Most common causes
- The on-premises or gateway source IP changed
- Connector certificate identity no longer matches the configured path
- Mail was routed through a different gateway than the connector expects
- Hybrid or relay configuration changed without a corresponding connector update
What to verify next
- Map the message route and identify the actual connecting host
- Compare current source IP and certificate identity with the connector design
- Review recent gateway, NAT or routing changes
- Retest through the intended connector path after configuration is aligned
Best diagnostic path
Mail Failure Doctor
Classify the complete rejection and preserve provider-specific diagnostic context.
Open analysis → Live analysisEmail Dependency Discovery
Map applications and devices that depend on a relay or submission path before changing it.
Open analysis → Live analysisEmail Infrastructure Digital Twin
Map the domain’s public mail infrastructure and provider relationships before remediation.
Open analysis →Why the exact message matters
The same status family can be triggered by different conditions, and providers frequently add diagnostic text that narrows the issue. Use the complete rejection text rather than treating the numeric code as a complete diagnosis.
Provider reference
For the provider-defined meaning and current requirements, review Microsoft Exchange Online NDR reference.