Related Tools
Need Help?
Our tools are designed to be intuitive, but if you need assistance, we're here to help.
About Our Tools
Professional-grade email and DNS diagnostic tools trusted by IT professionals worldwide.
Our tools are designed to be intuitive, but if you need assistance, we're here to help.
Professional-grade email and DNS diagnostic tools trusted by IT professionals worldwide.
Modern Microsoft Exchange and Exchange Online rely on multiple service endpoints: Autodiscover, EWS (Exchange Web Services), MAPI over HTTP, and SMTP submission. Connectivity problems often appear as profile creation failures, intermittent sync, or calendar discrepancies. This guide walks through a layered test approach to isolate DNS, TLS, authentication, or service health issues.
autodiscover.example.com and SRV records if applicable./EWS/Exchange.asmx.smtp.office365.com:587 or your on-prem relay.Ensure autodiscover records exist and point to the correct endpoint. Validate certificates with matching CN/SAN, unexpired validity, and a trusted CA. Use:
nslookup autodiscover.example.com
openssl s_client -connect mail.example.com:443 -servername mail.example.com -showcerts
On Exchange on-prem, leverage built-in tests:
Test-OutlookConnectivity -ProbeIdentity OutlookMapiHttpSelfTestProbe
Test-WebServicesConnectivity -ClientAccessServer CAS01 -MailboxCredential (Get-Credential)
Review results for latency, endpoint reachability, and auth errors. In Exchange Online, use Microsoft Remote Connectivity Analyzer to confirm Autodiscover and EWS.
Verify modern auth (OAuth) is enabled where required. Legacy Basic Auth deprecation causes unexpected failures if clients still attempt basic auth. Confirm Conditional Access policies and MFA requirements for affected accounts.
Check firewalls and proxies for TLS inspection that might break SNI or cause certificate pinning issues. Monitor throughput and server health; high CPU or throttling can surface as sporadic sync delays.
With a layered approach, you can quickly isolate whether the issue lies at the edge (DNS/TLS), identity (OAuth/MFA), or service tier (EWS/MAPI/HTTP).