Muhammad Basim
Email Marketing

Email Bounce Rate: What’s Normal and How to Fix a High One

By Muhammad Basim·

Most people read their bounce rate as a number and stop there. Three percent, say. Bad, presumably. Delete some addresses.

That's the wrong instinct, and occasionally an expensive one — because a chunk of what your platform files as "bounces" isn't about your addresses at all. It's your own DNS quietly failing, and the subscribers you're about to delete were perfectly fine.

The difference lives in the bounce text, not the bounce rate. So let's start with what the categories mean and then get to the codes, because reading them is a two-minute habit that saves whole segments.

The short version

Bounce rate Status
Under 1% Healthy
1–2% Warning — investigate
Over 2% Emergency — stop sending and verify the whole list

Hard bounces are permanent failures. Remove immediately, after a single occurrence.
Soft bounces are temporary. Retry is fine, but suppress after three to five consecutive failures.

And one exception that matters: a 550 5.7.x authentication rejection is not a bad address. It's your setup. Fix that before removing anybody.

Why bounces hurt you

A high bounce rate is a direct signal that you don't know your own list.

Providers read it exactly that way, and the conclusion they draw is unflattering: senders who mail large numbers of non-existent addresses are usually senders who bought, scraped, or never cleaned. That's the company you're keeping in the classifier's eyes, regardless of how you actually got there.

Which is why the thresholds are tighter than people expect. Under 1% total. Between 1% and 2% is worth a real investigation. Above 2% you should stop sending and verify the entire list before your next campaign — because at that level you're actively burning reputation with every send.

Hard bounces

Permanent failures. Three causes:

The address doesn't exist. Typo at signup, employee left, mailbox deleted.

The domain is dead. Company folded, domain expired.

The receiving server rejected you on policy — increasingly common since 2025, and this is the one that gets misread. It's not the address failing. It's your authentication.

The rule: any true invalid-address hard bounce is removed immediately and never mailed again. One occurrence, not three. Most platforms do this automatically — verify yours actually does, because the setting isn't always on by default.

Soft bounces

Temporary failures. The mailbox is full, the server's down, the message was too large, or you've hit greylisting.

Retrying is fine and expected. But an address that soft-bounces across three to five consecutive sends is functionally dead — a permanently full mailbox is an abandoned one — so suppress it at that point rather than retrying forever.

That's also the population that eventually becomes a recycled spam trap, which is a much more expensive problem than a soft bounce. More on that here.

Reading the codes

This is the part worth learning, because it's where the money is.

5xx codes are permanent. The address or the policy has failed definitively.

4xx codes are temporary. Retry expected.

Two families deserve special attention:

550 5.7.x — authentication policy rejections. Microsoft's 550 5.7.515 Access denied is the one you'll see most. This means your setup is the problem, not the address. The recipient exists and is perfectly reachable; the receiving server refused you because your authentication doesn't meet its requirements.

Delete these addresses and you'll have removed valid subscribers while leaving the actual fault in place — and it'll happen again on the next send. Fix authentication first.

421-4.7.x — Gmail's temporary family. Usually rate limiting or alignment problems. Slow down, and check DMARC alignment.

The two-minute habit

After every large send, skim ten actual bounce messages. Not the rate — the text.

Your platform's summary category ("Invalid recipient") is a guess it made by pattern-matching the message. The full text is where the code actually lives, and the code is the difference between "delete this subscriber" and "fix your DNS."

Two minutes. It's the highest-return habit in list hygiene, and virtually nobody does it.

When the whole rate spikes at once

A sudden jump across the board is almost never a sudden jump in dead addresses — addresses don't die in batches on a Tuesday.

Work these in order:

Check authentication first. A DNS change, host migration, or website rebuild routinely breaks records nobody remembers exist. This produces exactly the symptom you're seeing, and it's the most common cause of a sudden spike.

Then check what you sent to. A newly imported segment, an inherited list, a source you hadn't mailed before. If the spike coincides with a new segment, that segment is your answer.

Then check for infrastructure changes. New ESP, new sending domain, new subdomain.

Only after those three does "the list has gone stale" become the likely explanation — and stale lists produce a drift upward, not a cliff.

Preventing bounces at the source

Cleaning bounces is treating symptoms. The addresses were bad when they arrived.

Real-time verification at capture. An API checks syntax, domain validity, and mailbox existence as the address is typed. This is the single highest-return fix.

Typo correction prompts. "Did you mean gmail.com?" Every catch prevents a hard bounce and rescues a subscriber who currently thinks they signed up and is wondering why nothing arrived.

Bot protection and honeypot fields on every public form.

Double opt-in on risky sources — giveaways, contests, anything incentivised.

An immediate welcome email, which surfaces an invalid address within minutes rather than at your next campaign.

The full front-door stack is here.

The routine

Four habits on four clocks:

  • At capture — verify new addresses in real time
  • Automatically — suppress hard bounces after one occurrence, cap soft-bounce retries at three to five
  • After every large send — skim ten bounce messages
  • Quarterly — verify the full list

Frequently asked questions

What is a good email bounce rate?
Under 1% total is healthy. Between 1% and 2% is a warning worth investigating. Above 2% is an emergency — stop sending and verify the entire list before your next campaign, because at that level you're actively damaging your reputation with each send.

Should I remove soft bounces?
Not on the first occurrence, since soft bounces are temporary by definition — a full mailbox or a server hiccup. But an address that soft-bounces across three to five consecutive sends is functionally dead and should be suppressed. A permanently full mailbox is an abandoned one, and abandoned addresses eventually become recycled spam traps.

What does SMTP 550 mean?
550 is a permanent rejection, but the sub-code matters enormously. A plain invalid-recipient 550 means the address doesn't exist and should be removed. A 550 5.7.x — like Microsoft's 550 5.7.515 Access denied — is an authentication policy rejection, which means your setup is the problem rather than the address. Removing those subscribers deletes valid people and leaves the real fault untouched.

What to do next

Open your last campaign's bounce report and read ten of the actual messages. Not the summary — the full text.

If you see 5.7.x codes in there, stop cleaning your list. You have an authentication problem, and every address you delete is a valid subscriber you're throwing away while the real cause keeps working.

If they're genuine invalid-recipient bounces, confirm your platform is suppressing them after a single occurrence.

Free: The 60-Minute Email Authentication Fix — rule out the technical cause before you touch your list.

Go deeper: The Email Deliverability Playbook — the full SMTP error decoder and the inherited-list cleanup process.


Related guides

Join the Newsletter

Get practical marketing tactics delivered straight to your inbox.

Muhammad Basim

Written by

Muhammad Basim

Related Articles

Newsletter

Free: The 60-Minute
Email Authentication Fix

A no-fluff checklist from the Deliverability Playbook. In one hour: set up SPF, DKIM & DMARC correctly, check your domain against blocklists, and pass Gmail & Yahoo's 2026 sender requirements.

No spam — that would be ironic. Unsubscribe anytime.