The administration and maintenance of Microsoft Exchange Server to ensure secure, reliable, and efficient email and collaboration services across an organization.
For this scenario, the next step is to get the sender-side diagnostic data and verify whether the vendor is being rejected before mail ever reaches the environment.
- Ask
vendor1.comto provide the full non-delivery report (NDR) or bounce message from their sending system.- The error code is the key indicator of where the failure occurs.
- If the vendor receives a block-related NDR, that explains why no inbound handshake appears in the mail logs.
- Match the NDR code to the likely cause:
- 550 5.7.606-649 Access denied, banned sending IP [x.x.x.x]: the vendor’s sending IP is banned by Microsoft 365. The sender should use the self-service delist portal at
https://sender.office.com. - 550 5.7.511 Access denied, banned sender [x.x.x.x]: the sender should forward the full NDR, including the IP address, to
delist@microsoft.com. Microsoft contacts the sender within 48 hours with next steps. - 5.7.513 Service unavailable, Client host blocked by recipient domain using Customer Block list: the recipient domain has blocked the sender IP on a custom block list. In that case, the recipient must remove the sender IP from the custom block list.
- 550 5.7.606-649 Access denied, banned sending IP [x.x.x.x]: the vendor’s sending IP is banned by Microsoft 365. The sender should use the self-service delist portal at
- If the vendor does not receive an NDR, the message might not be reaching Microsoft 365 at all, or it could be failing before final acceptance. In that case, ask the vendor to verify their outbound mail path and MX resolution for the recipient domain.
- If the environment is Exchange-based and admin access is available, run message trace for messages from
vendor1.com.- If the trace shows Failed, inspect the rejection details.
- If it shows Quarantined, review quarantine in Microsoft Defender.
- If there is no trace at all, that supports the finding that the vendor’s servers are not successfully reaching the service.
- If the issue is only with this vendor and all internal blocklists, spam filters, and public DNSBL/RBL checks are already clear, focus on sender authentication and sender-side reputation.
- SPF failures on the sender side must be corrected by the sender’s mail administrators.
- For blocked Microsoft 365 delivery scenarios, the sender must complete the delisting process from their side.
Based on the symptoms described—no inbox delivery, no junk/quarantine placement, and no successful inbound handshake in logs—the most likely immediate action is to obtain the vendor’s full NDR and have the vendor follow the Microsoft delisting path that matches the returned error code.
References:
- Email non-delivery reports and SMTP errors in Exchange Online
- External senders - Use the delist portal to remove yourself from the blocked senders list and address 5.7.511 Access denied errors
- Fix NDR error "550 5.7.1" in Exchange Online
- Error When Receiving Emails - Microsoft Q&A
- Not receiving most emails all of a sudden - Microsoft Q&A
- No longer able to send or receive emails from particular vendors - Microsoft Q&A Any ideas why one vendor is not receding my emails and I am not receiving emails from a second vendor.