How to clean up this mess related to The domain part of the primary mail address is not in list of configured mail domains"

wanted to join an updated server into a MS AD
some ueers threw this error on sync:

univention.admin.uexceptions.valueError: The domain part of the primary mail address is not in list of configured mail domains

and yes i know about this :

ucr set directory/manager/web/modules/users/user/properties/mailPrimaryAddress/syntax=string

but how do i clean up the users that are currently throwing this error.
I saw this answer in German for the S4 connector:

BUT!!!, this was just a normal join so there is no s4
only
connector-ad-status
so even in a simple join of a UCS system to the AD , it is a problem.

Mastodon