Inbound Email Delivery Failure from a Specific Vendor Domain Despite Delisting

Ericksanders Lesmana 0 Reputation points
2026-09-11T03:06:48.04+00:00

mail server is currently failing to receive inbound emails from a specific vendor (vendor1.com), while emails from all other external vendors and clients arrive without issues.

The sender domain was previously blacklisted/blocked, but it has since been verified and removed from our internal blocklists, spam filters, and major public DNSBL/RBL databases. Despite confirming the domain is clean and no longer listed as blocked, emails from vendor1.com still do not reach user inboxes or the junk/quarantine folders, and our inbound mail logs show no successful delivery handshakes from their mail exchange servers.

Exchange | Exchange Server | Management
Exchange | Exchange Server | Management

The administration and maintenance of Microsoft Exchange Server to ensure secure, reliable, and efficient email and collaboration services across an organization.

0 comments No comments

2 answers

Sort by: Newest
  1. Jade Ng 15,470 Reputation points Microsoft External Staff Moderator
    2026-09-11T04:26:23.9+00:00

    Dear Ericksanders Lesmana,

    As an initial step, please contact the sender at vendor1.com and ask them to provide the full Non-Delivery Report (NDR) or bounce message generated by their sending system.

    The NDR is important because:

    • The error code can help identify exactly where the delivery failure is occurring.
    • If the sender receives a block-related NDR, it may explain why no inbound SMTP handshake appears in the mail logs.
    • Different error codes can indicate different causes, such as sender IP blocking, connection issues, or routing problems.

    After you receive the NDR, please share the exact error code and full error message with me so I can review it further and advise on the appropriate next steps.

    Additionally, could you please reconfirm whether you are using Exchange Server or Exchange Online? Also, could you check with the sender regarding their email environment? If you are the recipient and there is no record whatsoever of the email being sent (for example, no results appear in Message Trace), this would suggest that the message may not have successfully reached Microsoft's mail service. In that case, I would need to obtain additional information from the sender before providing any further suggestions.

    Kindly let me know the outcome after trying the steps above. Thank you very much for your valuable time and your cooperation.

    I am looking forward to your response!

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-09-11T03:07:08.4133333+00:00

    For this scenario, the next step is to get the sender-side diagnostic data and verify whether the vendor is being rejected before mail ever reaches the environment.

    1. Ask vendor1.com to provide the full non-delivery report (NDR) or bounce message from their sending system.
      • The error code is the key indicator of where the failure occurs.
      • If the vendor receives a block-related NDR, that explains why no inbound handshake appears in the mail logs.
    2. Match the NDR code to the likely cause:
      • 550 5.7.606-649 Access denied, banned sending IP [x.x.x.x]: the vendor’s sending IP is banned by Microsoft 365. The sender should use the self-service delist portal at https://sender.office.com.
      • 550 5.7.511 Access denied, banned sender [x.x.x.x]: the sender should forward the full NDR, including the IP address, to delist@microsoft.com. Microsoft contacts the sender within 48 hours with next steps.
      • 5.7.513 Service unavailable, Client host blocked by recipient domain using Customer Block list: the recipient domain has blocked the sender IP on a custom block list. In that case, the recipient must remove the sender IP from the custom block list.
    3. If the vendor does not receive an NDR, the message might not be reaching Microsoft 365 at all, or it could be failing before final acceptance. In that case, ask the vendor to verify their outbound mail path and MX resolution for the recipient domain.
    4. If the environment is Exchange-based and admin access is available, run message trace for messages from vendor1.com.
      • If the trace shows Failed, inspect the rejection details.
      • If it shows Quarantined, review quarantine in Microsoft Defender.
      • If there is no trace at all, that supports the finding that the vendor’s servers are not successfully reaching the service.
    5. If the issue is only with this vendor and all internal blocklists, spam filters, and public DNSBL/RBL checks are already clear, focus on sender authentication and sender-side reputation.
      • SPF failures on the sender side must be corrected by the sender’s mail administrators.
      • For blocked Microsoft 365 delivery scenarios, the sender must complete the delisting process from their side.

    Based on the symptoms described—no inbox delivery, no junk/quarantine placement, and no successful inbound handshake in logs—the most likely immediate action is to obtain the vendor’s full NDR and have the vendor follow the Microsoft delisting path that matches the returned error code.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.