Diagnose and fix the 554 Reject by behaviour spam bounce error, which occurs when the sending IP address, domain, or email content is flagged by Alibaba Mail's anti-spam system.
Problem description
When Alibaba Mail rejects an inbound email, the sender receives a bounce message starting with:
554 Reject by behaviour spam...
554 is a permanent rejection code. Retrying the same email without fixing the underlying issue will not succeed.
Cause
The rejection comes from Alibaba Mail's behavior-based anti-spam check. The sub-message at the end of the bounce string identifies the specific cause.
1. IP address, sender address, or domain is on an international anti-spam blacklist
Sub-messages: bad sending, list on rbl sites, bad antispam requestCONTINUE
host mxn.mxhichina.com[xxx.xxx.xxx.xxx] said: 554 Reject by behaviour spam at DATA State(Connection IP address:xxx.xxx.xxx.xxx)ANTISPAM_BAT[]: bad sending
host mxn.mxhichina.com[xxx.xxx.xxx.xxx] said: 554 Reject by behaviour spam at DATA State(Connection IP address:xxx.xxx.xxx.xxx)ANTISPAM_BAT[]:list on rbl sites
554 Reject by behaviour spam at Rcpt State(Connection IP address:xxx.xxx.xxx.xxx)ANTISPAM_BAT[01201311R9565, ay29a033002195075]: bad antispam requestCONTINUE
Alibaba Mail's anti-spam system detected that the sending IP address, sender address, or domain is on an international anti-spam blacklist. These sources are identified as having a low email reputation and engaging in spam or phishing. To protect users, Alibaba Mail rejects their emails.
Alibaba Mail applies its own anti-spam policy, which may differ from policies used by other email services. An IP address on Alibaba Mail's blacklist may still be able to send email through other providers.
Resolution: Check whether the sending IP address or domain is on a blacklist or has a low reputation. Use a reputation lookup tool such as Talos Intelligence to run a query.

Email Reputation is the IP reputation for email. Poor indicates a low reputation.
If the IP address or domain is on a blacklist, contact the sender's email service provider (ESP) and request that the IP address be removed. The delisting process varies by anti-spam organization.
2. Invalid sender address in the mailfrom field (multiple possible reasons)
Sub-message: bad antispam requestCONTINUE
554 Reject by behaviour spam at Rcpt State(Connection IP address:xxx.xxx.xxx.xxx)ANTISPAM_BAT[01201311R9565, ay29a033002195075]: bad antispam requestCONTINUE
The sender address contains an invalid format. The domain part (after @) cannot be an IP address. For example, gitlab@192.168.1.0 is invalid.
Resolution: Check the sending program and verify that the mailfrom field contains a valid sender address with a proper domain name, not an IP address.
3. Sending frequency or volume exceeds Alibaba Mail limits
Sub-message: too frequently sending
554 Reject by behaviour spamANTISPAM_BAT[01201311R196xxxxx, c01a1xxxxx]: too frequently sending
The sending IP has exceeded Alibaba Mail's sending frequency or volume limits, triggering the spam filter.
Resolution: Reduce the sending frequency or volume.
4. Blocked by other anti-spam rules
Sub-message: unexpected sendingREJECT
554 Reject by behaviour spam at Rcpt State(Connection IP address:xxx.xxx.xxx.xxx)ANTISPAM_BAT[01201311R78xxxxx, ay29a0330021xxxxx]: unexpected sendingREJECT
The email was blocked by Alibaba Mail's anti-spam rules. Common causes include shortened links, links to malicious websites, or other suspicious content in the email body.
Resolution: Review the email body and remove any shortened links or links to malicious websites, then resend.
Solutions
Match the sub-message in your bounce log to the resolution below:
|
Sub-message |
Resolution |
|
|
Check the sending IP address or domain against an international anti-spam blacklist using a tool such as Talos Intelligence. If listed, contact the sender's ESP and request that the IP address be removed. |
|
|
Check the sending program and verify that the |
|
|
Reduce the sending frequency or volume. |
|
|
Review the email body and remove shortened links or links to malicious websites, then resend. |
For related bounce errors, see: