Microsoft 365

Tenant External Recipient Rate Limit (TERRL): monitor it and fix 5.7.233

How the Exchange Online tenant-wide external recipient limit is calculated after the 2026 changes, how to monitor it in the EAC and PowerShell, and what to do when users get 550 5.7.233.

10 min read
On this page

The Tenant External Recipient Rate Limit (TERRL) is the maximum number of external recipients that an entire Exchange Online tenant can send to in a 24-hour sliding window. For a standard tenant it is calculated as 500 * (non-trial email licenses ^ 0.7) + 9500, with reduced quotas for new tenants and a separate formula for free EDU licenses from September 2026. When the tenant goes over, every sender gets 550 5.7.233 for external mail until usage falls back under the quota. You monitor it in the Exchange admin center's Tenant Outbound External Recipients report or with Get-LimitsEnforcementStatus.

Who this is for and what you will have

This guide is for Exchange Online administrators whose users or applications send a lot of external email, and for anyone who has just seen a whole tenant stop sending to the internet with a 5.7.233 bounce. At the end you will:

  • Understand how the quota is calculated, including the changes Microsoft announced on August 13, 2026.
  • Know exactly what counts against it and what doesn't.
  • Have a PowerShell check you can schedule to warn you before the tenant is blocked.
  • Have a procedure to recover from a block and to stop it from happening again.

How TERRL differs from the per-mailbox limits

Exchange Online has applied per-mailbox sending limits for a long time. TERRL adds a tenant-wide limit on top of them:

LimitScopeValueWhat happens when exceeded
Recipient rate limitPer mailbox10,000 recipients per dayThat mailbox can't send until its 24-hour count drops
Message rate limitPer mailbox30 messages per minuteExtra submissions are throttled into following minutes
Outbound spam policy limitsPer user (policy scoped)0 to 10,000 per hour or per day (0 = service default)Restrict, restrict until next day, or alert only
TERRLWhole tenantCalculated from licensesAll senders blocked from external recipients with 550 5.7.233

The difference matters during an incident. A single compromised mailbox or misconfigured application can use up the tenant quota and block external mail for every user. Outbound spam policy limits apply per user and don't increase the tenant quota.

How the quota is calculated

Standard tenants

The daily quota grows with the number of email licenses, meaning any license that includes Exchange Online or Exchange Online Protection, but at a decreasing rate per license:

TERRL = 500 * (Number of Non-trial Email Licenses ^ 0.7) + 9500

Microsoft's published examples:

Non-trial, non-EDU email licensesTERRL (external recipients per 24 hours)
110,000
1012,006
2514,259
10022,059
1,00072,446
10,000324,979
100,0001,590,639

The count uses the total number of email licenses the tenant has, not the number that are assigned.

Changes rolling out from September 14, 2026

The Exchange Team's August 13, 2026 update changes the calculation for some tenants:

TenantQuota
New tenant, less than 31 days old10% of the standard calculated quota
New tenant, 31 to 60 days old25% of the standard calculated quota
New tenant, more than 60 days old100% of the standard calculated quota
Tenant with free EDU licenses (such as Microsoft 365 A1)500 * (Purchased Email Licenses ^ 0.7 + Free EDU Licenses ^ 0.3) + 9500

The EDU formula means free licenses now add to the quota, but much less than purchased licenses.

For trial tenants, the updated Exchange Team post lists a limit of 500 external recipients per day regardless of license count. At the time of writing, the Exchange Online limits service description and the Defender troubleshooting article still give 5,000. Because the published figures differ, read the actual value from the report or cmdlet rather than relying on either number.

The same update postponed TERRL for the GCC, GCCH, DoD and 21Vianet environments. In the worldwide environment, TERRL is fully implemented.

What counts against the quota

An external recipient is any recipient whose domain isn't an accepted domain in your tenant. That includes recipients in other Microsoft 365 tenants.

Counted:

  • Every external recipient on every message. Sending 1,000 messages to the same address counts as 1,000, because TERRL doesn't track unique recipients.
  • Every external member of a distribution group, after the group and any nested groups are fully expanded. A message to a group with 1,000 external members counts as 1,000.
  • Mail relayed through Exchange Online from on-premises servers, applications or the internet to external recipients.
  • Cross-tenant messages within a multitenant organization (currently treated as external).

Not counted:

  • Journaling messages from Exchange Online journaling rules.
  • Automatic replies, including Out of Office.
  • Delivery status notifications: NDRs, delivery receipts and read receipts.
  • Messages sent with Azure Communication Services Email and Exchange Online High Volume Email.
  • Notifications from Microsoft cloud apps such as SharePoint and Teams.
  • Mail to hybrid on-premises mailboxes whose addresses use an accepted domain.

A subdomain isn't automatically internal. Mail to a subdomain counts as internal only if the subdomain is itself an accepted domain, or if the root accepted domain is an internal relay domain with Accept mail for all subdomains enabled. Messages routed out to a signature service and back are now counted once. Microsoft has fixed an earlier double-counting problem.

A separate limit applies to the default onmicrosoft.com domain: 100 external recipients per organization in a rolling 24-hour window, with 550 5.7.236 bounces when it's exceeded. If an application still sends from contoso.onmicrosoft.com, move it to a custom domain.

Monitor TERRL

Exchange admin center report

  1. Open the mail flow reports at https://admin.exchange.microsoft.com/#/reports/mailflowreportsmain (Reports > Mail flow).
  2. Select Tenant Outbound External Recipients.
  3. Review the current external recipient volume, the daily quota, the share already used, the number of blocked recipients and the Enforcement state.

If Enforcement shows Disabled, nothing is being blocked, even if the report shows the quota exceeded and recipients as blocked.

PowerShell

Connect-ExchangeOnline -UserPrincipalName admin@contoso.com
Get-LimitsEnforcementStatus
PropertyMeaning
VerdictBlock means the tenant is over its quota and external mail is blocked (if enforcement is enabled). None means it's under the quota.
EnforcementEnabledTrue means blocking happens when the quota is exceeded. False means it doesn't, even if Verdict is Block.
ThresholdThe tenant's TERRL quota.
ObservedValueExternal recipients sent in the last 24 hours.

Microsoft's FAQ notes that it doesn't currently send an alert specifically when you approach the quota. Its stated plan was a system alert at 80%. Until that alert is in your tenant, a scheduled check gives you warning. This example uses only the four documented properties:

# Run on a schedule (for example every hour) with app-only auth to Exchange Online
$status  = Get-LimitsEnforcementStatus
$percent = [math]::Round(($status.ObservedValue / $status.Threshold) * 100, 1)
 
if ($percent -ge 80 -or $status.Verdict -eq 'Block') {
    Write-Warning ("TERRL at {0}% ({1} of {2}). Verdict: {3}. Enforcement: {4}" -f `
        $percent, $status.ObservedValue, $status.Threshold, $status.Verdict, $status.EnforcementEnabled)
    # Send the warning to your monitoring system here
}

Also check that the default alert policies are on in the Microsoft Defender portal at Email & collaboration > Policies & rules > Alert policy. Microsoft's outbound limits troubleshooting article associates the Email sending limit exceeded alert with TERRL being exceeded, and the User restricted from sending email and Suspicious email sending patterns detected alerts catch the compromised accounts that often cause a spike.

When users report 550 5.7.233

The bounce text for a paid tenant is:

550 5.7.233 - Your message can't be sent because your tenant exceeded its daily limit for sending email to external recipients (tenant external recipient rate limit)

Trial tenants get 550 5.7.232 with similar wording.

Step 1: Confirm it's TERRL

Run Get-LimitsEnforcementStatus. A Verdict of Block with EnforcementEnabled set to True confirms that the tenant quota is the cause. If only one user is affected and the bounce is 5.1.8 instead, the cause is a restricted user, not TERRL. See Fix 550 5.1.8 Access denied, bad outbound sender.

Step 2: Find who used the quota

  • In the Microsoft Defender portal, open Email & collaboration reports > Top senders and recipients.
  • Use message trace in the EAC to list outbound messages for the last 24 hours and group them by sender.
  • Look for a single mailbox or application sending to large external lists, a newsletter sent to a distribution group with many external members, or a mailbox that's sending spam.

Step 3: Stop the source

If a mailbox looks compromised, follow Microsoft's compromised-account procedure: disable the account or reset its password, revoke sessions, and remove forwarding and inbox rules. If an application or campaign is the source, pause it.

Step 4: Wait for the window

There's no manual unblock for TERRL. Sending to external recipients resumes when the count for the last 24 hours drops below the threshold. That can take minutes or up to 24 hours, depending on when the earlier volume was sent. Internal mail isn't affected.

Prevent it from happening again

  • Move bulk and application mail to ACS Email. Microsoft recommends Azure Communication Services Email for bulk or high-volume external mail, and ACS messages don't count against TERRL. The sending options are compared in SMTP AUTH vs Direct Send vs relay connector.
  • Move internal notifications to HVE. Mail from apps to employees sent through High Volume Email doesn't count either.
  • Spread large sends over several days so the 24-hour total stays below the quota.
  • Check external members of large distribution groups, because every member counts after expansion.
  • Use outbound spam policies to put lower per-user limits on mailboxes that shouldn't send large volumes. Choose Restrict the user from sending mail or the default Restrict the user from sending mail until the following day so one mailbox can't use up the tenant quota.
  • Plan quotas for new tenants. A newly created tenant gets 10% of its calculated quota for its first 30 days and 25% from day 31 to day 60. If you build a new tenant, for example as the target of a tenant-to-tenant migration, schedule bulk external communications for after day 60. The wider migration plan is covered in Microsoft 365 tenant-to-tenant migration architecture.
  • License count matters. Microsoft's own recommendation for tenants that need more external volume is a dedicated high-volume service or more Exchange Online licenses.

Summary checklist

  • Current Threshold recorded from Get-LimitsEnforcementStatus or the EAC report
  • Scheduled check warns at 80% of the quota
  • Defender alert policies on, with real recipients
  • Bulk and customer mail moved to ACS Email; internal app mail moved to HVE
  • No production sender using the onmicrosoft.com domain
  • Outbound spam policies limit high-risk or shared mailboxes
  • Runbook for 5.7.233: confirm, find the sender, stop the source, wait for the window

References

Questions people ask

How do I see my tenant's TERRL quota?

In the Exchange admin center go to Reports, then Mail flow, and open the Tenant Outbound External Recipients report, which shows your daily quota, current usage, blocked recipients and whether enforcement is enabled. In Exchange Online PowerShell, Get-LimitsEnforcementStatus returns the same data as Threshold, ObservedValue, Verdict and EnforcementEnabled.

How can my tenant get a higher TERRL?

The quota is calculated from the tenant's email licenses, and Microsoft's guidance for tenants that need more external volume is to buy more Exchange Online licenses or to move high-volume sending to a dedicated service such as Azure Communication Services Email, whose messages don't count against the quota. Outbound spam policy limits apply per user and only accept values up to 10,000, so they can't raise the tenant quota.

How long does a 550 5.7.233 block last?

The quota uses a 24-hour sliding window. Messages to external recipients stay blocked until the number of external recipients sent in the last 24 hours drops below the threshold, which can take minutes or up to 24 hours depending on when the earlier volume was sent. Sending resumes automatically.

Do messages to other Microsoft 365 tenants count as external?

Yes. Any recipient whose domain isn't an accepted domain in your tenant is external, including recipients in other Microsoft 365 tenants. Microsoft's FAQ also states that cross-tenant messages within a multitenant organization are currently counted as external.

Exchange OnlineTERRLExchange admin centerExchange Online PowerShell
  1. Message trace in Exchange Online: the new EAC and Get-MessageTraceV2

    Trace a missing email with the new message trace in the Exchange admin center, Get-MessageTraceV2, the Graph message trace API and historical searches.

    Microsoft 36511 min read
  2. Calendar permissions in Exchange Online: Add-MailboxFolderPermission guide

    Share calendars, change the organization-wide Default permission and add calendar delegates in Exchange Online with Add-, Set- and Remove-MailboxFolderPermission, including localized folder names.

    Microsoft 3659 min read
  3. Convert a user mailbox to a shared mailbox and remove the license safely

    Keep a leaver's email and calendar in Exchange Online without paying for a license: secure the account, convert the mailbox, grant access, then remove the license in the right order.

    Microsoft 36511 min read