exchange-online error

Exchange Online 550 5.7.367 — Forwarded or Relayed Message Authentication Failure

Microsoft rejected a forwarded or relayed message after SPF or DKIM authentication failed along the intermediary mail path.

Most common causes

  • Forwarding changed the delivery IP so SPF no longer represents the original sender
  • A gateway modified signed content and invalidated DKIM
  • The intermediary path does not preserve enough authentication context
  • A non-Microsoft gateway changed the message or routing identity

What to verify next

  1. Analyze the forwarded message with ARC Forwarding Analyzer
  2. Compare authentication before and after the intermediary hop
  3. Inspect whether DKIM broke because message content was modified
  4. Review the forwarding or gateway design instead of changing the original sender blindly

Best diagnostic path

Why the exact message matters

The same status family can be triggered by different conditions, and providers frequently add diagnostic text that narrows the issue. Use the complete rejection text rather than treating the numeric code as a complete diagnosis.

Provider reference

For the provider-defined meaning and current requirements, review Microsoft Exchange Online NDR reference.