A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
The code 550 5.7.1 TRANSPORT.RULES.RejectMessage; the message was rejected by organization policy means that an Exchange Online (Microsoft 365) mail flow rule or other organization policy blocked the message. The server name DS4PR01MB9251.prod.exchangelabs.com is just one of Microsoft’s Exchange Online mailbox servers; it does not identify an attacker and is not evidence of who “cyber robbed” the account.
What this error tells:
- The message hit a transport (mail flow) rule or policy in the recipient’s or sender’s Microsoft 365 organization.
- The rule’s action was to reject the message, which generated the 550 5.7.1 non‑delivery report (NDR).
- The rejection is due to security or compliance configuration (for example, anti‑spam, DLP, or a custom rule), not because someone is actively intercepting the mail.
How to find more detail (admin steps):
- Run a message trace in the Exchange admin center for the affected message to see:
- The exact rule or policy that rejected it.
- Whether the message was classified as spam, malware, or matched a specific rule condition.
- Review mail flow rules and security policies that could be rejecting messages (for example, rules that reject messages from external senders, or that enforce TLS and reject on failure).
If there is concern about account compromise or “cyber robbery,” that must be investigated separately (sign‑in history, device checks, MFA status, password changes, etc.). The 550 5.7.1 TRANSPORT.RULES.RejectMessage NDR itself only shows that organization policy blocked the email, not where an attacker is located or who they are.
References: