How to Fix Exchange Online Recipient Limit Errors by Updating Outbound Spam Policy

📄 Article

How to Fix Exchange Online Recipient Limit Errors by Updating Outbound Spam Policy

In Exchange Online, email sending restrictions can block legitimate communications if tenant-level recipient limits or outbound spam policies are set too low. In this case, a user encountered email delivery failures because the recipient count exceeded the configured limit of 25 recipients per message. During a remote troubleshooting session, the restriction was identified and resolved by adjusting the limits and updating the outbound spam policy.

🔍 The Symptoms / Error Message

⚠️ Non-Delivery Reports (NDRs) Similar To

“The message can’t be sent because it exceeds the maximum number of allowed recipients.”

or

“550 5.7.1 Recipient limit exceeded”

🧠 Root Cause

💡 Why This Happens

  • The maximum number of recipients per message is configured too low
  • The user is not included in an appropriate outbound spam policy, or the policy enforces strict limits

Exchange Online uses outbound spam filtering policies as part of Microsoft Defender for Office 365 to prevent abuse and limit bulk email sending. If these limits are exceeded, sending is restricted automatically.

🛠️ Step-by-Step Resolution

1

Open the Microsoft 365 Defender Portal

Navigate to security.microsoft.com

2

Navigate to Anti-Spam Policies

Go to: Email & Collaboration → Policies & Rules → Threat Policies, then click Anti-spam policies.

3

Locate and Edit the Outbound Spam Filter Policy

Find the relevant policy (e.g., Default or a custom policy) and open it for editing.

4

Update Outbound Spam Filter Settings

Adjust the recipient limits to match your organisation’s legitimate sending needs.

✅ Settings to Update

  • Increase Recipient limit per message
  • Adjust Recipient limits per day if required
5

Save the Policy Changes

Confirm and apply the updated settings.

6

Ensure the Affected User Is Assigned to the Policy

Without correct policy assignment, the new limits will not apply to the affected mailbox.

✅ Assignment Steps

  • Under Users, groups, and domains
  • Add the specific mailbox or group

💡 Best Practices & Recommendations

  • Use Least Privilege Access — assign only necessary users to high-recipient policies
  • Avoid Overly High Limits — excessive recipient limits may trigger Microsoft’s anti-abuse systems
  • Monitor Activity — use Message Trace and Defender reports to track outbound activity
  • Create Separate Policies — define custom outbound spam policies for bulk senders instead of modifying the default policy

💡 Related Scenarios

If you’re managing similar cases — such as domain blocks, bulk email restrictions, or spam flags — setting proper outbound policies proactively can save significant troubleshooting time during urgent incidents.

📚 References & Further Reading

Leave a Comment

Your email address will not be published. Required fields are marked *