exchange-online error

Exchange Online 550 5.7.64 — TenantAttribution Relay Access Denied

Exchange Online could not attribute the relayed message to the expected tenant because the inbound connector path no longer matched the configured identity or network conditions.

Most common causes

  • The on-premises or gateway source IP changed
  • Connector certificate identity no longer matches the configured path
  • Mail was routed through a different gateway than the connector expects
  • Hybrid or relay configuration changed without a corresponding connector update

What to verify next

  1. Map the message route and identify the actual connecting host
  2. Compare current source IP and certificate identity with the connector design
  3. Review recent gateway, NAT or routing changes
  4. Retest through the intended connector path after configuration is aligned

Best diagnostic path

Why the exact message matters

The same status family can be triggered by different conditions, and providers frequently add diagnostic text that narrows the issue. Use the complete rejection text rather than treating the numeric code as a complete diagnosis.

Provider reference

For the provider-defined meaning and current requirements, review Microsoft Exchange Online NDR reference.