What does an NDR message mean when Microsoft 365 does not deliver an email?
An NDR is a non-delivery report that contains a code and details of the server that rejected the message. The cause may be an incorrect address, missing or full mailbox, security restriction, domain authentication, connector, reputation, or time limit. The exact code and trace of the message should be reviewed before changing DNS or policies.
Risks to review
- Retry repeatedly and trigger sending limits or anti-spam controls.
- Modify SPF, DKIM, DMARC or connectors without identifying the rejection code.
- Add senders or entire domains to allowlists to solve one isolated case.
- Publish an NDR containing addresses, servers or internal identifiers in public forums.
Safe recommendations
- Keep the complete NDR and record sender, recipient, time and status code.
- Check the address and test whether the problem affects one or more recipients.
- Use the Exchange Online message trace to determine where the flow ended.
- Review service status and DNS records only when the error points to them.
- Validate connectors, rules, and anti-spam policies before creating exceptions.
- Perform a controlled test and document the change that resolved the problem.
When to seek specialized help
- The rejection affects the whole domain or multiple external recipients.
- The NDR mentions blocking, authentication, a connector or a 5.7.x error.
- A compromised account may be sending bulk email.
Reference sources
These public sources provide general good-practice guidance. They do not replace an assessment of your environment.

