Outlook's sending limits in 2026 depend on the account. A Microsoft 365 mailbox, on any business or enterprise plan, can send to 10,000 recipients in a rolling 24 hours, at up to 30 messages a minute, with 500 recipients per message by default and up to 1,000 if an admin raises it. A personal Outlook.com account with a Microsoft 365 subscription can reach 5,000 recipients a day, 500 per message and 1,000 people it has never written to before, and free accounts get less. On top of the per-mailbox numbers, every Microsoft 365 tenant has a shared daily cap on external recipients.
That shared cap is the limit that catches outreach teams. A tenant with 25 licences can send to 14,259 external recipients a day in total, across all its mailboxes, and once it passes that number every user in the company loses external sending, not just the one who sent too much. A tenant less than 31 days old gets a tenth of its quota. We read every figure below on Microsoft's own documentation and Exchange team blog on 8 October 2026, and worked through what they mean for a team sending from Microsoft 365.
What are the Outlook sending limits in 2026?
Microsoft publishes separate limits for each kind of account and each way of sending. The figures that matter:
| Account or route | Daily limit | Recipients per message | Rate and other limits |
|---|---|---|---|
| Microsoft 365 mailbox (Exchange Online) | 10,000 recipients in a rolling 24 hours | 500 by default, admins can set 1 to 1,000 | 30 messages a minute |
| Microsoft 365 tenant, all mailboxes together | External recipients: 500 × licences^0.7 + 9,500 | Not applicable | 10 percent of the quota for tenants under 31 days old, 25 percent from 31 to 60 days |
| Trial Microsoft 365 tenant | 500 external recipients, per Microsoft's August 2026 update | Same as a mailbox | Microsoft's limits page still says 5,000 |
| Sending from an onmicrosoft.com address | 100 external recipients per organization | Same as a mailbox | Rolled out by tenant size through June 2026 |
| SMTP AUTH (smtp.office365.com) | The mailbox's limits | The mailbox's limits | 3 concurrent connections per mailbox |
| Microsoft Graph sendMail | Exchange Online's mailbox limits, since Microsoft says delivery is subject to them | Exchange Online's mailbox limits | 10,000 API requests per 10 minutes and 4 concurrent requests, per app and mailbox |
| Outlook.com, with a Microsoft 365 subscription | 5,000 recipients | 500 | 1,000 recipients you have never emailed before, per day |
| Outlook.com, free account | Lower, no figure published | Not published | New accounts start with a lower temporary quota |
The Microsoft 365 limits are the same on Business Basic, Standard and Premium, Office 365 E1, E3 and E5, F3 and the standalone Exchange Online plans, according to Microsoft's Exchange Online limits page. Microsoft calls the recipient rate limit and the message rate limit hard limits that cannot be increased, and they apply to applications as well as people, to internal mail as well as external.
How does Microsoft count recipients?
Every address in To, Cc and Bcc counts, and the window rolls. Microsoft's own example: a mailbox that sends to 5,000 recipients at 9:00, 2,500 at 10:00 and 2,500 at 11:00 has used its 10,000 and cannot send again until 9:00 the next morning, when the first batch leaves the window.
Three counting rules trip people up. A distribution group from the organization's address book counts as one recipient against the mailbox limit, but a personal contact list counts every member. Mail sent on behalf of a shared mailbox counts against the person who sends it, and for the outbound spam policy, Microsoft says that switching to a different From address does not reset that person's count. And the tenant-wide limit below counts differently again: it expands every group into its members and counts each message to the same person separately.
How does the tenant external recipient rate limit work?
It caps how many external recipients the whole tenant can send to in a rolling 24 hours, whatever each mailbox does. Microsoft's Exchange team announced it in February 2025, updated it in August 2026, and describes it as fully implemented in its worldwide environment. External means any domain that is not an accepted domain of the tenant, which includes other Microsoft 365 companies. The quota comes from a formula on the number of licences the tenant owns, assigned or not:
| Licences in the tenant | External recipients a day, whole tenant | Per mailbox if every licence sends equally |
|---|---|---|
| 1 | 10,000 | 10,000 |
| 10 | 12,006 | About 1,200 |
| 25 | 14,259 | About 570 |
| 100 | 22,059 | About 220 |
| 1,000 | 72,446 | About 72 |
The first two columns are Microsoft's table, from 500 × licences^0.7 + 9,500. The third is our division, and it shows the design: the quota grows far slower than the licence count, so each extra mailbox adds little external capacity. Microsoft's announcement of the tenant limits lists the counting rules. It does not deduplicate, so 1,000 messages to one external address count as 1,000. Mail relayed from on-premises servers counts. Automatic replies, out-of-office messages, delivery reports and mail sent through Azure Communication Services or High Volume Email do not.
New tenants start lower. Under Microsoft's August 2026 update, rolling out from 14 September 2026, a tenant less than 31 days old gets 10 percent of its calculated quota, one between 31 and 60 days gets 25 percent, and only after 60 days does it get the full figure. Trial tenants are capped at 500 external recipients a day regardless of licences, according to that update, although Microsoft's limits pages still show the older 5,000.
When the tenant goes over, external sending stops for every user, with this bounce:
550 5.7.233 - Your message can't be sent because your tenant exceeded its daily limit for sending email to external recipients (tenant external recipient rate limit)Trial tenants get a near-identical message under 550 5.7.232. Internal mail keeps flowing, and external sending comes back once the rolling count drops below the quota, which Microsoft says can take minutes or up to 24 hours. Admins can watch the count in the Exchange admin center under Reports, Mail flow, Tenant Outbound External Recipients Rate, or with the Get-LimitsEnforcementStatus PowerShell cmdlet, which returns the threshold and the observed value. Microsoft suggests a custom alert at 80 percent, since no built-in one existed when the limit launched.
One number to stop repeating: in 2024 Microsoft announced a separate limit of 2,000 external recipients a day per mailbox, planned for 2025 and later 2026. On 6 January 2026 it cancelled that limit indefinitely. Guides that still quote 2,000 external recipients a day for Microsoft 365 are out of date. The 10,000 per mailbox and the tenant limit are what apply.
How do you know which Outlook limit you hit?
From the bounce code. Each limit has its own non-delivery report, and each calls for a different response. These are the codes on Microsoft's Exchange Online troubleshooting pages:
| Code | What it means | What to do |
|---|---|---|
| 5.1.90 "you've reached your daily limit for message recipients" | The mailbox passed 10,000 recipients in 24 hours | Stop sending from that mailbox until the rolling window clears |
| 5.2.2 Submission quota exceeded, or 554 5.2.0 SubmissionQuotaExceededException over SMTP | The recipient rate or message rate limit | Same, and slow down if you were above 30 messages a minute |
| 432 4.3.2 Concurrent connections limit exceeded | More than 3 SMTP AUTH connections on one mailbox | Use fewer parallel connections, or one mailbox per application |
| 550 5.7.233, or 5.7.232 on a trial | The tenant's external recipient limit | All external sending is paused for the tenant: find the sender, wait for the window |
| 550 5.7.236 | The onmicrosoft.com external limit of 100 a day | Send from your own domain |
| 550 5.1.8 Access denied, bad outbound sender | The user is on the Restricted entities list | An admin must unblock the user |
| 5.7.705 Access denied, tenant has exceeded threshold | The tenant sent too much spam or bulk mail | Only Microsoft Support can lift it |
| 5.7.708 Access denied, traffic not accepted from this IP | Low reputation on the sending IP, more common on new tenants | Contact Microsoft Support, especially on a trial tenant |
| 550 5.7.30 Basic authentication is not supported for Client Submission | SMTP AUTH with a password after basic authentication was turned off | Move to OAuth |
The 550 5.1.8 case is the one that surprises people, because no published number triggers it. Every tenant has an outbound spam policy with three thresholds, external recipients per hour, internal recipients per hour and recipients per day, and by default all three are set to 0, which Microsoft says means the service defaults apply, pointing to its published sending limits. Separately, Microsoft blocks accounts that pass thresholds for spam and overall outbound volume that it does not publish, so spammers cannot game them. Its recommended configuration sets 500 external recipients an hour and 1,000 recipients a day per user. When a user crosses the default threshold, Microsoft blocks them from sending until the next day in UTC time, and Microsoft treats exceeding these limits as a sign the account may be compromised.
An admin unblocks a user in the Microsoft Defender portal, under Email and collaboration, Review, Restricted entities, or with the Remove-BlockedSenderAddress cmdlet. Microsoft says restrictions are usually lifted within an hour, and within 24 hours at most. The user can still receive mail while blocked.
How do you send email with the Outlook API?
Through Microsoft Graph. Exchange Web Services is on its way out: Microsoft is switching EWS off for tenants still on the default setting as its rollout reaches them from 1 October 2026, and plans the final shutdown for 1 April 2027. The Graph call is a POST to /me/sendMail, or to /users/{id}/sendMail for another mailbox, with the Mail.Send permission. This is Microsoft's documented example, shortened to one recipient:
POST https://graph.microsoft.com/v1.0/me/sendMail
Content-type: application/json
{
"message": {
"subject": "Meet for lunch?",
"body": {
"contentType": "Text",
"content": "The new cafeteria is open."
},
"toRecipients": [
{
"emailAddress": {
"address": "frannis@contoso.com"
}
}
]
},
"saveToSentItems": "false"
}The answer is 202 Accepted, and Microsoft's sendMail documentation says that code does not mean processing has completed. Graph saves the message as a draft and returns, and the rest of the delivery happens afterwards. If transport fails later, the failure arrives as a non-delivery report in the sender's inbox, not as an API error, so code that sends through Graph has to watch the mailbox for bounces. Delivery is subject to Exchange Online's limits and throttling, and every external message counts toward the tenant limit.
Graph adds its own throttling for Outlook, counted for each combination of app and mailbox: 10,000 requests in 10 minutes, 4 concurrent requests and 150 MB of uploads in 5 minutes. A throttled call returns 429 with a Retry-After header, and Microsoft warns that requests made while throttled still count against the limit, so retrying immediately makes it worse:
import time, requests
def send_mail(token, message):
# delegated token; app-only tokens use /users/{id}/sendMail
url = "https://graph.microsoft.com/v1.0/me/sendMail"
for attempt in range(5):
r = requests.post(url, json={"message": message},
headers={"Authorization": f"Bearer {token}"}, timeout=30)
if r.ok:
return # 202 accepted, not yet delivered: watch the inbox for bounces
if r.status_code == 429:
time.sleep(int(r.headers.get("Retry-After", 2 ** attempt)))
continue
r.raise_for_status()
raise RuntimeError("still throttled after 5 attempts")Two more details matter for anyone building on Graph. The application version of Mail.Send lets an app send as any user in the tenant, and RBAC for Applications in Exchange Online is Microsoft's way to limit which mailboxes the app can use. And attachments over 3 MB need an upload session, sent in chunks up to 150 MB. Our email API guide compares Graph with the other ways to send from code, and our EmailEngine review covers a self-hosted gateway that wraps Graph and IMAP behind one API.
What are the limits for SMTP AUTH on Microsoft 365?
The same daily and per-minute limits as the mailbox, plus three constraints of its own. Each mailbox accepts at most 3 concurrent SMTP AUTH connections, and a fourth gets 432 4.3.2. Every message sent over SMTP AUTH is saved to Sent Items, and a full mailbox stops sending. And SMTP AUTH is often off. Microsoft disables it for organizations created after January 2020, where an admin turns it back on per mailbox with Set-CASMailbox and SmtpClientAuthenticationDisabled set to false. In tenants with security defaults it stays off until security defaults are turned off.
The connection details are smtp.office365.com on port 587 with TLS 1.2 or 1.3. Port 465 is not supported: Microsoft says a device that defaults to it doesn't support the required TLS versions. Password authentication is ending in stages. According to Microsoft's updated timeline of January 2026, basic authentication for SMTP AUTH keeps working until the end of December 2026, when it is disabled by default for existing tenants, which can still switch it back on. In tenants created after December 2026 it will be unavailable by default, with OAuth as the supported method, and Microsoft plans to announce the final removal date in the second half of 2027. OAuth works today, with the SMTP.Send scope for a signed-in user or SMTP.SendAsApp for an application.
Personal Outlook.com accounts already require OAuth. Microsoft ended basic authentication for them on 16 September 2024, and they send through smtp-mail.outlook.com on port 587 with STARTTLS.
What rules apply when you send to Outlook.com addresses at volume?
Microsoft's consumer service, which covers outlook.com, hotmail.com and live.com addresses, sets requirements for domains that send more than 5,000 emails a day to it. Those senders must pass SPF and DKIM for the sending domain and publish a DMARC record of at least p=none, aligned with SPF or DKIM. Microsoft's April 2025 update says mail that fails is rejected from 5 May 2025 with "550 5.7.515 Access denied, sending domain [SendingDomain] does not meet the required authentication level", its support page for that code describes the rejection as in force, and Microsoft says Safe Senders lists will not override it. Microsoft also recommends working unsubscribe links, list hygiene and consent.
These rules concern mail sent to consumer Outlook addresses, from any provider. Most B2B cold email lands in Microsoft 365 business inboxes instead, but the same authentication is what any receiving server checks first, and it costs nothing to set up before the first send.
What do Outlook's limits mean for cold email?
That the tenant decides more than the mailbox does. Take a team that sets up a new Microsoft 365 tenant with 10 mailboxes for outreach, each sending 150 cold emails a day. That is 1,500 external recipients a day. A mature 10-licence tenant has a quota of 12,006 a day, so 1,500 is comfortable. In its first 30 days, the same tenant gets 10 percent, about 1,200, so day one at full volume blocks external sending for every mailbox in the tenant. Between days 31 and 60 the quota is about 3,000, which leaves room. The arithmetic says to ramp new tenants slowly for two months, which is also what a new domain needs for its reputation.
The second constraint is the outbound spam protection. Microsoft's account-blocking thresholds are undisclosed, its recommended policy settings stop at 1,000 recipients a day per user, and the default action blocks the user until the next UTC day. Microsoft is also explicit about its position: its documentation says sending bulk email from Microsoft 365 is not a supported use of the service and is permitted only on a best-effort basis, and that it would rather block a user who sends too much than allow bulk activity. A cold email program that wants to keep its Microsoft 365 mailboxes stays far below every limit, spreads its volume across mailboxes, keeps each tenant within its external quota, and stops a sequence as soon as someone replies or asks to stop.
Microsoft's own high-volume products do not change that. High Volume Email, generally available since March 2026 and billed at $42 per million recipients from June 2026, delivers to internal recipients only. Azure Communication Services Email, which Microsoft recommends for bulk mail to external recipients, starts custom domains at 30 emails a minute and 100 an hour per subscription and raises them after a quota review that weighs failure rates, domain reputation and spam reports. The Google side of the same question, with its own daily caps and spam-rate rules, is in our guide to Gmail sending limits.
On Swarmhit, the cold email API, in beta and opened workspace by workspace, runs that layer for you. A campaign spreads its volume across a pool of mailboxes, keeps one mailbox per lead for the whole thread, applies per-mailbox daily caps and sending windows, and suppresses bounces and complaints. You connect your own Microsoft, Google or IMAP mailboxes, or buy a domain and Microsoft 365 or Google Workspace mailboxes that arrive connected and already warming, and join campaigns after a 14-day hold. You pay for the emails you send, not for the mailboxes, from $59 a month for 50,000 sends. Our comparisons of cold email software and outreach APIs cover the other ways to run that layer.
Spread cold email across mailboxes, not onto one tenant's quota
Swarmhit's cold email API runs mailbox pools, per-mailbox daily caps, sending windows and bounce suppression, with Microsoft 365 mailboxes that arrive connected and warming.
Cold email in beta from $59 a month for 50,000 sends, unlimited mailboxes; pricing may change during the beta.
FAQ
How many emails can I send per day from Outlook?
A Microsoft 365 work or school mailbox can send to 10,000 recipients in a rolling 24 hours, at up to 30 messages a minute. A personal Outlook.com account with a Microsoft 365 subscription can send to 5,000 recipients a day, including at most 1,000 people it has never emailed, and free accounts get a lower, unpublished limit. Business tenants also share a daily cap on external recipients across all their mailboxes.
What is the maximum number of recipients per email in Office 365?
500 by default. Admins can set any value from 1 to 1,000 for a mailbox with the Set-Mailbox cmdlet and its RecipientLimits parameter, or for future mailboxes through the mailbox plan. To, Cc and Bcc all count. An address-book distribution group counts as one recipient for this limit, but the tenant's external recipient limit counts each of its members, so one message to a large group can use a big share of the tenant's daily quota.
What is the tenant external recipient rate limit?
It is a daily cap on external recipients for a whole Microsoft 365 tenant, calculated as 500 × licences^0.7 + 9,500: 10,000 for one licence, 14,259 for 25 and 22,059 for 100. It counts every message to the same person separately. When the tenant goes over, every user loses external sending with bounce 550 5.7.233 until the rolling 24-hour count drops. New tenants get 10 percent of the quota in their first 30 days.
How long does an Exchange Online sending block last?
It depends on the limit. The 10,000-recipient limit clears as the rolling 24-hour window moves. The tenant external limit lifts within minutes to 24 hours. A user blocked by the outbound spam policy's default action can send again the next day in UTC time, while the stricter action keeps them blocked until an admin removes them from Restricted entities, which usually takes effect within an hour.
Does Microsoft Graph have its own sending limits?
Yes, on top of Exchange Online's. Graph throttles Outlook requests per app and mailbox at 10,000 requests in 10 minutes, 4 concurrent requests and 150 MB of uploads in 5 minutes, and returns 429 with a Retry-After header when you go over. Delivery is still subject to the mailbox limits and the tenant's external limit, and sendMail's 202 response only means Graph accepted the request, not that the email was delivered.
Does Microsoft 365 still limit external recipients to 2,000 a day per mailbox?
No. Microsoft announced a 2,000 external recipients a day limit per mailbox in 2024 and planned it for 2025 and then 2026, but its Exchange team cancelled it indefinitely on 6 January 2026. The limits in force are 10,000 recipients a day per mailbox, internal and external together, and the tenant-wide external recipient limit, which depends on the number of licences.




