How do Exchange Online sending and receiving limits work?

Exchange Online applies several independent limits, not one sending quota. A recipient can receive 3,600 messages per hour, one sender is limited to 33% of that recipient's hourly volume, a user can address 10,000 recipients in a rolling 24-hour window, and a tenant has a separate daily limit for external recipients. Per-message, per-minute, message-size, and outbound-spam controls also apply. Diagnose the direction, scope, counter, and time window before changing a mail flow.
Quick takeaways
- Receiving limits protect a user, group, or public folder. Sending limits constrain a user, a message, or the whole tenant.
- The published receiving limit is 3,600 messages per hour, and the sender-recipient pair limit is 33% of that total.
- The per-user recipient rate limit is 10,000 recipients in a rolling 24-hour window, not 10,000 messages and not a midnight reset.
- A single message can address up to 1,000 recipients when the mailbox setting allows it, while the message-rate limit is 30 messages per minute.
- Tenant External Recipient Rate Limit, or TERRL, counts external recipients across the tenant and scales with eligible email licenses.
- Exchange Online is not designed as a bulk commercial mail platform. Moving newsletters to a suitable provider is safer than trying to evade service limits.
Each counter has its own direction, scope, and time window. Open the full-size Exchange Online limit map.
The limits that are easiest to confuse
Microsoft's current Exchange Online limits page separates receiving limits from several outbound counters. The numbers can look similar in an alert or NDR, but they answer different questions:
- Receiving limit: How many messages did this recipient receive from all sources in one hour?
- Sender-recipient pair limit: How many messages did one sender send to this one recipient in an hour?
- Recipient rate limit: How many recipients did this user address during the last 24 hours?
- Recipient limit: How many recipients are on this one message?
- Message rate limit: How many messages did this user submit per minute?
- TERRL: How many external recipients did the entire tenant address during the last 24 hours?
- Message size limit: How large is this message after the relevant client and transport handling?
This guide covers organizational Exchange Online. Consumer Outlook.com sending policies, on-premises Exchange Server settings, Microsoft Graph throttles, and provider-specific marketing-platform limits are separate systems.
How the Exchange Online receiving limit works
The receiving limit applies to an Exchange Online user, group, or public folder. Microsoft currently publishes 3,600 messages per hour across the supported Microsoft 365 and Office 365 plans shown in its service description.
The counter includes messages from internal senders, the internet, and on-premises servers. When the threshold is exceeded, Microsoft says messages from the internet and on-premises senders are returned with an NDR stating that the mailbox exceeded the maximum delivery threshold. Internal messages still count, but they are not blocked by this limit. The counter refreshes after an hour.
This creates an important diagnostic pattern. A mailbox can continue receiving internal mail while external senders bounce. That does not prove the external sender is blocked for reputation or authentication. It can be a recipient-side volume limit.
The limit also explains why operational mailboxes are vulnerable to notification storms. An alerting platform, scanner, ticket system, loop, or application that produces one message per event can fill a recipient's hourly capacity even when every message is legitimate.
How the sender-recipient pair limit works
The sender-recipient pair, or SRP, limit constrains the volume from one sender to one recipient. Microsoft publishes it as 33% of the overall receiving limit. That is roughly 1,200 messages per hour, but treat the percentage as the documented value instead of hard-coding a rounded count into an application.
If one sender crosses the pair limit, Exchange Online can stop accepting that sender's internet or on-premises messages for the affected recipient while continuing to accept other senders. That is narrower than the overall receiving limit.
The distinction helps isolate the cause:
- one sender fails to one recipient while other senders work: investigate the SRP limit or a sender-specific control
- every external sender fails to one recipient: investigate the overall receiving limit or a recipient problem
- one sender fails across many recipients: investigate outbound throttling, reputation, authentication, or a sender-wide policy instead
How the per-user recipient rate limit works
The outbound recipient rate limit is 10,000 recipients per user in a rolling 24-hour window for the Exchange Online plans in Microsoft's current table. It counts outbound and internal recipients. It is not a count of messages.
A message to ten recipients consumes ten recipient units. A user who sends 500 messages to twenty recipients each has addressed 10,000 recipients. Microsoft says the mailbox cannot send again until enough recipient events fall out of the prior 24-hour window.
The distribution-list behavior depends on where the list lives. A distribution group in the organization's shared address book counts as one recipient for the per-user rate limit. A personal list in a mailbox Contacts folder is expanded and its members count individually.
Sending through permissions does not move the counter to the visible From mailbox. Microsoft states that sending from another mailbox is counted for the delegate who used the permission. This matters when a service account or operator sends as a shared mailbox.
If the NDR says The message can't be submitted because the sender's submission quota was exceeded, Microsoft's submission-quota troubleshooting page points to the 10,000-recipient limit. If the user did not generate that volume, treat possible account compromise as an incident, not as a quota-planning problem.
How the per-message and per-minute sending limits work
Recipient limit on one message
Exchange Online allows the per-message recipient limit to be customized up to 1,000 recipients. This counts the addresses in To, Cc, and Bcc for one message. Administrators can set a lower value for existing or future mailboxes.
This is different from the 10,000-recipient rolling limit. A user can stay below 10,000 for the day and still fail because one message exceeds the mailbox's per-message setting.
Meeting messages have another ceiling. Microsoft currently documents a 5,000-recipient maximum for an outgoing meeting invitation, update, or cancellation. That exception does not turn Exchange Online into a general broadcast service.
Message rate limit
Microsoft publishes a 30 messages per minute limit for Exchange Online. Its service description says excess outbound volume is throttled and carried into later minutes. For SMTP client submission, messages above the rate can be rejected and the client must retry.
A sound client distinguishes a temporary submission response from a permanent rejection, uses bounded backoff, and preserves message identifiers. The guide to SMTP error 421 explains the broader difference between a temporary server response and a permanent bounce.
Do not add more concurrent connections to force traffic through. That can increase retry noise while leaving the account-level counter unchanged.
How the tenant external-recipient limit works
TERRL is a tenant-wide rolling 24-hour limit for recipients whose domains are not accepted domains in the tenant. It is separate from each user's 10,000-recipient limit. A tenant can therefore stay below every individual mailbox limit and still exceed its combined external-recipient allowance.
Microsoft says the allowance depends on eligible non-trial email licenses and exposes the current threshold in Exchange admin center > Reports > Mail flow > Tenant Outbound External Recipients. The current published formula for non-trial tenants is:
500 * (non-trial email licenses ^ 0.7) + 9,500
The official TERRL announcement notes that Exchange Online or Exchange Online Protection licenses count. Trial-only tenants are capped at 5,000 external recipients per day. Group members are counted after expansion, so a group with 1,000 external members consumes 1,000 external-recipient units.
Messages sent from the default onmicrosoft.com domains have a much smaller tenant rule: 100 external recipients per organization in a rolling 24-hour window. Microsoft's service description associates excess sends with NDR 550 5.7.236. Use a verified custom domain for ordinary business mail rather than treating the default tenant domain as a production broadcast identity.
Microsoft's current NDR reference identifies 550 5.7.233 as a tenant external-recipient rate problem. That is not the same incident as one user's submission quota, a recipient's hourly limit, or an SMTP reputation block.
How message-size limits fit in
Message size is another independent layer. Microsoft currently states that the default maximum for Microsoft mailboxes is 35 MB for sending and 36 MB for receiving, with administrator-configurable values from 1 MB to 150 MB. The effective limit can still be lower because of the client, mailbox setting, transport path, or recipient system.
The 150 MB headline needs context. Microsoft says messages that stay inside its datacenters can be sent and received up to 150 MB. Messages routed outside Microsoft datacenters are subject to a 33% encoding increase, which makes the maximum 112 MB. Outlook on the web also reserves encoding headroom and can restrict the message to 25% less than the configured setting.
Do not compare only the attachment's file size with the mailbox setting. MIME encoding, headers, and other message parts can make the transmitted message larger. For large files, use an approved file-sharing workflow rather than raising every mailbox to the service maximum.
How to diagnose which limit was reached
Capture the exact evidence
Save the NDR or client response, sender, recipients, UTC time, message ID, submission method, and whether the failure was inbound or outbound. The exact response text is more useful than a screenshot of a generic send error.
If the response is a Microsoft 5.4.1, do not assume it is a quota. The guide to Microsoft SMTP 5.4.1 separates invalid-recipient and relay-routing failures from these volume limits.
Identify the scope
Compare controlled tests without creating more volume:
- same sender to a different Exchange Online recipient
- different sender to the affected recipient
- internal sender versus internet sender
- one-recipient message versus many-recipient message
- affected user versus another user in the same tenant
Use the right Microsoft report
For inbound pressure, open the Exchange admin center's Mailboxes exceeding receiving limits report. Review Hot, SRP, and Warm events, the affected mailbox, hour, limit value, maximum observed rate, and top sender.
For tenant outbound volume, use Tenant Outbound External Recipients and compare ObservedValue with Threshold and EnforcementEnabled. For a user-level incident, review message trace, alerts, audit evidence, and the user's recent legitimate activity. An unexplained spike can indicate a compromised account.
Check policy without confusing it with service capacity
Outbound spam policies can set external, internal, and daily recipient thresholds from 0 to 10,000 and choose the restriction applied when a user reaches them. Microsoft's outbound spam policy documentation says the default value 0 uses service defaults.
A custom policy can set a safer lower threshold for a user class. It does not raise the Exchange Online service limit or TERRL. Also review the default alerts for sending-limit events and restricted users instead of relying on a mailbox owner to report the failure.
Fix the traffic pattern, not the counter
For an inbound notification storm, reduce event fan-out. Batch repeated alerts, suppress duplicates, set severity thresholds, or send summaries to an operations system designed for that load. Moving the same flood to another mailbox only transfers the risk.
For an SRP event, pace the single sender-to-recipient flow and change the application that creates one message per event. Do not rotate sender addresses to evade the pair limit. That hides the defective pattern and can create reputation problems.
For a legitimate user who reaches the rolling recipient rate, wait for events to age out and move future bulk communication to a platform intended for it. For unexplained volume, secure the account, review delegates and rules, revoke sessions where appropriate, and preserve audit evidence.
For TERRL, verify the report and route legitimate high-volume external email through a fit-for-purpose service. Microsoft explicitly recommends a specialized provider for bulk commercial email and points high-volume external use cases toward Azure Communication Services email. License purchases should follow real user and product needs, not a plan to manufacture quota.
How to validate the repair
Wait until the relevant rolling window has cleared or the report shows the counter below its threshold. Then send a small, labeled test through the same route that failed. Confirm submission, message trace, recipient delivery, and absence of a new limit event.
Watch the next normal production interval. Record messages per recipient per hour, messages per sender-recipient pair, recipients per user over 24 hours, and tenant external recipients over 24 hours. Set internal warning thresholds below Microsoft's ceiling so the team can act before delivery stops.
A successful one-message test proves the path is open. It does not prove that the repaired application can sustain its old rate safely. It also does not prove inbox placement, as the separate investigation for a Mailchimp message marked delivered but placed in spam demonstrates. Increase only to the intended normal load and stop if the relevant counter climbs unexpectedly.
Where Palisade fits
Palisade does not raise Exchange Online quotas, read private tenant counters, change outbound spam policies, pace application traffic, or guarantee delivery. Microsoft reports and the sending application's logs are the sources of truth for these limits.
Palisade can help with a separate layer: using DMARC aggregate data to identify services sending as your domains and show their SPF, DKIM, and DMARC results. If a Microsoft response identifies authentication rather than a volume counter, use the free Email Security Score to review the public configuration. If the incident exposes an unmanaged sender inventory across several domains or clients, start a Palisade account after the quota and traffic design are corrected.
Frequently asked questions
Is the Exchange Online 10,000 limit messages or recipients?
It is recipients per user over a rolling 24-hour window. One message to 100 recipients consumes 100 units. A shared-address-book distribution group counts as one for this per-user limit, while members of a personal contact list count individually.
Does the Exchange Online recipient limit reset at midnight?
No. Microsoft describes a rolling 24-hour window. Sending capacity returns as earlier recipient events age out. The restriction action in an outbound spam policy can use a next-day UTC boundary, but that policy action is not the same counter behavior.
Can an administrator increase the 10,000-recipient rate limit?
Not as a normal mailbox customization. Administrators can set the per-message recipient limit up to 1,000 and can configure lower outbound spam policy thresholds, but Exchange Online's published per-user service rate remains 10,000 recipients per 24 hours.
Does the 3,600-message receiving limit block internal mail?
Internal messages count toward the hourly total, but Microsoft says they are not blocked when the receiving limit is exceeded. Internet and on-premises senders receive NDRs until the limit refreshes.
Is the sender-recipient pair limit exactly 1,200 messages?
Microsoft documents it as 33% of the 3,600-message receiving limit. About 1,200 is a useful explanation, but applications should not depend on a rounded absolute threshold. Operate well below the service ceiling.
Do SPF, DKIM, or DMARC increase Exchange Online limits?
No. Authentication helps a receiver evaluate identity, but it does not raise recipient, user, message, or tenant counters. Fix authentication when the SMTP evidence identifies it, and fix pacing or architecture when a volume limit is responsible.
Keep going with AI
Ask AI how this applies to you
Take this guide to your assistant — each question opens pre-filled, with a link back to this page so it can read the details.

Written by
Samuel ChenardCEO & Co-Founder, Palisade
Samuel Chenard is the CEO and co-founder of Palisade, AI-first DMARC software for IT teams and MSPs, from one domain to thousands.
More from Samuel →


