exchange-online error

Exchange Online 550 5.4.316 — Message Expired, Connection Refused

Exchange Online retried delivery until the message expired because the destination mail server refused every connection attempt.

What the bounce says

Exact wording as it appears in the rejection or NDR. Placeholders such as x.x.x.x and example.com stand for your own address and domain.

550 5.4.316 Message expired, connection refused (Socket error code 10061)

550 5.4.316 Message expired, connection refused

Exchange Online found the recipient’s mail server in DNS, tried to connect, and was refused every time until the message expired. Socket error 10061 is Windows’ "connection actively refused": the host exists but nothing is accepting connections on port 25.

Reviewed 2026-09-08. Provider wording and requirements change; the provider reference below is authoritative.

Most common causes

  • The destination MX host is down or not listening on port 25
  • A firewall in front of the destination blocks Microsoft’s sending ranges
  • The MX record points at a host that no longer runs a mail service
  • The destination accepts connections only from specific sources

What to verify next

  1. Identify the destination host from the NDR
  2. Check whether the MX hosts accept connections on port 25 from the internet
  3. Ask the recipient organization whether Microsoft ranges are allowed
  4. Do not resend until the destination is reachable; the retry will fail the same way

Refused, not unreachable

A refusal is different from a timeout. The destination address answered — with a reset — meaning a firewall or the host itself rejected the connection. Typical causes are a mail service that stopped, a firewall rule that no longer allows inbound 25, or an MX record pointing at a host that was repurposed.

Because Microsoft retries for hours before expiring the message, this NDR usually arrives long after the problem began. The recipient side is often already aware; the sender should not resend until it is fixed.

  • Port 25 on the MX host is closed or filtered.
  • The MX may point at the wrong host after a change.
  • Resending before the fix produces the same expiry.

Check every MX host

The transport security tool lists the MX hosts and tests whether each accepts a connection and offers STARTTLS. If the primary is refused and the secondary accepts, senders should still deliver via the secondary; an NDR means all published hosts refused.

If you are the recipient, confirm the mail service is running, inbound 25 is allowed from the internet, and the MX record names the correct host.

Cloud and filtering services

Domains behind a filtering service sometimes restrict inbound connections to the service’s own ranges and forget that the MX still points at the origin server. Microsoft then connects to the origin directly and is refused. Point MX at the filtering service or allow Microsoft’s ranges.

Best diagnostic path

Known limits

  • The sender cannot open the recipient’s firewall.
  • Expiry timing depends on Exchange Online’s retry schedule.

Common questions

Does 10061 mean the server is down?

It means nothing is listening on port 25 at that address, or a firewall is rejecting. The host may be up for other services.

Why did other senders deliver?

They may have used a secondary MX, or their attempts happened before the problem started.

How long does Exchange retry?

Up to its queue lifetime — typically around a day — before producing this NDR.

Why the exact message matters

The same status family can be triggered by different conditions, and providers frequently add diagnostic text that narrows the issue. Use the complete rejection text rather than treating the numeric code as a complete diagnosis.

Provider reference

For the provider-defined meaning and current requirements, review Microsoft Exchange Online NDR reference.