5.7.64 TenantAttribution; Relay Access Denied
Sample bounce line
550 5.7.64 TenantAttribution; Relay Access Denied [AM0PR0102CA0070.eurprd01.prod.exchangelabs.com 2026-10-02T12:00:00.000Z]
What it means
Exchange Online could not attribute the message to a tenant through an inbound connector. Microsoft's explanation is that an inbound connector is used to receive mail from an on-premises environment and something in that environment changed, leaving the connector's configuration no longer correct.
Why it happens
- The certificate the on-premises server presents no longer matches the certificate name on the inbound connector, usually after a renewal.
- The public IP of the on-premises or appliance sending the mail changed and the connector still lists the old one.
- A connector configured for one domain while the mail is sent for another.
- A third-party filtering service in front of the tenant whose own sending addresses changed.
How to fix it
- Compare the certificate subject or SAN presented by the sending host with the name on the inbound connector and make them agree.
- Update the connector's address list to the IPs that actually send today.
- Confirm the domain being sent for is an accepted domain on the tenant.
- After any change, send one test message and read the headers to confirm the connector matched.
Check your domain now
Many of these errors come from missing or broken SPF, DKIM, DMARC or reverse DNS records. Enter your domain to run the free check.