MailFixIt

Microsoft 365 connector error

Fix Outlook 550 5.7.64 TenantAttribution relay denial

Microsoft documents 5.7.64 TenantAttribution; Relay Access Denied when an inbound connector for an on-premises environment no longer matches the environment sending mail.

Problem description

The NDR reports:

550 5.7.64 TenantAttribution; Relay Access Denied
Diagnostic availability: this is private Microsoft 365 connector state. Public DNS cannot confirm tenant attribution, so MailFixIt has no checker CTA here.
Is this temporary or permanent?

The response is permanent until connector or sending-environment configuration matches again.

What changed?

Resolution sequence

  1. Confirm the final source IP and certificate presented to Exchange Online.
  2. Inspect the matching inbound connector's scope and identification method.
  3. Compare intended hybrid topology with current message trace.
  4. Update the connector through approved Microsoft 365 administration procedures.
  5. Test narrowly and confirm tenant attribution before restoring volume.

Frequently asked questions

What does Microsoft 5.7.64 mean?

Exchange Online could not attribute relayed mail to the expected tenant because the inbound connector no longer matches the on-premises environment.

Is this an MX error?

Not normally. Microsoft identifies inbound connector configuration as the primary owner.

What changes commonly trigger it?

Public IP, certificate, smart-host, hybrid, or connector-scope changes can break tenant attribution.

Related email diagnostics

Primary source: Microsoft Exchange Online NDR reference.