Exchange mail flow guides › Authentication and SMTP errors

Messages over 10 MB are not arriving: size limits between the POP3 connector and Exchange

When large messages go missing between a provider mailbox and Exchange, the limit is almost always one of Exchange’s own message size limits — on the receive connector, in the organization-wide transport settings or on the mailbox — and not the connector. Exchange enforces the most restrictive of these limits. A POP3/IMAP connector such as POPcon has no practical size limit of its own; a message that Exchange refuses because of its size is kept in the connector’s TOOLARGE folder and can be delivered again once the limit has been raised.

Updated on 2026-10-02

The Exchange behaviour on this page is taken from Microsoft Learn, where it is documented for Exchange Server 2016, 2019 and Subscription Edition; the connector side is taken from the POPcon knowledge base, whose articles on this subject were written for Exchange 2007 and 2010, and from our Exchange configuration guides. Where the two give different default values, both are named.

Where Exchange limits the size of a message

Microsoft’s reference is Message size and recipient limits in Exchange Server. It lists limits at four levels — organization, connector, server and mailbox — of which three matter for mail that a connector hands to Exchange over SMTP, plus the limit on the message header:

LimitDefault per Microsoft (2016, 2019, SE)Exchange admin centerExchange Management Shell
Organization: maximum size of a message received10 MBMail flow › Receive connectors › More options › Organization transport settings › Limits › Maximum receive message size (MB)Set-TransportConfig, parameter MaxReceiveSize
Organization: maximum size of a message sent10 MBSame tab, Maximum send message size (MB)Set-TransportConfig, parameter MaxSendSize
Receive connector: maximum size of a message36 MBMail flow › Receive connectors › Edit › General › Maximum receive message size (MB)Set-ReceiveConnector, parameter MaxMessageSize
Receive connector: maximum size of all header fields256 KBNot availableSet-ReceiveConnector, parameter MaxHeaderSize
Recipient: maximum size of a message that can be sent to a mailboxUnlimitedRecipients › Mailboxes › Edit › Mailbox features › Message size restrictions › Received messagesSet-Mailbox, parameter MaxReceiveSize
Mail flow rule: message or attachment sizeNot configuredMail flow › Rules, condition on the message size or on the size of any attachmentSet-TransportRule, parameters MessageSizeOver, AttachmentSizeOver

Two details of the organizational limits are easy to miss, and both concern mail that arrives from outside. First, they apply to anonymous, unauthenticated senders — and that is how a connector delivers: POPcon submits to Exchange over standard unauthenticated SMTP, the same way an internet mail server would. Second, Microsoft states that for inbound messages from external senders Exchange applies the organizational maximum send message size, while the maximum receive size is applied to the internal recipient: “a message size must be within the message size limits for both the sender and the recipient.” Raising only one of the two organizational values can therefore leave the other one in the way.

Where the 10 MB comes from

The number turns up in three places, which is why it is the size at which this problem is usually noticed:

The limit is also reached earlier than its name suggests. Microsoft: “Base64 encoding increases the size of the message by approximately 33%, so the value you specify should be approximately 33% larger than the actual message size you want enforced.” Its example is a limit of 64 MB, which gives a realistic maximum message size of approximately 48 MB. By the same ratio a 10 MB limit is reached by roughly 7.5 MB of attachments.

Which limit wins, and where the message stops

Microsoft’s rule is short: “The order of precedence for message size limits is the most restrictive limit is enforced. The only question is where that limit is enforced.” For mail delivered by a connector that second sentence decides what happens to the message, because there are two places where it can stop and they behave differently:

Where the message is refusedWhat happensWho noticesWhere the message is afterwards
At the receive connector, during the SMTP sessionExchange refuses the message while the connector is handing it over. POPcon moves it to its TOOLARGE subfolder (knowledge base)Nobody, unless somebody looks into the folder or the log: the sender gets no notice, because POPcon cannot generate non-delivery reports itselfAs a .msg file in TOOLARGE, ready to be delivered again
After the receive connector accepted it: organizational limit or mailbox limitExchange has taken the message and then finds it too large. According to the knowledge base, Exchange then sends a non-delivery report to the sender automatically and the TOOLARGE folder is not used (article)The sender, through the non-delivery reportRejected by Exchange; the sender has to send it again after the limit was raised

With the defaults Microsoft lists for 2016 and later — 36 MB on the receive connector, 10 MB for the organization — a message between the two values passes the connector and is refused afterwards. Microsoft describes exactly this arrangement as a waste of resources for a server that receives from the internet (“it’s a waste of system resources for the Internet Receive connector to accept large messages that are eventually rejected because of a lower organizational limit”) and recommends the same limits everywhere or the more restrictive limit where messages enter the organization. Behind a POP3 connector there is a reason to keep it the other way round, described under If the sender should be told below.

The mailbox limit has one more property that causes confusion. Limits between authenticated senders and recipients — typically internal ones — are exempt from the organizational size restrictions, so a mailbox can be allowed larger messages than the organization. “However, this exemption applies only to messages sent between authenticated senders and recipients.” In Microsoft’s example the organizational limit is 10 MB and the marketing department is configured for 50 MB: these users “will be able to exchange large messages with each other, but not with Internet senders and recipients”. Mail from a connector arrives anonymously and falls under the second half of that sentence.

How to raise the limits and deliver the waiting messages

  1. Read the limits that are in force. Microsoft gives one command per level. Organization: Get-TransportConfig | Format-List MaxReceiveSize,MaxSendSize,MaxRecipientEnvelopeLimit. Connectors: Get-ReceiveConnector | Format-Table Name,Max*Size,MaxRecipientsPerMessage. A mailbox: Get-Mailbox <MailboxIdentity> | Format-List MaxReceiveSize,MaxSendSize,RecipientLimits. The lowest value you find is the one that stops the mail.
  2. Choose the new value. Allow for the encoding: about 33 percent above the largest message you want to accept. The configuration guides and the knowledge base use 100 MB (102400 KB) on the receive connector.
  3. Raise the receive connector limit. In the Exchange admin center edit the receive connector that accepts the connector’s sessions and change Maximum receive message size on the General tab; the Exchange 2013 / 2016 configuration guide shows the dialog. In the shell the cmdlet is Set-ReceiveConnector with the parameter MaxMessageSize, for example Set-ReceiveConnector "Default Frontend <ServerName>" -MaxMessageSize 100MB; the knowledge base gives set-receiveconnector "*default*" -maxmessagesize 100MB for Exchange 2007 and 2010, where the limit is on the General tab of the connector under Server Configuration › Hub Transport › Receive Connectors. If several receive connectors exist, make sure you change the one that answers — which receive connector is answering explains how Exchange picks it.
  4. Raise the organizational limits. In the Exchange admin center: Mail flow › Receive connectors › More options › Organization transport settings › Limits. In the shell: Set-TransportConfig with MaxReceiveSize and MaxSendSize. Change both, for the reason given above. On Exchange 2007 and 2010 the setting is under Organization Configuration › Hub Transport › Global Settings › Transport Settings.
  5. Check the mailbox if only one recipient is affected. The default is unlimited; a value that somebody set years ago shows up in the Get-Mailbox command from step 1 and is changed with Set-Mailbox, parameter MaxReceiveSize, or under Message size restrictions in the mailbox properties.
  6. Deliver the waiting messages. Move the .msg files from POPcon’s TOOLARGE folder into the PICKUP subfolder. POPcon picks them up in the next retrieval cycle and attempts delivery again (how to resend them). Messages that were refused after Exchange had accepted them are not in that folder: their senders received a non-delivery report and have to send again.

The knowledge base article Only messages under 10 MB come through has the screenshots of the three places for the older Exchange versions.

If the sender should be told

A message that waits in TOOLARGE is safe, but nobody outside knows that it did not arrive. If you would rather have oversized mail returned to the sender, the knowledge base describes the arrangement (How to have NDRs sent for emails that are too large): POPcon cannot generate non-delivery reports itself, so let Exchange do it. Set the receive connector limit high — the article uses 100 MB — so that the connector does not refuse the message at the wrong level, and set the organizational maximum receive size to the limit you actually want, for example 20 MB (and, following Microsoft’s note above, the maximum send size to the same value). Exchange then accepts the message from the connector, finds it larger than the organizational limit and sends the non-delivery report; the TOOLARGE folder is no longer used.

This is the opposite of Microsoft’s general advice to reject as early as possible, and the difference is the delivery path. When a mail server on the internet delivers directly, an early refusal reaches the sending server, which informs its user. When a connector collects the mail from a provider mailbox, the sending server finished its work long ago; a refusal at the receive connector reaches only the connector. Which of the two you prefer — the message kept in TOOLARGE without notice, or a non-delivery report and no message — is a decision for your organization; the limits let you have either.

Symptoms and the limit behind them

SymptomLimit behind itFix
Large messages never arrive, the sender hears nothing, .msg files collect in TOOLARGEReceive connector, MaxMessageSizeSteps 3 and 6
The sender receives a non-delivery report with status 5.3.4, “Message size exceeds fixed maximum message size”A message size limit; Microsoft notes that this error “can be generated by the source or destination messaging system” (DSNs and NDRs in Exchange Server)Step 1 to find the lowest value, then steps 3 and 4
The sender receives a non-delivery report with status 5.2.3, “RESOLVER.RST.RecipSizeLimit; message too large for this recipient”The recipient’s own limitStep 5
552 5.3.4 Header size exceeds fixed maximum size, message in BADMAILNot the message size but the header size, MaxHeaderSize on the receive connectorKnowledge base article; the row in the table of Exchange SMTP error codes
On Windows SBS 2008 with the built-in POP3 Connector: the message stays in the provider mailbox and an event is loggedThe connector’s 10 MB ruleDownload or delete the message manually or raise the Exchange limit, as the event advises; comparison with a current connector

The reply Exchange gave to the connector is in the log, for POPcon the file POPconSrv.log in the program directory. The complete setup of the receive connector is in How to download POP3 and IMAP mailboxes into Exchange.

Frequently asked questions

Does the POP3 connector itself limit the size of a message?

POPcon does not. Its knowledge base states that POPcon handles messages up to 100 MB and beyond and has no practical size limit of its own; when only messages under 10 MB come through, the restriction comes from Exchange. The SBS 2008 POP3 Connector was different: according to Microsoft it did not attempt to retrieve messages larger than 10 MB at all.

What are the default message size limits in Exchange Server 2016, 2019 and SE?

Microsoft lists 10 MB for the organizational maximum receive size and 10 MB for the organizational maximum send size, 36 MB for a receive connector, 10 MB for a send connector and no limit on a mailbox. The most restrictive limit is the one that is enforced. Our knowledge base and configuration guides, written for Exchange 2007 to 2013, give 10 MB (10240 KB) as the receive connector default, so read the values on your own server before changing anything.

Why is an attachment smaller than the limit still rejected?

Attachments travel Base64 encoded, and Microsoft puts the growth at approximately 33 percent: a limit must be set about 33 percent higher than the real message size you want to allow. Microsoft's example is a 64 MB limit that gives a realistic maximum message size of about 48 MB. By the same ratio a 10 MB limit is reached by roughly 7.5 MB of attachments.

Are the messages in the TOOLARGE folder lost?

No. POPcon moves a message that Exchange refused because of its size into the TOOLARGE subfolder as a .msg file and keeps it there. After the limit in Exchange has been raised, move the files from TOOLARGE into the PICKUP subfolder; POPcon picks them up in the next retrieval cycle and delivers them again.

I raised the limit on one mailbox. Why is large mail from the internet still refused?

Because the organizational limits still apply to it. Microsoft exempts messages between authenticated senders and recipients, typically internal ones, from the organizational size restrictions, so a higher mailbox limit works for internal mail. For messages from anonymous senders, which is how internet mail and mail delivered by a POP3 connector arrive, the organizational limits apply. Raise the organizational values as well.

More in the Exchange mail flow guides, on the POPcon product page, the POPcon download page or in the knowledge base. Auf Deutsch: Nachrichten über 10 MB kommen nicht an.