Do you try to reconfigure a new Outlook profile on your mobile when connecting from the external?
Based on your description, PC could connect to Exchange successfully with VPN, I think the DNS records are correct. This phenomenon may relate to VPN for mobile.
I would suggest you try to test the ActiveSync configuration from this tool on an external computer which connected with VPN. If could test successfully, it means this phenomenon caused by the mobile device cannot find the correct DNS record.
If this tool returns an error, could you provide that error message to us?
You can also try to configure mailbox on the Mail UWP App (Also using ActiveSync to connect with Exchange) on Win 10/11, I also could help us narrow down this phenomenon.
Another question- do you know that there is tricky configuration instead of using WAP and ADFS for publishing exchange resources? can I publish resources without WAP and ADFS? All devices connect using VPN for any external connections so proxy doesn't make sense. Nothing is opened directly to the internet
ADFS could provide a two-way verification for mailbox, it also could be used when VPN down. Just connecting with VPN without ADFS is also ok.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.