logo
search
Outlook Error Codes

How to Fix Outlook Error 550 5.4.312 DNS Query Failed

Kushani NimanthikaKushani Nimanthika Sep 28, 2026 870 views

Question details

The user is experiencing email delivery failures when sending messages from Microsoft 365 Outlook to specific external domains, receiving a DNS query failed error.

How to Fix Outlook Delivery Error 550 5.4.312 DNS Query Failed
Product
Microsoft 365 Outlook
Device & OS
not provided
Scenario
Sending emails to specific external domains (such as university domains) from a Microsoft 365 Exchange account.
Observed behavior
Emails are not delivered, and the Exchange message trace reports '550 5.4.312 Message expired, DNS query failed, ServerFailure', even though other providers like Gmail deliver successfully to the same addresses.
Before you start

Ensure you have administrative access to your Microsoft 365 admin center and your domain's DNS hosting provider, as resolving this issue requires checking and modifying DNS records.

Solution 1Recommended

Verify and Update Sender DNS Records (SPF, DKIM, DMARC)

Properly configuring your sender domain's email authentication records can resolve routing rejections caused by strict security policies on the recipient's server.

Even if the error points to a DNS query failure, ensuring your own domain's reputation and authentication are fully established is a critical first step. Missing or misconfigured SPF and DKIM records can cause recipient servers to silently drop connections or reject queries from your tenant.

1
Log in to DNS provider

Sign in to your domain registrar's DNS management portal where your custom domain is hosted.

2
Verify SPF record

Locate your TXT records and ensure your SPF record correctly includes 'include:spf.protection.outlook.com' for Microsoft 365.

3
Configure DKIM and DMARC

Generate DKIM keys in the Microsoft 365 Defender portal, add the provided CNAME records to your DNS, and set up a DMARC TXT record to specify how receiving servers should handle authentication failures.

Verify and Update Sender DNS Records (SPF, DKIM, DMARC)
Free Microsoft Office alternative

Looking for a Lightweight and Free Alternative to Microsoft Office? Try WPS Office

If you are dealing with complex Microsoft 365 configuration errors, you might appreciate a simpler, user-friendly office suite. WPS Office provides a lightweight, highly compatible alternative to Microsoft Word, Excel, and PowerPoint without the hassle of complicated backend setups.

  1. 1. Visit the website: Go to the official WPS Office website.
  2. 2. Download the installer: Click the Free Download button for your respective operating system (Windows, Mac, or Linux).
  3. 3. Install and launch: Run the downloaded installer file and follow the on-screen instructions to start using your new office suite.
Seamlessly opens and edits Microsoft Office formats (.docx, .xlsx, .pptx)Completely free core features with a lightweight installation footprintBuilt-in PDF editor for easy, all-in-one document managementFamiliar user interface makes migration effortless for former MS Office users
microsoft office alternative - wps office

Frequently Asked Questions

Why can Gmail send emails to the recipient but Outlook cannot?

Different email service providers use different DNS resolvers and routing paths. If the recipient domain recently updated their DNS records or has a localized routing issue, Gmail's cached DNS might still connect successfully, whereas Microsoft 365's strict real-time query fails.

What does 'ServerFailure' mean in the 5.4.312 error?

'ServerFailure' indicates that the sender's email server (Exchange Online) was unable to successfully query the recipient domain's DNS records. This is often due to query timeouts, misconfigured name servers on the recipient's end, or domain expiration.

How long does it take for DNS changes like SPF or DKIM to take effect?

DNS changes typically take anywhere from 15 minutes to 48 hours to fully propagate across the global internet. You should wait at least an hour after modifying SPF or DKIM records before testing email delivery again to ensure the receiving servers see the new rules.

Can an expired recipient domain cause the 550 5.4.312 error?

Yes. If the recipient's domain expires, their DNS records (including MX records) are deactivated by their registrar. This prevents any sending server from looking up where to route the email, immediately resulting in a DNS query failure.