Microsoft is investigating Exchange Online incident EX1464935, a service disruption causing Outlook and Exchange Online authentication failures, mailbox-operation errors, synchronization problems, and delayed or failed inbound and outbound email delivery. Administrators reported Outlook on the web access issues, failed searches, administrative-function disruptions, and mail-flow errors including 550 5.6.200 STOREDRV.Deliver; message is treated as poison. Downdetector reports indicated that tens of thousands of users were affected, with organizations in the U.S. Southwest reporting particularly substantial impact while some tenants remained operational.
Microsoft identified a shared failure pattern involving authentication and protocol connectivity and is reviewing telemetry to establish the root cause, affected scope, and remediation options. Exchange Online is the only service Microsoft has formally identified as affected; separate user reports involving Teams, Azure, Microsoft Store, and a distinct Teams VDI issue (TM1463371) have not been confirmed as related. Organizations should monitor the Microsoft 365 Service Health Dashboard, mail queues, delivery reports, and Exchange connectivity while the investigation continues.

See attribution, scope, and your downstream exposure.
10 events from the most recent confirmed update back to the earliest known activity.
Administrators reported Microsoft 365 email from two domains bouncing when sent to personal Gmail recipients, with bounce messages saying a Microsoft outbound IPv6 address failed SPF authentication. A second administrator also reported similar failures and observed failed DNS resolution for SPF, DKIM, and DMARC records; the cause and any link to the prior Microsoft outage were unconfirmed.
A sole administrator reported that scanner email relayed through SMTP2GO remained in a processed state for more than 12 hours before reaching its Microsoft 365 tenant. Whitelisting SMTP2GO IPs did not resolve the delays, while an SMTP2GO IP rotation briefly allowed one message through; other inbound mail to the tenant continued to function normally.
Administrators reported frequent errors, failed data loads, lengthy load times, and repeated release or deletion attempts in the Microsoft 365 email-quarantine portal. One commenter said the quarantine functionality had been worse than usual since the Monday outage.
Microsoft acknowledged EX1464935 as an incident after user reports, while Downdetector indicated tens of thousands of affected users. Reported impacts included authentication errors, failed or delayed email delivery, mailbox-operation failures, Outlook web access issues, and Exchange administration problems.
Microsoft confirmed it was investigating reports exceeding its alerting threshold and opened EX1464935. The advisory formally identified Exchange Online as the affected service and warned of degraded functionality.
Exchange Online incident EX1464935 began, with users reporting access problems and mail-flow failures.
A separate mail-flow pipeline incident caused Exchange Online message-delivery delays across North America, Europe, and Asia-Pacific, with some messages delayed by more than an hour.
Microsoft attributed the separate Exchange Online incident EX1454755 to a DNS-related fault at a third-party email provider.
Microsoft attributed the broader Microsoft 365 outage to a core authentication configuration used by multiple services, applied a fix to the affected component, and reported increasing availability. The company validated recovery of authentication, connectivity, and search operations while monitoring for residual effects, including Exchange Online scenarios.
Microsoft identified a shared failure pattern involving authentication and protocol connectivity in affected Exchange Online requests. Engineers analyzed telemetry and mail-flow diagnostics to determine the root cause, impact scope, and remediation options.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
15 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcereddit.com
Open sourcereddit.com
Open sourcereddit.com
Open sourcecybersecuritynews.com
Open sourcereddit.com
Open sourcereddit.com
Open sourcedowndetector.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.