exchange-online error

Exchange Online 550 5.4.8 — MX Failed MTA-STS Validation

Exchange Online rejected the transport path because the destination MX host did not match the MX identities permitted by the domain’s MTA-STS policy.

Most common causes

  • The published MTA-STS policy does not include the active MX hostname
  • MX records changed but the MTA-STS policy was not updated
  • A backup MX or failover host is missing from policy
  • Cached policy and current DNS describe different transport paths

What to verify next

  1. Run Mail Transport Security for the destination domain
  2. Compare every active MX hostname with the published MTA-STS mx patterns
  3. Review recent MX, gateway or failover changes
  4. Publish a consistent policy and allow normal policy/DNS cache propagation before retesting

Best diagnostic path

Why the exact message matters

The same status family can be triggered by different conditions, and providers frequently add diagnostic text that narrows the issue. Use the complete rejection text rather than treating the numeric code as a complete diagnosis.

Provider reference

For the provider-defined meaning and current requirements, review Microsoft Exchange Online NDR reference.