T The Triage ManualTechnical Guides for IT Emergencies
P2 · Exchange & Mail Flow

Exchange Online mail flow problems

Mail not delivering, NDRs, mass quarantine, or hybrid connector failure. The diagnosis runs from envelope sender to mailbox, in order.

Indicators

Likely causes

Diagnostic steps

  1. Check Microsoft 365 Service Health — rule out tenant-wide incident first
  2. Use Message Trace (Exchange admin) — find the actual delivery path and rejection reason
  3. Inspect message headers for SPF/DKIM/DMARC results, anti-spam stamps (X-MS-Exchange-Organization-SCL, X-Forefront-Antispam-Report)
  4. Verify DNS — SPF flat lookup count <10, DKIM selectors present, DMARC valid
  5. For hybrid: test connector with Test-OutboundConnector / Test-MailFlow; check certificate expiry dates
  6. Quarantine review for false positives; sender / domain allow lists scrutinised

Resolution path

Prevention

Tools

References

exchange-onlinemail-flowspfdkimdmarcmicrosoft-365