Source review: September 15, 2026. Tenant validation pending.
Page tools and document details
Start with one exact message
Repeated resends can create duplicates and hide the original problem. Trace the original message first.
Use authorized Exchange access
The tenant needs Exchange Online, and the operator needs an authorized Exchange role with message-trace permissions. Exchange Administrator is a supported option; do not use Global Administrator merely for convenience. A normal mailbox user supplies evidence to the helpdesk.
The current EAC can search up to 90 days of trace history. Use a narrow interval of at most 10 days for a summary query; broader reports are downloadable and can take longer. A recent status can lag delivery by several minutes. Record the queried period and recheck when appropriate.
A hybrid route or third-party gateway can require evidence from another system. A trace gap in this tenant does not prove the sender never sent the message.
Trace the message, then read its events
- Open Exchange admin center → Mail flow → Message trace → Start a trace. Verify the tenant.
- Set the exact sender, recipient and a bounded time range with the correct time zone. Start with all delivery statuses. Use the full Internet Message-ID, including angle brackets when present, to narrow a known message.
- Open the matching result and its message events. Check recipient expansion, redirection and the final destination, not only the top-level status.
- Save the query filters, result and UTC investigation time. Preserve the relevant report in approved storage; it can contain personal addresses and subjects.
| Result | Next action |
|---|---|
| No matching result | Verify addresses, time zone, aliases and message ID; widen the interval carefully. Confirm the source system submitted to this route. Preserve the NDR or upstream trace. |
| Pending or deferred | Read the latest event and retry reason. Check service health and the identified destination/connector. Recheck the same message before resending. |
| Failed or filtered | Use the exact SMTP/error or filtering explanation to choose the correction. Do not assume DNS is responsible for every failure. |
| Quarantined | An authorized operator reviews the message, detection and release eligibility. Do not release malware or broadly allowlist a sender to test delivery. |
| Delivered | Inspect event detail, recipient and folder/rule behavior. Delivery does not prove that the person saw it in the Inbox or read it. |
Correct the cause supported by the trace
For a wrong address or recipient configuration, have its owner correct that specific setting. For a client-only symptom, retain the cloud copy and investigate the affected client's account, views and synchronization.
For a filtering result, have the security owner review the detection and use the appropriate false-positive or release workflow. For a connector, rule or DNS problem, preserve the prior configuration and make a scoped change with the service owner. Do not add a tenant-wide bypass.
If a rule is named, compare its current settings with the settings at the message's time. A rule may have changed since the trace event. Record that uncertainty before attributing the original action to today's configuration.
Unexpected forwarding or a rule created without authorization can be an incident. Preserve it and use Compromised Account rather than simply deleting the evidence.
Check the original and one controlled test
If the scoped change causes a regression, its authorized owner restores the saved configuration and checks the same route again. Escalate with trace/NDR evidence if another service owns the failure or the cause remains unknown.
Prepare the mail-flow handoff
Problem: missing / delayed / failed / client only Direction and affected recipient scope: Original send time and UTC offset: Message-ID and NDR preserved internally: Trace interval, status and relevant event: Cloud mailbox / upstream system checks: Scoped change and test result: Evidence gap / next owner:
Request mail-flow support with a redacted summary. Agree a secure channel before sharing headers, message bodies or trace exports.