An email that is not visible is not necessarily lost. Message trace shows what Exchange Online did with a message; it does not prove that anyone read it. This guide applies to the current Exchange admin center, not on-premises Exchange servers.
Record the specific case
Record sender and recipient addresses, sending time and time zone, any sender feedback and the full internet Message-ID from the message headers. Do not confuse it with the Network Message ID. Work only in the authorized tenant with an appropriate administrative role; additional global privileges are not an investigation goal.
Start a targeted search
- Open the Exchange admin center and confirm the tenant. Go to Mail flow → Message trace and start a new trace.
- Enter the exact sender and recipient addresses; external addresses are supported. Start with a narrow window around the sending time and verify the time zone. Initially leave delivery status set to All so failures are not excluded.
- If the internet Message-ID is known, enter the full string, including any angle brackets, in Message ID. Subject alone is not unique evidence.
- Run the search and open the matching recipient entry. Inspect message events in the details and record times, status and error. For distribution groups and forwarding, inspect related entries too: one message can generate several records.
Interpret the result
- Delivered / Deliver: successful delivery to the destination or mailbox, not proof of reading or Inbox placement. If the message is not visible, check folders, rules and the client view with the mailbox owner.
- Failed / Fail: examine error details together with any nondelivery report, not only the status heading.
- Pending / Defer: delivery is outstanding or being retried. Record the time and events and check again later.
- Quarantined: investigate the quarantine case with appropriate permissions; do not release it solely because someone reports it missing.
Document limits and the conclusion
No results do not prove that nothing was sent. Check addresses, aliases, tenant, time zone and range; current status data can lag by five to ten minutes. Historical data goes back up to 90 days. For direct summary results, query windows of no more than ten days; larger ranges require downloadable reports and can take hours. Archived reports typically do not yet include the last 24 hours.
Record search parameters, recipient event, error code and the next responsible person. Export only necessary data to the designated protected location. Do not change a transport rule, forwarding or filter exception based on an unclear trace. A conclusion might be “delivered to mailbox, folder check pending” or “delivery failed, documented error handed over for action”.
