Skip to content
Help · Microsoft 365

550 5.7.520 Access denied — your organization does not allow external forwarding

550 5.7.520 Access denied
Your organization does not allow external forwarding. Please contact your administrator for further assistance. AS(7555)

What's actually happening

Your forwarding rule is fine. Microsoft 365's outbound spam policy blocks automatic forwarding to any address outside your tenant by default, so Exchange rejects the message at send time. It affects every external destination, not just the one you chose.

The fix — about two minutes as an admin

  1. Open security.microsoft.com → Email & collaboration → Policies & rules → Threat policies → Anti-spam.

  2. Open Anti-spam outbound policy (Default) and choose Edit protection settings.

  3. Set Automatic forwarding rules to On — Forwarding is enabled. Tighter option: leave the default off and create a new outbound policy scoped to just the one mailbox that forwards.

  4. Save, then re-send a test email. Policy changes usually apply within the hour.

If it still fails

Run a message trace (admin.exchange.microsoft.com → Mail flow → Message trace) and look at the failure reason. A remaining 5.7.520 means the policy hasn't propagated or a different policy has higher priority. Also consider a transport rule with a Bcc action instead of mailbox forwarding — it bypasses this policy entirely; our Microsoft 365 setup guide shows that route.

If you're doing this to share one address across a team: that's what Bosun is for — one forwarding rule, and everyone answers hello@ from their own login.