A 550 that contains the word "content" will put a template review on the calendar before anyone has read the rest of the reply. I have watched that review take an afternoon. The subject line gets a new verb, a tracking link is swapped for a shorter one, the preheader is rewritten, and the following send returns the same enhanced status code and the same sentence. Often the body matches the send from the month before, and those recipients accepted it then.
The status code and the sentence do different jobs. RFC 3463 describes 5.7.1 as "delivery not authorized, message refused," and it allows the cause to be per-host or per-recipient filtering. A content rule is one form of that filtering. A block on the sending domain, a score driven by IP reputation, and an authentication failure are reported with that same enhanced code. Some gateways also park a rate limit on 5.7.1, though a deferral would have been the more accurate class. A workflow that branches on the word content, because it showed up in the sentence, sends that whole set into a template rewrite.
Microsoft 365 has long returned variations of "550 5.7.1 Message rejected as spam by Content Filtering." The 550 marks a permanent refusal for this attempt. The 5.7.1 places it in the policy class, and the sentence names Content Filtering, a scoring agent. The agent scores the sending IP and the domain's recent history together with authentication and the bytes of the message. The refusal means the score crossed a bar set by the service or by that tenant. The subject line can match a send that same tenant accepted, and the reply still does not name a token in the HTML.
Other gateways compress the reason the same way. Proofpoint, Barracuda, Mimecast, and Cisco email security appliances return 5.7.1 replies whose sentences mention content, policy, or an administrative prohibition, and the admin of the receiving domain can overwrite the sentence. When that admin writes one, the word content is an easy default to leave in place. In the logs this shows up as one corporate domain refusing a password reset that every other domain accepted in the same hour. The payload is the same and the MX is different. If the reply includes a link to the gateway vendor's documentation, open that page before the template. Vendors use those pages to name the check behind the code, after the SMTP sentence has shortened the reason to the word content.
Reading the status code ahead of the sentence
A leading 4 means defer. A 421 with enhanced code 4.7.0 or 4.7.1 is sometimes worded so that it sounds final, with policy language or content language in the text. This attempt was refused, and a later attempt may be accepted. Suppressing the address, or holding the template, on the strength of that wording drops recipients a retry would have reached. Drive the retry from the class.
5.1.1 and 5.1.2 describe the mailbox: an unknown user, or a destination address the domain rejects. That address belongs on a suppression list. The domain has reported the account absent, and a new subject line has no way to create it.
5.2.2 is a full mailbox or another quota condition. A run of them is a hygiene question. One of them means the mailbox was full at that moment, and retiring the address on that single hit is premature.
5.7.0 and 5.7.1 are the codes whose vague sentences get filed under content. Gmail uses 5.7.26 when mail from a domain fails the DMARC policy that domain published. The reply talks about the message that was offered. DMARC failed because the message had no passing, aligned SPF or DKIM result of the kind the domain's record demands. A wording change leaves the SPF and DKIM results unchanged.
A bounce that quotes a URL, a header, an attachment type, or a rule id is reporting a match. If the text says a URL in the message is on a blocklist, a hostname in the body is on a list the gateway consults, commonly a Spamhaus domain list or a SURBL feed. The sentences around the link can stay. Replace the hostname, or get the listing removed. If the gateway refuses an exe attachment, stop sending that file type, or send the file by a path the gateway allows. A sentence that announces content restrictions without naming a URL, a header, or a rule id means the gateway's reply template had nothing finer to include.
A test that changes one variable
Hold the sending IP, the envelope sender, the DKIM selector, and a seed recipient at the gateway that refused the mail. Send the production message. Send a second message as plain text, with no links, no images, and a subject made of one ordinary word. If both draw 5.7.1 and the reply text matches, the gateway reached the same decision after the body was replaced outright. Further edits to the subject line or the preheader will come back with the same code. Look next at who is sending, how much volume went out, whether authentication passed, and whether a tenant rule matches mail from you regardless of wording.
If the plain version is accepted and the production version is refused, add the differences back in stages. Put the links back first, still in plain text, then the images, then the HTML, then the original subject. A refusal that appears when the links return, and was absent from the control, points at a hostname. Reputation and authentication stay fixed across the stages, so the reply moved with the piece you added.
Group a day's 5.7.1 replies by receiving organization before anyone edits a shared template. One customer domain refusing every message you send them points at their transport rule or their allow-list. Their mail admin can see the rule that fired. It may match a word they chose, such as invoice, or any link that leaves their domain. On that domain, the body can be the cause. A global change to the password reset, so that one legal department will accept a word, rewrites the message every other recipient receives.
When consumer mailboxes at one provider refuse you and other providers accept the same template and the same payload hash, that provider is scoring your IP or domain differently from the others. The template is the same in the comparison. Scattered 5.7.1 replies, one recipient at a time and each with its own wording, are usually a per-user block or a mailbox rule. A 5xx by itself is a thin basis for suppressing those addresses permanently.
Fields worth storing on the bounce
Store the SMTP code, the enhanced status code, the exact reply text, the receiving MX or organization, the template id, and a hash of the payload. The next incident groups from those fields. You can see that a reply text is new for an organization, or that an MX returned it on an earlier send of a payload you have already cleared.
Keep permanent suppression for codes that mean the mailbox is gone, chiefly 5.1.1 and 5.1.2, and for the repeat count you have chosen on quota and long-inactive mailboxes. Leave 5.7.1 off that list. A provider-wide 5.7.1 is a reputation event or a policy event. Write every recipient at Outlook.com or Microsoft 365 who drew "content filtering" onto the suppression list, and you stop mailing addresses that were reachable. The bounce count on the next run falls because those addresses were removed from the send.
Page on a few dozen identical 5.7.x replies to one receiving organization inside an hour, or on a payload hash that starts drawing reply text absent from the day before. Refused mail never reaches someone who could mark it as spam, so the complaint chart can stay ordinary through the cluster.
For one refused recipient, pull the raw source you sent and the SMTP transcript. The transcript shows a refusal at RCPT TO, a refusal after DATA, or a session that ended in 250. At RCPT TO the body is still unsent. The sentence can mention content anyway. The gateway decided from the envelope and the IP. If the session ended in 250 and the 5.7.1 arrived later inside a DSN, the receiving side accepted the message and a later filter produced the bounce. URL lists and attachment rules belong to that later pass. A refusal at RCPT TO is too early in the session for either check.