Most common causes
- The From or sending domain is not configured as an accepted domain
- A connector is using an unexpected or unregistered identity
- Bulk traffic is being sent from a domain outside the tenant’s intended configuration
What to verify next
- Confirm the domain used in the failing message
- Verify accepted-domain configuration
- Review connector and outbound identity settings
- Retest after the sending identity is correctly registered
Best diagnostic path
Live analysis
Mail Failure Doctor
Classify the complete rejection and preserve provider-specific diagnostic context.
Open analysis → Live analysisEmail Infrastructure Digital Twin
Map the domain’s public mail infrastructure and provider relationships before remediation.
Open analysis →Why the exact message matters
The same status family can be triggered by different conditions, and providers frequently add diagnostic text that narrows the issue. Use the complete rejection text rather than treating the numeric code as a complete diagnosis.
Provider reference
For the provider-defined meaning and current requirements, review Microsoft Exchange Online NDR reference.