554 5.7.1 Relay access denied — the server will not pass your mail on
Retrying will not help. The message will not be delivered.
The reply
554 5.7.1 <user@example.com>: Relay access deniedPostfix's reply when a client asks it to deliver to a domain it does not host, without proving it is allowed to. The usual cause is a mail client or application sending without authentication.
What it means
A mail server accepts two kinds of mail: mail for its own domains, and mail from trusted clients to anywhere. Anything else would make it an open relay, so Postfix refuses at RCPT TO with "554 5.7.1 <address>: Relay access denied" — the reject_unauth_destination restriction. A trusted client is one whose address is in mynetworks or one that logged in over SASL. Other servers word the same refusal differently: "Relaying denied" in Sendmail, "relay not permitted" in Exim, "Unable to relay" in Exchange.
Why it happens
- The client sends without SMTP authentication: it is switched off in the settings, or the program fell back to port 25 without logging in.
- The application runs on a host that is not in mynetworks — a new server, a container, a changed IP — while the relay trusted it by address.
- A login and password are set for incoming mail (IMAP or POP3) only, and authentication for outgoing mail is off.
- The server should receive mail for the recipient's domain, but the domain is missing from mydestination, relay_domains or virtual_mailbox_domains, so the message looks like relaying.
What to do
- Turn on authentication in the client and send on port 587 (STARTTLS) or 465 (SSL/TLS) with a login and password.
- If the server is yours and should accept this mail, check that the recipient's domain is in mydestination, relay_domains or virtual_mailbox_domains.
- If an internal host has to send without a password, add it to mynetworks narrowly: one address, not a subnet.
- Read the server log: the postfix/smtpd lines show whether a login (sasl_username=) happened before RCPT TO.
- Do not fix this by opening the relay to everyone. An open relay is found and used for spam quickly, and its IP ends up on the blocklists.
Questions
454 4.7.1 or 554 5.7.1 — what is the difference?
It is the same refusal. Since 2.10, Postfix defaults to defer_unauth_destination, which answers with the temporary 454 4.7.1; reject_unauth_destination answers with the permanent 554 5.7.1. The fix is the same.
Why does it send from the office but not from the server?
The relay trusts the office network by address (mynetworks) and does not trust the server. Authenticate with a login and password instead of relying on the IP.
Does this mean my server is an open relay?
The opposite: this reply means the server refuses to be one. Worry if a test from outside, without logging in, gets 250 to RCPT TO for a foreign domain.