Microsoft 365 connector error
Fix Outlook 550 5.7.64 TenantAttribution relay denial
Microsoft documents 5.7.64 TenantAttribution; Relay Access Denied when an inbound connector for an on-premises environment no longer matches the environment sending mail.
The NDR reports:
550 5.7.64 TenantAttribution; Relay Access Denied
The response is permanent until connector or sending-environment configuration matches again.
What changed?
- The on-premises public sending IP changed.
- The TLS certificate name or certificate changed.
- A new gateway or smart host became the final sender.
- The connector was deleted, disabled, or narrowed.
- Hybrid configuration and actual flow diverged.
Resolution sequence
- Confirm the final source IP and certificate presented to Exchange Online.
- Inspect the matching inbound connector's scope and identification method.
- Compare intended hybrid topology with current message trace.
- Update the connector through approved Microsoft 365 administration procedures.
- Test narrowly and confirm tenant attribution before restoring volume.
Frequently asked questions
What does Microsoft 5.7.64 mean?
Exchange Online could not attribute relayed mail to the expected tenant because the inbound connector no longer matches the on-premises environment.
Is this an MX error?
Not normally. Microsoft identifies inbound connector configuration as the primary owner.
What changes commonly trigger it?
Public IP, certificate, smart-host, hybrid, or connector-scope changes can break tenant attribution.
Related email diagnostics
Primary source: Microsoft Exchange Online NDR reference.