Exchange Online Message Trace for Missing Business Email

A missing customer reply can stall an order before anyone knows where the message went. An Exchange Online message trace gives your IT team a place to start: it shows how Microsoft 365 handled a message as it moved through your organization.

The result can point to a delivery failure, filtering, or a mailbox that needs closer inspection. Start with the message details, then follow the trace rather than guessing at the cause.

Key Takeaways

  • Search with the sender, recipient, and a narrow time range. Keep the exact error or bounce message if the sender received one.
  • Read the trace events alongside the final status. Delivered doesn't prove the email appeared in the user's inbox.
  • If the trace has no result, verify the address and timing before checking systems outside Exchange Online.
  • Message trace records are available for up to 90 days . Older searches within that window may take hours and return a CSV report.

Gather the details before searching

A trace works best when you're looking for one identifiable message. Ask the sender for the address they sent from, the exact recipient address, the approximate send time, and the subject. If they have a nondelivery report, save it. Its error code and message identifiers may explain more than a screenshot of the sent item.

Confirm the address the sender used

Check the full address, including its domain. A customer may have written to an old employee address, an alias, or a shared mailbox rather than the person who reported the problem. A distribution group introduces another question: which members should have received the message?

For automated email, identify the sending service too. Invoices from accounting software and alerts from a scanner may use different sender addresses than staff expect.

Pin down when it happened

Record the sender's local time and time zone. Then allow a reasonable margin around that time in the search. A message reported as "sent at 9" might have left an application queue later.

Ask whether one email is missing or several. A single missing reply calls for a narrow search; a pattern across customers or mailboxes may point to a rule, connector, filtering policy, or wider service issue.

How to run an Exchange Online message trace

Sign in with an account that has the appropriate Exchange Online permissions. An Exchange administrator can usually investigate mail flow without using a Global administrator account. In the Exchange admin center , open Mail flow > Message trace , then select Start a trace .

Search narrowly first

Enter the known sender and recipient addresses, and choose a time range around the reported send time. Run the search, then compare the returned messages with the subject and timing you collected. Open the matching result to inspect its details and event history.

If you can't find it, widen the time range before changing every filter at once. Search the alias or shared mailbox address the sender used, not only the employee's primary address. A message sent to a group may need a closer look at recipient expansion.

Keep a record of what you find

Save the sender, recipient, subject, time, and trace result with the support ticket. For a recurring problem, note whether the same sender or destination appears in each incident. This helps the next administrator distinguish a new failure from a repeat of the same one.

The Microsoft Defender portal also provides a route to Exchange message trace under Email & collaboration . It reaches the same investigation tool, so use whichever portal your team normally works in.

What the trace status means

Start with the final status, but don't stop there. A trace can show that Exchange Online received, rejected, deferred, or delivered a message. Its events provide the detail needed to decide what happened next.

Trace result What it tells you Where to look next
Delivered Exchange Online completed a delivery step. Check event details, the destination, and the recipient's mailbox.
Failed Delivery did not complete. Read the reported reason and compare it with any nondelivery report.
Pending Processing has not reached a final result. Check again later for an updated status.
Filtered as spam Spam filtering affected the message. Review the filtering details and any applicable quarantine record.

The status narrows the search. The event history tells you whether the next step belongs with your mailbox team, security team, or sender.

Read the failure, not just the word "Failed"

A failed result can reflect different problems, including an invalid destination or a policy-related rejection. Open the details and record the error text. If the sender received a nondelivery report, compare its code and recipient address with the trace.

A deferral means delivery was delayed during processing; it isn't the same as a final failure. Likewise, a pending result isn't proof that the message was lost. Check for a later event before asking the sender to resend sensitive or time-critical material.

Look for processing that changed the route

Mail flow rules, data loss prevention policies, and filtering can affect a message before delivery. Review events for a rule or policy action, especially if the message was redirected, rejected, or handled differently than similar email.

A final Delivered status can coexist with processing that changed the expected destination or message. That's why an administrator should confirm the actual route before telling a user to search their inbox again.

When a delivered message is still missing

"Delivered" often shifts the investigation toward mailbox access and post-delivery activity. Ask the recipient to search Outlook on the web using the sender and subject. Check Junk Email , Deleted Items , and other folders, as well as any focused or filtered inbox view. Comparing Outlook on the web with a desktop or mobile app also helps identify a device-specific display problem.

Check rules and forwarding separately

Review the user's inbox rules for actions that move, delete, or redirect mail. Then check mailbox-level forwarding and the destination configured for it. These controls are separate from organization-wide mail flow rules, and a transport rule review won't replace either check.

If a rule or forwarding address looks unfamiliar, treat that as a security finding. Preserve the relevant details and review recent mailbox changes and sign-in activity. A Microsoft 365 audit log review checklist can help the team examine suspicious mailbox activity beyond the message trace.

Verify the mailbox people actually use

For a shared mailbox, confirm the user has access to the correct mailbox and is searching inside it. For a distribution group, confirm membership and inspect how Exchange Online handled the group recipient. An employee's personal inbox may be the wrong place to look.

Message trace doesn't show that someone read an email. It also isn't a complete record of later mailbox actions. Use mailbox searches, rule checks, and audit records to answer those separate questions.

What to do when the trace shows no message

A blank search result doesn't prove the sender never sent the email. First, check the spelling of both addresses, the recipient alias, and the time range. Ask for the original sent message or a nondelivery report if you only have a verbal description.

Check where the message was supposed to enter

Confirm the sender addressed your Microsoft 365 domain and that the domain's mail route points where you expect. If a third-party email security gateway sits in front of Exchange Online, check that gateway's logs. A message blocked there may never reach the tenant for Exchange Online to trace.

The sender's mail system may also have held or rejected the message before handing it off. Ask the sender's IT team to investigate their outbound records when your tenant has no matching result.

Test the path without losing the evidence

For an ongoing issue, arrange a fresh test using the affected sender and recipient addresses. Record the exact send time and subject, then search for that test separately. Include a normal external sender as a comparison if you suspect a sender-specific problem.

Don't ask someone to delete the original message or its bounce report. Those records may contain the detail needed to identify a failed handoff or policy match.

Understand the trace window and report delays

Exchange Online message trace data is available for 90 days . A message outside that window can't be recovered through a new trace search, so investigate missing invoices, approvals, and customer requests promptly.

Recent searches may return results on screen. Older searches can require a report that arrives as a downloadable CSV and may take a few hours. Microsoft's guidance differs on whether the quick-results period ends at seven or ten days. Allow for a report delay rather than treating an unfinished search as an empty result.

Use PowerShell for repeat investigations

Administrators who need to check several addresses or date ranges can use Exchange Online PowerShell. Get-MessageTraceV2 retrieves trace records, and Get-MessageTraceDetailV2 provides event detail for a message. A single Get-MessageTraceV2 query can cover no more than 10 days , so split a longer investigation into smaller periods.

For historical reporting within the available window, Start-HistoricalSearch is another option. Whichever method you use, retain the search dates and filters with the results. A CSV without its search scope is hard to interpret later.

Know when to escalate the investigation

Escalate quickly if multiple customers can't reach your business, payroll or invoice mail is missing, or a trace shows an unexplained rule or redirect. The same applies when delivered messages repeatedly disappear from one mailbox. These patterns deserve more than another Outlook search.

Give your IT provider the affected addresses, timestamps, trace details, error messages, and a list of users reporting the issue. Include recent changes to mail flow rules, gateways, or security policies if you know of any. For teams without a dedicated Exchange administrator, Microsoft 365 email and Outlook support can help connect the trace result to the tenant settings and user experience.

Once delivery is restored, review recurring causes. Mail filtering, forwarding, domain authentication, and account access belong in the same business email security review, even though each requires its own checks.

Frequently Asked Questions

Can message trace recover a missing email?

No. It helps identify how Exchange Online processed the message; it doesn't restore a deleted item or pull mail back from another system. The trace result tells your team where to investigate recovery options.

Does "Delivered" mean the recipient saw the message?

No. It means Exchange Online recorded a delivery outcome, not that the email appeared in the expected inbox or was read. Check the destination, folders, rules, forwarding, and mailbox access.

How long should an administrator wait for a trace?

A recent message may appear quickly, while an older search can take hours and produce a CSV report. If a newly sent test message isn't visible yet, keep its exact details and check again before deciding it never reached Exchange Online.

Conclusion

A missing email needs a trail, not a guess. Start with the exact sender, recipient, and time , then read the trace events alongside the final status.

If Exchange Online delivered the message, inspect the mailbox and its rules. If there's no trace, follow the path into your tenant. That distinction gets business email problems to the right team faster.

ASK AN IT PRO