exchange-online error

Exchange Online 550 5.7.321 — STARTTLS Not Supported

Exchange Online could not deliver because the destination mail server did not support STARTTLS where TLS was required for the route.

Most common causes

  • The destination SMTP service does not advertise STARTTLS
  • A gateway or load balancer is terminating SMTP without the expected TLS capability
  • The wrong MX target or service endpoint is receiving the connection
  • A transport-security policy requires TLS but the destination path cannot negotiate it

What to verify next

  1. Run Mail Transport Security against the destination domain
  2. Verify the MX targets and whether each advertises STARTTLS
  3. Check whether an MTA-STS or connector policy requires encrypted transport
  4. Inspect recent gateway or certificate configuration changes

Best diagnostic path

Why the exact message matters

The same status family can be triggered by different conditions, and providers frequently add diagnostic text that narrows the issue. Use the complete rejection text rather than treating the numeric code as a complete diagnosis.

Provider reference

For the provider-defined meaning and current requirements, review Microsoft Exchange Online NDR reference.