Microsoft 365 email configuration guide

Microsoft 365: MX records not receiving mail

Public MX records must lead to the receiving path configured for the Microsoft 365 accepted domain and existing recipient.

Problem description

A provider setup symptom may look like:

MX records not receiving mail after a provider DNS change.

Check the sending domain

What this usually means

Mail is routed somewhere other than the intended Microsoft 365 receiving path, or Exchange Online does not recognize the domain or recipient. An intentional email-security gateway may correctly appear in public MX instead of Microsoft.

Fix it

  1. Confirm that the domain is verified and configured as an accepted domain in the correct Microsoft 365 tenant.
  2. Create or synchronize the mailbox, mail user, group, or alias before changing mail flow.
  3. If Exchange Online receives mail directly, copy the tenant-specific MX target shown in Microsoft 365 and publish it for the domain.
  4. If a security gateway receives first, keep its MX records and verify the gateway’s next hop plus Microsoft 365 connector.
  5. Remove stale provider MX records only after confirming they are not part of the intended route, then send a new test to an existing recipient.

Common mistake

A generic Microsoft MX value from another tenant is wrong. Public MX also cannot show whether Exchange Online accepts the domain or recipient.

What MailFixIt can check

MailFixIt can identify missing, mixed, or unexpected public MX records. Tenant objects, connectors, and message trace require Microsoft 365 administration.

Use the related MX and DNS-change guides when the public route still points to an old provider.

Frequently asked questions

What does MailFixIt check for Microsoft 365?

It can show the public MX route and provider conflicts. The Microsoft 365 tenant must confirm the accepted domain, recipient, and connector state.

Should I replace every existing DNS record with the provider values?

No. Confirm the exact record type and owner, preserve unrelated legitimate services, and change only the provider-controlled record required for the intended mail route.

Related email diagnostics

Primary sources: Microsoft 365 official setup guidance.