What the bounce says
Exact wording as it appears in the rejection or NDR. Placeholders such as x.x.x.x and example.com stand for your own address and domain.
550 5.4.316 Message expired, connection refused (Socket error code 10061) 550 5.4.316 Message expired, connection refused
Exchange Online found the recipient’s mail server in DNS, tried to connect, and was refused every time until the message expired. Socket error 10061 is Windows’ "connection actively refused": the host exists but nothing is accepting connections on port 25.
Most common causes
- The destination MX host is down or not listening on port 25
- A firewall in front of the destination blocks Microsoft’s sending ranges
- The MX record points at a host that no longer runs a mail service
- The destination accepts connections only from specific sources
What to verify next
- Identify the destination host from the NDR
- Check whether the MX hosts accept connections on port 25 from the internet
- Ask the recipient organization whether Microsoft ranges are allowed
- Do not resend until the destination is reachable; the retry will fail the same way
Refused, not unreachable
A refusal is different from a timeout. The destination address answered — with a reset — meaning a firewall or the host itself rejected the connection. Typical causes are a mail service that stopped, a firewall rule that no longer allows inbound 25, or an MX record pointing at a host that was repurposed.
Because Microsoft retries for hours before expiring the message, this NDR usually arrives long after the problem began. The recipient side is often already aware; the sender should not resend until it is fixed.
- Port 25 on the MX host is closed or filtered.
- The MX may point at the wrong host after a change.
- Resending before the fix produces the same expiry.
Check every MX host
The transport security tool lists the MX hosts and tests whether each accepts a connection and offers STARTTLS. If the primary is refused and the secondary accepts, senders should still deliver via the secondary; an NDR means all published hosts refused.
If you are the recipient, confirm the mail service is running, inbound 25 is allowed from the internet, and the MX record names the correct host.
Cloud and filtering services
Domains behind a filtering service sometimes restrict inbound connections to the service’s own ranges and forget that the MX still points at the origin server. Microsoft then connects to the origin directly and is refused. Point MX at the filtering service or allow Microsoft’s ranges.
Best diagnostic path
Mail Failure Doctor
Classify the complete rejection and preserve provider-specific diagnostic context.
Open analysis → Live analysisMail Transport Security
Inspect MX, TLS, MTA-STS and transport-policy evidence for the destination.
Open analysis → Live analysisEmail Infrastructure Digital Twin
Map the domain’s public mail infrastructure and provider relationships before remediation.
Open analysis →Known limits
- The sender cannot open the recipient’s firewall.
- Expiry timing depends on Exchange Online’s retry schedule.
Common questions
Does 10061 mean the server is down?
It means nothing is listening on port 25 at that address, or a firewall is rejecting. The host may be up for other services.
Why did other senders deliver?
They may have used a secondary MX, or their attempts happened before the problem started.
How long does Exchange retry?
Up to its queue lifetime — typically around a day — before producing this NDR.
Why the exact message matters
The same status family can be triggered by different conditions, and providers frequently add diagnostic text that narrows the issue. Use the complete rejection text rather than treating the numeric code as a complete diagnosis.
Provider reference
For the provider-defined meaning and current requirements, review Microsoft Exchange Online NDR reference.