I was hacked and opened an attachment and now any email sent is rejected by other peoples server

John Bachenski 0 Reputation points
2026-04-30T11:58:59.5133333+00:00

This is the message I get. Rather be taken off the list of hacked emails than create a new email address. No clear answers and this has turned into an example of the worst customer service by one of the largest corporations in the world. No live person with any knowledge to fix the problem just AI and silence.

This message couldn't be delivered because the sending email address was not recognized as a valid sender. The most common reason for this error is that the email address is, or was, suspected of sending spam. Contact the organization's email admin for help and give them this error message.

Outlook | Web | Outlook.com | Email

1 answer

Sort by: Oldest
  1. AI answer

    2026-04-30T11:59:13.9666667+00:00

    The error indicates that the sending address has been flagged as a bad or spammy sender and is now blocked by the receiving systems. In Microsoft 365/Exchange Online this appears as an NDR like:

    "Your message couldn't be delivered because you weren't recognized as a valid sender… Remote Server returned 550 5.1.8 Access denied, bad outbound sender."

    This typically happens after malware or a hacker uses the account to send spam, or the account exceeds sending limits.

    To fix this, two things must happen:

    1. Secure the compromised account
      Because an attachment was opened and the account was hacked, the account and devices must be treated as compromised:
      • Follow the guidance in “Secure a compromised email account in Exchange Online” to:
        • Reset the account password.
        • Check and remove malicious inbox rules, forwarding, and delegates.
        • Review sign-in activity and revoke suspicious sessions.
      • Follow the steps in “Responding to a compromised email account” (linked from the NDR guidance) to ensure no malicious rules or connectors remain.
      • Run a full malware scan on all devices used to access the mailbox.
    2. Remove the sending block placed by Microsoft
      Once the account is secure, the sending block must be lifted:
      • If this is an organizational Microsoft 365/Exchange Online account, the email administrator must:
        1. Go to the Microsoft 365 Defender portalRestricted entities page (https://security.microsoft.com/restrictedusers).
        2. Locate the blocked user and unblock the account.
        3. After unblocking, outbound restrictions are usually removed within about an hour so mail can be sent again.
      • If this is a consumer Outlook.com/Hotmail account and messages are being rejected by Outlook.com recipients, review and follow the Outlook.com sender support guidance to improve spam reputation and, if needed, contact support using the troubleshooting form under “Troubleshooting tips for IT admins”.

    If the problem is that other organizations (not Microsoft 365) are rejecting the mail because the sending IP or domain is on a block list, their NDRs may reference a blocked IP and direct to a delist portal such as https://sender.office.com/. In that case, follow the NDR instructions and use the Office 365 Anti-Spam IP Delist Portal to request removal from the blocked senders list after confirming the environment is clean.

    Until the account is fully secured and the sending block removed, any mail sent from that address is likely to continue to be rejected as suspected spam.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.