Outlook Cannot Connect to Proxy Server Error Code 20: Causes and Fixes
When Outlook shows “Outlook cannot connect to the proxy server (error code 20),” the problem is usually related to certificate validation while Outlook is connecting to Exchange through HTTPS or an older RPC-over-HTTPS configuration. It is not normally an ordinary Outlook password error.
The most important clue is the wording that often appears with the code: “There is a problem with the proxy server’s security certificate.” The certificate may be expired, revoked, issued by an untrusted authority, or registered for a name that does not match the server Outlook is contacting. Microsoft also lists third-party add-ins and browser components as possible causes.
What Error Code 20 Means
Outlook uses secure connections to communicate with Microsoft 365 or an Exchange server. In older Outlook and Exchange environments, this may involve RPC over HTTPS; newer Exchange connectivity commonly uses MAPI over HTTP. In either case, Outlook must be able to validate the server or proxy certificate before it trusts the connection. For other Outlook connection and send/receive problems, see our guide to Outlook send/receive errors.
Error code 20 is best treated as a certificate or secure-connection symptom, not as proof that the proxy address itself is wrong. If Outlook is generally unable to establish a server connection, see our guide on Outlook cannot connect to the server.
The number can be accompanied by different certificate details, so the complete message matters. Microsoft’s documentation explains that certificate-related error values can represent conditions such as an invalid certificate, an untrusted certificate authority, a name mismatch, an expired certificate, or a revoked certificate.
Common Causes
The error usually comes from one of these conditions:
- The certificate has expired.
- The certificate has been revoked or is otherwise invalid.
- The certificate name does not match the proxy or Exchange server name.
- The certificate authority is not trusted on the computer.
- Outlook is connecting through an outdated or incorrect proxy configuration.
- A corporate proxy, firewall, load balancer, or TLS-inspection device is presenting its own certificate.
- The computer’s date, time, or time zone is incorrect.
- A third-party Outlook or browser add-in interferes with the connection.
- The Exchange server, Autodiscover configuration, or external URL is incorrect.
- The Outlook profile or Office installation is damaged.
Microsoft identifies certificate trust, certificate validity, certificate-name matching, and third-party add-ins as primary causes of this class of Outlook connection error.
Before You Change Settings
First determine whether this is a local Outlook problem or an Exchange/server problem.
- Can you sign in to Outlook on the web using the same account?
- Do other employees receive the same error?
- Does Outlook work on a phone or another computer?
- Did the issue begin after a password change, network change, certificate renewal, Office update, or server migration?
- Does the message name a specific proxy or server?
If Outlook on the web and mobile access work but classic Outlook fails on one computer, investigate the local certificate store, proxy path, add-ins, profile, or Office installation. If many users fail at the same time, involve the Microsoft 365 or Exchange administrator before changing individual Outlook profiles.
Fix 1: Check Date, Time, and Time Zone
An incorrect system clock can make a valid certificate appear expired or not yet valid.
- Right-click the clock on the Windows taskbar.
- Select Adjust date and time.
- Turn on Set time automatically.
- Select the correct Time zone.
- Select Sync now, if available.
- Close and reopen Outlook.
On a company computer, the time may be controlled by domain policy. If it changes back after synchronization, contact IT rather than repeatedly changing it manually.
Fix 2: Inspect the Certificate
Do not bypass the certificate warning simply to make Outlook connect. First identify what is wrong with the certificate.
If the error displays a server name or provides a certificate-view option, inspect these fields:
- Issued to or Subject: should match the server name Outlook is using.
- Valid from and Valid to: should include the current date.
- Issuer: should be a trusted certification authority.
- Certificate chain: should not contain an untrusted or missing root/intermediate certificate.
- Revocation status: should not indicate that the certificate has been revoked.
Microsoft specifically recommends examining the certificate’s validity period and Subject name when Outlook reports a proxy certificate problem.
If the certificate name does not match the name Outlook uses, the correct fix is normally on the Exchange, proxy, load balancer, or DNS side. Ask the administrator to verify the external Exchange and Autodiscover names and the certificate assigned to the relevant service.
Fix 3: Verify the Correct Server Name
A certificate can be valid and still fail if Outlook connects to a different name than the certificate covers. For example, a certificate issued to mail.example.com may not validate if Outlook is directed to exchange.example.net unless the latter name is also included in the certificate’s subject alternative names.
Do not replace the server name with a guessed address. Ask your email administrator or provider for the official Exchange server and Autodiscover settings. Microsoft’s account-settings guidance recommends obtaining the Exchange server name from the organization that supplied the email account.
For an on-premises Exchange environment, the administrator should verify:
- The external URL used by Outlook.
- Autodiscover DNS and service configuration.
- The certificate subject and subject alternative names.
- The certificate assigned to IIS and relevant Exchange services.
- The proxy or load balancer’s certificate.
- Whether internal and external names resolve to the intended servers.
Fix 4: Check Windows Proxy Settings
A stale or incorrect Windows proxy can route Outlook through a server that is unavailable or presents the wrong certificate.
- Open Settings.
- Select Network & internet.
- Open Proxy.
- Review Automatically detect settings, Use setup script, and Use a proxy server.
- Keep only the configuration supplied by your organization or internet provider.
Do not delete a company proxy configuration without checking with IT. Corporate environments may require the proxy for authentication, filtering, or access to internal resources.
For classic Outlook connected to an on-premises Exchange account, proxy-related Exchange settings may also appear under File > Account Settings > Account Settings, then the account’s connection or advanced settings. The exact screen depends on the Outlook version and account type. Microsoft recommends obtaining server settings from the organization or email provider rather than guessing them.
Fix 5: Test Outlook in Safe Mode
A third-party add-in can interfere with Outlook’s connection process. Microsoft recommends starting Outlook in safe mode to isolate add-in problems.
- Close Outlook.
- Press Windows + R.
- Type outlook.exe /safe.
- Press Enter.
- Select the profile if Outlook asks you to do so.
If Outlook connects normally in safe mode, disable add-ins:
- Open Outlook normally.
- Go to File > Options > Add-ins.
- At the bottom, set Manage to COM Add-ins.
- Select Go.
- Clear third-party add-ins.
- Restart Outlook normally.
- Re-enable add-ins one at a time to identify the conflict.
Do not remove an add-in unless you know that it is unnecessary. Updating the add-in may resolve the issue.
Fix 6: Check Antivirus and TLS Inspection
Some security products inspect encrypted HTTPS traffic. In a business network, a proxy or firewall may decrypt Outlook traffic and present a company-issued certificate to the computer.
If that certificate authority is not trusted, Outlook may report a proxy certificate error. If the certificate is trusted but has the wrong name or has expired, the security appliance may still cause the failure.
Ask your IT administrator whether the network uses:
- HTTPS or TLS inspection.
- A secure web gateway.
- An authenticated proxy.
- A firewall performing certificate replacement.
- A load balancer in front of Exchange.
Do not permanently disable antivirus or TLS inspection as a first fix. Security software may protect sensitive email traffic, and disabling it can create a larger risk. The correct solution is to update the appliance certificate, install the organization’s approved root certificate, or configure the inspection policy correctly.
Fix 7: Install a Trusted Root Certificate Only When Appropriate
If the message says the certificate is not from a trusted certification authority, the computer may be missing a required root or intermediate certificate. Microsoft documents installing the trusted root certificate when that is the identified cause.
Only install a certificate supplied by your organization’s IT team, Microsoft, your email provider, or another verifiable administrator. Do not download a root certificate from a random website.
A root certificate should not be installed merely to suppress an Outlook warning. If the certificate is expired, has a wrong name, or is presented by an unknown device, adding trust will not correct the underlying configuration and could weaken security.
Fix 8: Update Windows and Microsoft 365
Out-of-date Windows, Office, or Outlook components can contribute to connection and authentication problems. Microsoft recommends running Windows Update when troubleshooting Microsoft 365 Outlook connection issues.
- Open Settings > Windows Update.
- Select Check for updates.
- Install available updates.
- Restart Windows.
- Open an Office application such as Word.
- Go to File > Account > Update Options > Update Now, if available.
- Restart Outlook and test again.
If your organization manages Office updates, allow the administrator’s update process to complete.
Fix 9: Repair Microsoft 365 or Office
If the certificate and network are correct but Outlook still fails on one computer, repair the Office installation.
- Open Settings > Apps > Installed apps.
- Find Microsoft 365 or Microsoft Office.
- Select the menu next to it.
- Choose Modify.
- Try Quick Repair first.
- If the issue continues, use Online Repair if your organization permits it.
- Restart Windows and test Outlook.
Online Repair may reinstall Office components and can take longer. Save work and confirm that you have the required account or installation information before starting it.
Fix 10: Create a New Outlook Profile
A damaged profile can preserve incorrect Exchange or Autodiscover information. Creating a new profile can show whether the problem is limited to the current profile.
- Close Outlook.
- Open Control Panel.
- Search for Mail.
- Open Mail (Microsoft Outlook).
- Select Show Profiles.
- Select Add.
- Enter a profile name.
- Add the account using the organization’s approved sign-in method.
- Select Prompt for a profile to be used or make the new profile the default.
- Open Outlook and test the connection.
Do not delete the old profile immediately. Keep it until the new profile works and you have confirmed that locally stored data is available. Exchange and Microsoft 365 mailboxes usually synchronize from the server, but local archives, PST files, signatures, and custom settings may need separate handling.
Fix 11: Rebuild the Outlook Cache Carefully
For Exchange accounts, Outlook commonly uses an OST cache. If the cache is damaged, creating a new profile often rebuilds it more safely than deleting files manually.
Do not delete an Outlook data file before confirming whether it is an OST, PST, or local archive. A PST may contain the only copy of older mail, contacts, or calendar items.
If an administrator confirms that the OST can be rebuilt:
- Close Outlook.
- Back up important local data.
- Create a new Outlook profile or follow your organization’s approved cache-rebuild procedure.
- Reopen Outlook and allow synchronization to complete.
Fix 12: Run Microsoft’s Diagnostic Tools
For Microsoft 365 connection problems, Microsoft provides diagnostic tools that can test Outlook connectivity and profile-related issues. Its guidance specifically recommends Outlook User Connectivity diagnostics and checking Exchange Online service health when multiple people are affected.
Use the diagnostic tool available to your account or ask your Microsoft 365 administrator to run it. Some diagnostics require administrator access and may not be available for every Microsoft 365 environment.
If several users are affected, the administrator should also check the Microsoft 365 service health dashboard and Exchange Online status before changing individual computers.
When the Administrator Must Fix It
Some causes cannot be repaired safely from the Outlook client. Contact your email administrator when:
- The certificate is expired, revoked, or issued for the wrong name.
- The certificate authority is not trusted across multiple computers.
- Several users receive the same error.
- Outlook on the web and mobile access also fail.
- The problem began after an Exchange migration or certificate renewal.
- The proxy, load balancer, firewall, or TLS inspection device is involved.
- Autodiscover or Exchange external URLs are incorrect.
- Your organization controls Outlook settings through Group Policy.
Give IT the complete error text, the number shown, the server or proxy name, the time the issue began, your Outlook version, and whether other devices can connect.
What Not to Do
Avoid these common but unsafe responses:
- Do not accept an invalid certificate permanently.
- Do not install an unknown root certificate.
- Do not guess the Exchange server or proxy address.
- Do not permanently disable Windows Firewall or antivirus protection.
- Do not delete PST files while troubleshooting.
- Do not change authentication settings supplied by your organization without approval.
- Do not reinstall Outlook before checking the certificate and server configuration.
A certificate warning is a security signal. The goal is to correct the trust relationship, not simply make the warning disappear.
Frequently Asked Questions
What does “Outlook cannot connect to the proxy server error code 20” mean?
It generally indicates that Outlook cannot validate the security certificate presented during its connection to Exchange or a proxy. The certificate may be expired, revoked, untrusted, or issued for a name that does not match the server.
Is Outlook error code 20 caused by a bad password?
Usually not. A password or authentication problem can prevent sign-in, but this specific wording points more strongly to certificate, proxy, server, or connection-path problems.
Can an incorrect Windows date cause error code 20?
Yes. An incorrect date or time can make a valid certificate appear expired or not yet valid. Synchronize the computer clock before changing Outlook settings.
Should I turn off antivirus to fix the error?
Do not permanently disable antivirus or TLS inspection. If security software is suspected, test only under approved procedures and ask IT to correct its Outlook or certificate-inspection configuration.
Why does Outlook work on my phone but not my computer?
The phone may use a different connection method and certificate path. If only the computer fails, inspect its clock, trusted certificates, proxy settings, add-ins, Office installation, and Outlook profile.
Can reinstalling Outlook fix error code 20?
It can help if the Office installation is damaged, but reinstalling Outlook does not repair an expired server certificate, a wrong proxy configuration, or an Exchange-side problem. Check the certificate and server first.
Does this error affect Outlook.com accounts?
The exact message is more commonly associated with classic Outlook connecting to Exchange or Microsoft 365 through a proxy or secure HTTP path. Outlook.com web access uses a different connection path, so identify the Outlook version and account type before applying Exchange-specific steps.
What information should I give IT support?
Provide the complete error message, error number, named proxy or server, Outlook version, Windows version, time the problem began, whether Outlook on the web works, and whether other users or devices are affected.
Conclusion
“Outlook cannot connect to the proxy server (error code 20)” usually points to a certificate-validation or secure-connection problem rather than a simple password failure. Start with the computer’s date and time, then inspect the certificate name, validity, issuer, proxy path, add-ins, Office updates, and Outlook profile.
If the certificate is wrong, expired, untrusted, or presented by a corporate proxy, the administrator must correct the Exchange, proxy, firewall, load balancer, DNS, or certificate configuration. Do not bypass the warning or install an unverified root certificate just to restore connectivity.
Disclaimer: Primotechy is an independent website and is not affiliated with or endorsed by Microsoft Corporation.