A bounce message is a receipt generated by someone else’s server. That makes it unusually good evidence: the sender cannot fabricate it, and it carries timestamps, message IDs, and the identity of the rejecting host.
The two codes describe different worlds
5.1.10 says the address does not exist as far as the receiving organization is concerned. 5.4.1 says the address may exist but the system will not accept mail for it. A mailbox that produces one and then the other has changed state twice.
The hard limit
Bounce codes fix behavior in time. They do not identify the administrator, policy, or lifecycle event responsible, and they do not establish that historical contents were destroyed. Only the receiving organization’s tenant audit logs do that.
The documented example
A county address produced an authenticated auto-reply on June 23, 2026, 550 5.1.10 on July 14, and 550 5.4.1 on July 29. See the transport record.