使用MgGraph+OAuth向Office365发邮件失败:550 5.7.708错误
使用Microsoft Graph API发送邮件遇550 5.7.708错误的排查与解决
错误详情
发送邮件后收到Exchange自动回复,诊断信息如下:
生成服务器AS8PR08MB9314.eurprd08.prod.outlook.com,远程服务器返回'550 5.7.708 Service unavailable. Access denied, traffic not accepted from this IP.'
操作背景
- 采用证书认证方式:在本地生成自签名证书,并添加至Azure AD应用注册中
- Azure AD应用已配置Graph API的
Mail.Send权限 - 执行PowerShell脚本调用Graph API的
POST /users/{fromEmail}/sendMail接口,请求返回成功,但立即触发上述未送达报告(NDR)
脚本代码
Install-Module MSAL.PS Import-Module MSAL.PS $appName = "MailSendingTestApp" $appRegistration = @{ TenantId = "xxx.onmicrosoft.com" ClientId = "<app-id>" ClientCertificate = (Get-ChildItem Cert:\CurrentUser\My | Where-Object {$_.Subject -eq ('CN={0}' -f $appName)}) } $msalToken = Get-MsalToken @appRegistration -ForceRefresh -AzureCloudInstance 1 $fromEmailAddress = "email address removed for privacy reasons" $requestBody = @{ "message" = [PSCustomObject]@{ "subject" = "OAuth Mail Test" "body" = [PSCustomObject]@{ "contentType" = "Text" "content" = "Hello this is a test" } "toRecipients" = @( [PSCustomObject]@{ "emailAddress" = [PSCustomObject]@{ "address" = "email address removed for privacy reasons" } } ) } "saveToSentItems" = "true" } $request = @{ "Headers" = @{Authorization = $msalToken.CreateAuthorizationHeader() } "Method" = "Post" "Uri" = "https://graph.microsoft.com/v1.0/users/$fromEmailAddress/sendMail" "Body" = $requestBody | ConvertTo-Json -Depth 5 "ContentType" = "application/json" } Invoke-RestMethod @request
排查结论
- 最初查阅资料得知,550 5.7.708错误常见于Microsoft 365试用租户,需联系支持申请IP例外,但本次使用的是**Microsoft 365 E5 Developer(Visual Studio合作伙伴权益)**租户
- 2023年5月19日验证确认:问题源于开发者租户的防滥用保护机制,在正式授权的生产租户中执行相同脚本,可正常发送邮件。推测微软对试用/开发者账号设置了流量限制,拒绝非可信IP的邮件发送请求。
内容的提问来源于stack exchange,提问作者bergsj
相关产品推荐
相关产品推荐

