Outlook Certificate Autodiscovery Error

If you use Microsoft Outlook to connect to a hosted or hybrid Exchange mailbox, you may hit a certificate warning during Autodiscover that names a domain you don’t recognise — commonly autodiscover.outlook.com — even though your actual mail domain is different. Why It Happens Outlook’s Autodiscover process tries several lookup methods in sequence, including a […]

Outlook Certificate Autodiscovery Error
If you use Microsoft Outlook to connect to a hosted or hybrid Exchange mailbox, you may hit a certificate warning during Autodiscover that names a domain you don’t recognise — commonly autodiscover.outlook.com — even though your actual mail domain is different.

Why It Happens

Outlook’s Autodiscover process tries several lookup methods in sequence, including a fallback to Microsoft’s own autodiscover.outlook.com endpoint when it can’t cleanly resolve Autodiscover for your own domain. If that fallback succeeds but presents a certificate that doesn’t match your domain, Outlook flags it as a mismatch.

The Fix

  1. Confirm your domain has a proper Autodiscover DNS record: either a CNAME for autodiscover.yourdomain.com pointing to autodiscover.outlook.com (for Microsoft 365/Exchange Online), or the correct internal record if you’re on-premises/hybrid.
  2. If you’re hybrid or on-prem, check the Autodiscover Service Connection Point (SCP) in Active Directory matches your actual Autodiscover URL.
  3. Clear Outlook’s Autodiscover cache by holding Ctrl and right-clicking the Outlook icon in the system tray, then choosing Test E-mail AutoConfiguration to see exactly which URLs Outlook is trying and in what order.
  4. Once DNS/SCP is corrected, restart Outlook so it re-runs Autodiscover against the right endpoint.
If the certificate warning persists after DNS is confirmed correct, it’s worth checking with your email host whether their Autodiscover endpoint’s certificate genuinely covers the domain your DNS is pointing to.

Does This Still Apply With New Outlook? (Updated for 2026)

The multi-step Autodiscover chain described above (root-domain guess, SCP lookup, HTTP redirect, DNS SRV record, then the autodiscover.outlook.com fallback) remains Microsoft’s current documented process for classic (Win32) Outlook connecting to on-premises or hybrid Exchange — nothing has replaced it for that scenario. What has changed is that Exchange Online mailboxes now try a newer JSON-based Autodiscover v2 lookup first, falling back to the classic chain above only if that doesn’t resolve cleanly — so the certificate-mismatch symptom described here is still a real, current issue for hybrid/on-prem setups specifically. Worth knowing if you’re troubleshooting this on newer machines: the rebuilt “new Outlook for Windows” client doesn’t support on-premises or hybrid Exchange connections at all — it only connects to Exchange Online, Outlook.com, or IMAP accounts via Microsoft’s own cloud services, bypassing this entire Autodiscover chain. If a user has switched to new Outlook, this fix doesn’t apply to them.

Resources

securityalert 2
🛠️

Gear We Recommend

Working from home? Here’s the desk tech we’d recommend.

Browse our Home Office Setup picks on Amazon

As an Amazon Associate, TechyGeeksHome earns from qualifying purchases.


Discover more from TechyGeeksHome

Subscribe to get the latest posts sent to your email.

Andrew Armstrong

Andrew Armstrong is a UK-based IT professional with 26+ years of hands-on experience in Windows, Windows Server, SCCM/ConfigMgr, Active Directory, PowerShell, and enterprise infrastructure.

He founded TechyGeeksHome in 2010 and has published over 1,500 practical guides covering real-world IT problems and solutions. When not solving IT problems,

Andrew develops free Windows utilities including Ultimate Settings Panel, which has been downloaded over 850,000 times.