How to Fix Outlook Error 550 5.4.312 DNS Query Failed
Question details
The user is experiencing email delivery failures when sending messages from Microsoft 365 Outlook to specific external domains, receiving a DNS query failed error.

- Product
- Microsoft 365 Outlook
- Device & OS
- not provided
- Scenario
- Sending emails to specific external domains (such as university domains) from a Microsoft 365 Exchange account.
- Observed behavior
- Emails are not delivered, and the Exchange message trace reports '550 5.4.312 Message expired, DNS query failed, ServerFailure', even though other providers like Gmail deliver successfully to the same addresses.
Ensure you have administrative access to your Microsoft 365 admin center and your domain's DNS hosting provider, as resolving this issue requires checking and modifying DNS records.
Verify and Update Sender DNS Records (SPF, DKIM, DMARC)
Properly configuring your sender domain's email authentication records can resolve routing rejections caused by strict security policies on the recipient's server.
Even if the error points to a DNS query failure, ensuring your own domain's reputation and authentication are fully established is a critical first step. Missing or misconfigured SPF and DKIM records can cause recipient servers to silently drop connections or reject queries from your tenant.
Sign in to your domain registrar's DNS management portal where your custom domain is hosted.
Locate your TXT records and ensure your SPF record correctly includes 'include:spf.protection.outlook.com' for Microsoft 365.
Generate DKIM keys in the Microsoft 365 Defender portal, add the provided CNAME records to your DNS, and set up a DMARC TXT record to specify how receiving servers should handle authentication failures.

Contact the Recipient Administrator to Verify MX Records
The error frequently originates from the recipient domain having expired or possessing misconfigured MX records that prevent DNS queries from completing.
Escalate to Microsoft Support with Message Trace Details
If both the sender and recipient DNS configurations are flawless, a routing glitch within the Exchange Online network may require Microsoft's intervention.
Looking for a Lightweight and Free Alternative to Microsoft Office? Try WPS Office
If you are dealing with complex Microsoft 365 configuration errors, you might appreciate a simpler, user-friendly office suite. WPS Office provides a lightweight, highly compatible alternative to Microsoft Word, Excel, and PowerPoint without the hassle of complicated backend setups.
- 1. Visit the website: Go to the official WPS Office website.
- 2. Download the installer: Click the Free Download button for your respective operating system (Windows, Mac, or Linux).
- 3. Install and launch: Run the downloaded installer file and follow the on-screen instructions to start using your new office suite.

Frequently Asked Questions
Why can Gmail send emails to the recipient but Outlook cannot?
Different email service providers use different DNS resolvers and routing paths. If the recipient domain recently updated their DNS records or has a localized routing issue, Gmail's cached DNS might still connect successfully, whereas Microsoft 365's strict real-time query fails.
What does 'ServerFailure' mean in the 5.4.312 error?
'ServerFailure' indicates that the sender's email server (Exchange Online) was unable to successfully query the recipient domain's DNS records. This is often due to query timeouts, misconfigured name servers on the recipient's end, or domain expiration.
How long does it take for DNS changes like SPF or DKIM to take effect?
DNS changes typically take anywhere from 15 minutes to 48 hours to fully propagate across the global internet. You should wait at least an hour after modifying SPF or DKIM records before testing email delivery again to ensure the receiving servers see the new rules.
Can an expired recipient domain cause the 550 5.4.312 error?
Yes. If the recipient's domain expires, their DNS records (including MX records) are deactivated by their registrar. This prevents any sending server from looking up where to route the email, immediately resulting in a DNS query failure.




