Sending, receiving, and organizing email in Outlook on the web for business
Hi Techniform Graphics
The undeliverable messages you receive for emails you did not send are known as backscatter. This usually happens when a spammer forges your address in the From field. The messages will not necessarily appear in Sent Items because they may not have originated from your mailbox. (To learn more, please visit: Backscatter in cloud organizations)
However, the tenant external recipient rate limit error is separate and means that your Microsoft 365 tenant has reached its outbound limit for external recipients. The limit applies across the entire tenant, including users, shared mailboxes, applications, and automated services. It uses a rolling 24-hour window, so sending becomes available again as earlier recipients fall outside that window. The limit cannot be manually increased or reset.
Because simple address spoofing occurs outside your tenant, it would not normally use your Microsoft 365 outbound allowance. Therefore, I recommend asking your Microsoft 365 administrator to investigate whether an account, application, connector, or automated process has been compromised or is sending unexpectedly.
Your organization's IT administrator should:
- Check Exchange admin center > Reports > Mail flow > Tenant outbound external recipients to review current usage and quota.
- Run a message trace for the affected period to identify which mailbox or service generated the outbound messages.
- Review the Microsoft Defender portal for restricted users and suspicious activity.
- If an account appears compromised, reset its password, revoke active sessions, enable multifactor authentication, and inspect mailbox forwarding and Inbox rules. Suspicious rules, unexpected forwarding, and a mailbox being blocked from sending can indicate compromise.
- Verify that SPF, DKIM, and DMARC are correctly configured for the domain. These authentication methods work together to help receiving systems identify forged messages. SPF alone does not provide complete spoofing protection.
You can share these guides with your administrator:
- Troubleshoot outbound sending limits
- Respond to a compromised email account
- Configure email authentication in Microsoft 365
In short, the restriction should clear automatically as usage drops below the tenant limit during the rolling 24-hour window.
For more information, please refer to the following link:"
- Email authentication in cloud organizations
- Troubleshoot email authentication in Microsoft 365
- Respond to a compromised cloud email account
I hope this helps you restore sending and prevent the issue from recurring. If you have any further questions or updates, please don’t hesitate to share.
Kind regards,