Exchange Online Mail Flow Troubleshooting

Deep diagnostic procedures for inbound/outbound mail failures, routing issues, NDRs, and delivery delays. Includes safe rollback and escalation criteria. Use message trace for evidence gathering.

Mail Flow Problem Categories

Mail Not Flowing

Zero delivery success, complete connector failure, or DNS/routing block.

Diagnostic entry point for total mail loss scenarios.

Delayed Email Delivery

Mail queuing, queue length monitoring, and delivery delays exceeding SLA.

Prioritized queue diagnostics and relief procedures.

NDR 5.5.4 (Service Unavailable)

Temporary service unavailability, connector overload, or transport rule blocking.

Decision tree for transient vs. permanent failures.

Throttling Detection & Relief

High-volume mail blocking, EOP throttling, and bulk operation limits.

Identifying throttling patterns and safe escalation.

Connector & Routing Issues

Inbound connector configuration, routing rules, and send connector failures.

Safe configuration audit and rollback procedures.

Quick Diagnostic Checklist

  1. Confirm scope: Single recipient, tenant domain, or all traffic?
  2. Check message trace: Is mail queued, rejected, or silent dropped?
  3. Verify connectors: Inbound/outbound connector health and queue depth
  4. Review transport rules: Are rules rejecting or redirecting?
  5. Check DLP/journaling: Silent drops due to policy or journal failures
  6. Validate DNS: MX, SPF, DKIM, and DMARC records
  7. Assess for throttling: Check throttling policy and queue monitoring
  8. Review recent changes: Connector, rule, or security policy modifications

Root Cause Patterns (By Frequency)

Mail flow root cause patterns with symptoms and fix types
Pattern Symptom Fix Type
Connector down/misconfigured Zero inbound, queued outbound Restart/reconfigure connector
Directory sync lag NDR 550 5.1.1 (invalid recipient) Force sync, validate mail attributes
Transport rule silently drops Mail missing, no NDR Audit and disable rule
DLP/journal queue full Delays, eventual delivery or NDR Clear journal queue, investigate journal target
Throttling policy triggered Intermittent NDR 5.5.4 Adjust throttling policy, reduce rate

When to Escalate to Microsoft

  • Connector shows healthy in admin center but mail still not flowing
  • Message trace shows accepted by EOP but never delivered to tenant
  • Throttling persists after policy adjustment and queue is clear
  • Silent drops continue after transport rules audit and DLP review
  • External mail flows fine but tenant-to-tenant fails (multi-tenant federation issue)

Full Runbooks

Step-by-step remediation with rollback procedures.