport rule with a Bcc action instead of mailbox forwarding — it
bypasses this policy entirely; our
Microsoft 365 setup guide shows that route.