The Tenant External Recipient Rate Limit (TERRL) is the maximum number of external recipients that an entire Exchange Online tenant can send to in a 24-hour sliding window. For a standard tenant it is calculated as 500 * (non-trial email licenses ^ 0.7) + 9500, with reduced quotas for new tenants and a separate formula for free EDU licenses from September 2026. When the tenant goes over, every sender gets 550 5.7.233 for external mail until usage falls back under the quota. You monitor it in the Exchange admin center's Tenant Outbound External Recipients report or with Get-LimitsEnforcementStatus.
Who this is for and what you will have
This guide is for Exchange Online administrators whose users or applications send a lot of external email, and for anyone who has just seen a whole tenant stop sending to the internet with a 5.7.233 bounce. At the end you will:
- Understand how the quota is calculated, including the changes Microsoft announced on August 13, 2026.
- Know exactly what counts against it and what doesn't.
- Have a PowerShell check you can schedule to warn you before the tenant is blocked.
- Have a procedure to recover from a block and to stop it from happening again.
How TERRL differs from the per-mailbox limits
Exchange Online has applied per-mailbox sending limits for a long time. TERRL adds a tenant-wide limit on top of them:
| Limit | Scope | Value | What happens when exceeded |
|---|---|---|---|
| Recipient rate limit | Per mailbox | 10,000 recipients per day | That mailbox can't send until its 24-hour count drops |
| Message rate limit | Per mailbox | 30 messages per minute | Extra submissions are throttled into following minutes |
| Outbound spam policy limits | Per user (policy scoped) | 0 to 10,000 per hour or per day (0 = service default) | Restrict, restrict until next day, or alert only |
| TERRL | Whole tenant | Calculated from licenses | All senders blocked from external recipients with 550 5.7.233 |
The difference matters during an incident. A single compromised mailbox or misconfigured application can use up the tenant quota and block external mail for every user. Outbound spam policy limits apply per user and don't increase the tenant quota.
How the quota is calculated
Standard tenants
The daily quota grows with the number of email licenses, meaning any license that includes Exchange Online or Exchange Online Protection, but at a decreasing rate per license:
TERRL = 500 * (Number of Non-trial Email Licenses ^ 0.7) + 9500Microsoft's published examples:
| Non-trial, non-EDU email licenses | TERRL (external recipients per 24 hours) |
|---|---|
| 1 | 10,000 |
| 10 | 12,006 |
| 25 | 14,259 |
| 100 | 22,059 |
| 1,000 | 72,446 |
| 10,000 | 324,979 |
| 100,000 | 1,590,639 |
The count uses the total number of email licenses the tenant has, not the number that are assigned.
Changes rolling out from September 14, 2026
The Exchange Team's August 13, 2026 update changes the calculation for some tenants:
| Tenant | Quota |
|---|---|
| New tenant, less than 31 days old | 10% of the standard calculated quota |
| New tenant, 31 to 60 days old | 25% of the standard calculated quota |
| New tenant, more than 60 days old | 100% of the standard calculated quota |
| Tenant with free EDU licenses (such as Microsoft 365 A1) | 500 * (Purchased Email Licenses ^ 0.7 + Free EDU Licenses ^ 0.3) + 9500 |
The EDU formula means free licenses now add to the quota, but much less than purchased licenses.
For trial tenants, the updated Exchange Team post lists a limit of 500 external recipients per day regardless of license count. At the time of writing, the Exchange Online limits service description and the Defender troubleshooting article still give 5,000. Because the published figures differ, read the actual value from the report or cmdlet rather than relying on either number.
The same update postponed TERRL for the GCC, GCCH, DoD and 21Vianet environments. In the worldwide environment, TERRL is fully implemented.
What counts against the quota
An external recipient is any recipient whose domain isn't an accepted domain in your tenant. That includes recipients in other Microsoft 365 tenants.
Counted:
- Every external recipient on every message. Sending 1,000 messages to the same address counts as 1,000, because TERRL doesn't track unique recipients.
- Every external member of a distribution group, after the group and any nested groups are fully expanded. A message to a group with 1,000 external members counts as 1,000.
- Mail relayed through Exchange Online from on-premises servers, applications or the internet to external recipients.
- Cross-tenant messages within a multitenant organization (currently treated as external).
Not counted:
- Journaling messages from Exchange Online journaling rules.
- Automatic replies, including Out of Office.
- Delivery status notifications: NDRs, delivery receipts and read receipts.
- Messages sent with Azure Communication Services Email and Exchange Online High Volume Email.
- Notifications from Microsoft cloud apps such as SharePoint and Teams.
- Mail to hybrid on-premises mailboxes whose addresses use an accepted domain.
A subdomain isn't automatically internal. Mail to a subdomain counts as internal only if the subdomain is itself an accepted domain, or if the root accepted domain is an internal relay domain with Accept mail for all subdomains enabled. Messages routed out to a signature service and back are now counted once. Microsoft has fixed an earlier double-counting problem.
A separate limit applies to the default onmicrosoft.com domain: 100 external recipients per organization in a rolling 24-hour window, with 550 5.7.236 bounces when it's exceeded. If an application still sends from contoso.onmicrosoft.com, move it to a custom domain.
Monitor TERRL
Exchange admin center report
- Open the mail flow reports at
https://admin.exchange.microsoft.com/#/reports/mailflowreportsmain(Reports > Mail flow). - Select Tenant Outbound External Recipients.
- Review the current external recipient volume, the daily quota, the share already used, the number of blocked recipients and the Enforcement state.
If Enforcement shows Disabled, nothing is being blocked, even if the report shows the quota exceeded and recipients as blocked.
PowerShell
Connect-ExchangeOnline -UserPrincipalName admin@contoso.com
Get-LimitsEnforcementStatus| Property | Meaning |
|---|---|
Verdict | Block means the tenant is over its quota and external mail is blocked (if enforcement is enabled). None means it's under the quota. |
EnforcementEnabled | True means blocking happens when the quota is exceeded. False means it doesn't, even if Verdict is Block. |
Threshold | The tenant's TERRL quota. |
ObservedValue | External recipients sent in the last 24 hours. |
Microsoft's FAQ notes that it doesn't currently send an alert specifically when you approach the quota. Its stated plan was a system alert at 80%. Until that alert is in your tenant, a scheduled check gives you warning. This example uses only the four documented properties:
# Run on a schedule (for example every hour) with app-only auth to Exchange Online
$status = Get-LimitsEnforcementStatus
$percent = [math]::Round(($status.ObservedValue / $status.Threshold) * 100, 1)
if ($percent -ge 80 -or $status.Verdict -eq 'Block') {
Write-Warning ("TERRL at {0}% ({1} of {2}). Verdict: {3}. Enforcement: {4}" -f `
$percent, $status.ObservedValue, $status.Threshold, $status.Verdict, $status.EnforcementEnabled)
# Send the warning to your monitoring system here
}Also check that the default alert policies are on in the Microsoft Defender portal at Email & collaboration > Policies & rules > Alert policy. Microsoft's outbound limits troubleshooting article associates the Email sending limit exceeded alert with TERRL being exceeded, and the User restricted from sending email and Suspicious email sending patterns detected alerts catch the compromised accounts that often cause a spike.
When users report 550 5.7.233
The bounce text for a paid tenant is:
550 5.7.233 - Your message can't be sent because your tenant exceeded its daily limit for sending email to external recipients (tenant external recipient rate limit)Trial tenants get 550 5.7.232 with similar wording.
Step 1: Confirm it's TERRL
Run Get-LimitsEnforcementStatus. A Verdict of Block with EnforcementEnabled set to True confirms that the tenant quota is the cause. If only one user is affected and the bounce is 5.1.8 instead, the cause is a restricted user, not TERRL. See Fix 550 5.1.8 Access denied, bad outbound sender.
Step 2: Find who used the quota
- In the Microsoft Defender portal, open Email & collaboration reports > Top senders and recipients.
- Use message trace in the EAC to list outbound messages for the last 24 hours and group them by sender.
- Look for a single mailbox or application sending to large external lists, a newsletter sent to a distribution group with many external members, or a mailbox that's sending spam.
Step 3: Stop the source
If a mailbox looks compromised, follow Microsoft's compromised-account procedure: disable the account or reset its password, revoke sessions, and remove forwarding and inbox rules. If an application or campaign is the source, pause it.
Step 4: Wait for the window
There's no manual unblock for TERRL. Sending to external recipients resumes when the count for the last 24 hours drops below the threshold. That can take minutes or up to 24 hours, depending on when the earlier volume was sent. Internal mail isn't affected.
Prevent it from happening again
- Move bulk and application mail to ACS Email. Microsoft recommends Azure Communication Services Email for bulk or high-volume external mail, and ACS messages don't count against TERRL. The sending options are compared in SMTP AUTH vs Direct Send vs relay connector.
- Move internal notifications to HVE. Mail from apps to employees sent through High Volume Email doesn't count either.
- Spread large sends over several days so the 24-hour total stays below the quota.
- Check external members of large distribution groups, because every member counts after expansion.
- Use outbound spam policies to put lower per-user limits on mailboxes that shouldn't send large volumes. Choose Restrict the user from sending mail or the default Restrict the user from sending mail until the following day so one mailbox can't use up the tenant quota.
- Plan quotas for new tenants. A newly created tenant gets 10% of its calculated quota for its first 30 days and 25% from day 31 to day 60. If you build a new tenant, for example as the target of a tenant-to-tenant migration, schedule bulk external communications for after day 60. The wider migration plan is covered in Microsoft 365 tenant-to-tenant migration architecture.
- License count matters. Microsoft's own recommendation for tenants that need more external volume is a dedicated high-volume service or more Exchange Online licenses.
Summary checklist
- Current
Thresholdrecorded fromGet-LimitsEnforcementStatusor the EAC report - Scheduled check warns at 80% of the quota
- Defender alert policies on, with real recipients
- Bulk and customer mail moved to ACS Email; internal app mail moved to HVE
- No production sender using the
onmicrosoft.comdomain - Outbound spam policies limit high-risk or shared mailboxes
- Runbook for 5.7.233: confirm, find the sender, stop the source, wait for the window
References
- Introducing Exchange Online Tenant Outbound Email Limits (Exchange Team, updated August 2026)
- Exchange Online limits: sending limits
- Troubleshoot outbound sending limits in Exchange Online
- Configure outbound spam policies
- Respond to a compromised email account in Microsoft 365
- Manage High Volume Email for Microsoft 365