
This is a representative scenario, not a specific client. It's a composite of the kind of email-outage call we handle regularly, written to show how we actually think through the problem. Every real situation differs in the details.
It's 9:40 on a Tuesday. A Perth law firm calls: nobody's email is working. Not one person can send or receive — desktop Outlook, phones, the lot. For a firm that bills by the hour and lives in its inbox, this isn't an IT annoyance; it's the whole practice unable to correspond with clients, courts and each other, with the meter running.
Here's how we work a call like that — the order we go in, why, and what we usually find.
First: define the blast radius (2 minutes)
Before touching anything, we establish how big the problem is, because it points straight at the cause:
One person, or everyone? One user is usually an account, licence or device issue. Everyone points at something central — the tenant, licensing, DNS or Microsoft itself.
Sending, receiving, or both? Both directions down for everyone is a different animal to "external senders get bounces."
All devices or just desktop? If Outlook on the web works but desktop doesn't, the mailboxes are fine and it's a client-side sync problem — which also gives us an instant stopgap.
In our scenario, it's everyone, both directions, every device. That narrows things fast.
Second: rule out the things you can't control
We check Microsoft 365 Service Health first — occasionally the answer is genuinely "Microsoft is having an incident," and the honest, useful thing is to tell the client that and monitor, rather than pretend to fix it. No active incident here.
Next, the two boring causes that take down everyone's email at once and get missed most often:
Billing and licensing. A declined renewal — often just an expired payment card on the tenant — deactivates licences and cuts off email for the whole firm. It looks like a catastrophic outage; it's a lapsed card. We've written up a real Perth example: an expired card that took a Victoria Park law firm's email offline for a morning.
Domain and DNS. A lapsed domain registration or a changed MX / DNS record stops mail flow cold. We confirm the domain is current and the mail-routing records point where they should.
Third: work down the mail-flow path
If billing and DNS are clean, we follow the path an email actually takes:
Authentication: can people sign in at all? A Conditional Access or MFA misconfiguration, or a tenant-wide sign-in block, can lock everyone out of email while the mailboxes themselves are perfectly healthy.
Mail flow rules & connectors: a transport rule or connector — sometimes one a well-meaning person added last week — can quietly quarantine or misroute everything.
Spam / spoofing filters: if the symptom is "our mail is bouncing or landing in junk," we look at SPF, DKIM and DMARC, which drift out of alignment surprisingly often.
Mailbox / client state: finally, if the mailboxes are fine but desktop Outlook won't play, it's a client-side re-sync — irritating, but not data loss.
We don't guess our way through this — we go in this order every time, because it moves from "affects everyone" causes to "affects one person" causes, which is the fastest route to the answer.
Getting people working again — usually within the hour
Diagnosis and restoration run in parallel. The moment we've confirmed mailboxes are intact (even if desktop Outlook is sulking), we move everyone onto Outlook on the web in Chrome or Edge so they're back in their inboxes immediately — often within minutes — while we fix the underlying cause and let the desktop clients rebuild.
That's the difference between "the firm lost ten minutes" and "the firm lost a morning." Whatever the root cause — a re-activated licence, a corrected DNS record, a removed rogue rule — the goal is the same: people working again first, tidy fix second.
What this really tells you
Notice what almost every version of this call has in common: the cause was avoidable and visible in advance. An expiring card, a domain coming up for renewal, a licence about to lapse, a filter drifting out of alignment — none of these are lightning strikes. They're things a system watching the tenant flags and sorts before they ever interrupt the business.
That's the entire argument for proactive managed IT over calling someone once it's already broken. When we manage a firm's Microsoft 365, renewals and payment methods are monitored, DNS and mail-flow health are checked, and backups of email are tested and in place — so the 9:40 Tuesday call mostly stops happening. And for law firms specifically, where confidentiality and deadlines are everything, that reliability is the point, which is why we built a dedicated approach for Perth legal practices.
If your firm's email has ever gone dark and you'd rather it didn't happen again, talk to the Computer Mechanics team or call (08) 9325 1196. We've kept Perth businesses' email running since 1997.



