What you need to know
Exchange Online message trace records how Microsoft 365 handled a message. Narrow queries, the correct identifier, ingestion timing, and preserved results make it useful evidence for mail-flow troubleshooting.
Potentially affected
Exchange Online administrators and support teams investigating delayed, rejected, deferred, quarantined, filtered, recalled, or delivered mail.
DSE recommendation
Collect sender, recipient, UTC time, subject, and Message ID; run the narrowest trace; account for ingestion delay and retention; inspect event details; and preserve the report with the support record.
Source fact: what Microsoft documents
Exchange Online message trace follows a message through the Microsoft 365 organization and reports whether the service received, rejected, deferred, delivered, quarantined, recalled, or filtered it, along with actions taken before the final status. The Exchange admin center begins with a default two-day query, but administrators can narrow by sender, recipient, time, subject, delivery status, Message ID, direction, and other supported fields.
Microsoft currently documents 90 days of message-trace data. Summary results for a range of 10 days or less are available directly; ranges greater than 10 days use downloadable historical reports and can take several hours. PowerShell V2 cmdlets also limit an individual query to 10 days within the retained period. A newly sent message can take approximately 5–10 minutes to appear, and displayed delivery status can have a similar delay.
The Internet Message ID from the message header is constant for the life of the message and is useful for a precise investigation, although not every external system creates a standards-compliant unique value. Trace proves how Exchange Online processed the message; a Delivered status does not prove that a person read it or that a downstream client displayed it.
Permissions and applicability
Message trace applies to Exchange Online and requires appropriate Exchange Online or Microsoft Entra administrative permissions. Microsoft documents Organization Management, Exchange Administrator, or Global Administrator as paths, while recommending the least-privileged available role and limiting Global Administrator to emergency use. Report size, event detail, status filters, and government-cloud behavior can vary.
DSE recommendation: production-safe operational steps
- Record the reporter, affected mailbox, exact sender and recipient addresses, UTC or documented local time with zone, approximate send time, subject, Message ID, expected behavior, and any nondelivery report.
- Wait for the normal ingestion interval when the message is new, then search the smallest possible time and recipient scope.
- Review detailed events and the policy or connector action, not only the final status. Correlate quarantine, transport-rule, connector, and authentication results where relevant.
- For older data, request the appropriate historical report early enough for processing and before the 90-day retention boundary.
- Export or capture results with the query criteria, time zone, trace time, administrator, and message identifiers. Protect message data as operational evidence.
- Change mail-flow policy only after the trace and configuration identify a reproducible cause. Test any change with representative legitimate and unwanted mail.
DSE recommends preserving the original report before rerunning or changing the query. When a message crosses another mail service, gateway, archive, or recipient system, obtain evidence from that system as well. Do not infer behavior outside Exchange Online from the Microsoft trace alone.
Official references
- Message trace in the Exchange admin center in Exchange Online — query options, time ranges, statuses, permissions, and event detail.
- Message Trace FAQ in Exchange Online — ingestion timing, retention, PowerShell V2, and historical reports.
Review the official source
Microsoft Learn: Message trace in the Exchange admin center in Exchange Online · Published May 27, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE