We're having a major issue today with messages from an on-site mail server that relay through Proofpoint Essentials, along with legitimate emails sent to people in our finance department. Proofpoint is flagging valid messages, and even items marked as remediated and released from quarantine aren't arriving in our Exchange Online mailboxes. This is the first time we've encountered something this severe, and I already have a P1 support case open with Proofpoint. Is anyone else seeing similar behavior, especially when sending to or receiving from organizations that use Proofpoint?
4 Answers
Treat the false positives and the failed releases as two separate problems. For a released message, record its Proofpoint message ID and run a trace in the Exchange admin center. That should show whether Microsoft 365 rejected it, quarantined it again, routed it elsewhere, or never received it. If Proofpoint says the release succeeded but Microsoft 365 has no trace at all, that points toward a Proofpoint-side delivery problem.
We’re also seeing trouble sending and receiving messages with recipients whose organizations use Proofpoint. It isn’t fully confirmed yet, but Proofpoint is the common factor so far.
Make sure the released copy is actually arriving through the expected Proofpoint connector, and confirm that the connector only accepts traffic from the approved Proofpoint hosts. If the trace shows delivery to another folder or a transport-rule action, the issue is in your tenant. If there’s no trace whatsoever, the message likely never left Proofpoint and the vendor ticket is the right path.
Check Microsoft Defender quarantine as well as Proofpoint. A common pattern is that Proofpoint releases the message, it comes back through the inbound connector, and Exchange Online catches it a second time. Message trace will show where it stopped. Also verify enhanced filtering and the connector configuration so Microsoft 365 recognizes the original sender correctly instead of judging only Proofpoint’s relay IP. Since finance is being affected, look for a recent change involving impersonation, supplier-risk, or lookalike-domain detection rather than assuming it’s a general outage.

That distinction is really helpful. I’m going to compare the Proofpoint release records with Microsoft 365 message traces instead of relying on the release status alone. The issue could easily be happening during the second pass through Exchange Online.