9 ms·
I remember while trying to figure out why Microsoft was blocking emails that IPv6 SMTP source addresses had a much higher risk of being blocked despite having d
by adevx 5y ago
I remember while trying to figure out why Microsoft was blocking emails that IPv6 SMTP source addresses had a much higher risk of being blocked despite having done all the required stuff like PTR, SPF, DKIM. Microsoft's form to submit delisting an IP address does not even accept an IPv6 address: https://sender.office.com/ https://sender.office.com/
Stuff like this really hinders adoption.
- nousermane 5y agoAnther example of big cloud providers not taking v6 seriously - AWS wouldn't even let your IPv6 hosts talk to their API: $ dig +short a ec2.amazonaws.com 52.46.140.46 $ dig +short aaaa ec2.amazonaws.com (no response)
- usrlocal1023 5y agoThey now have a dual stack EC2 API endpoint. But you have to go out of your way to use as it is on a totally different domain, and also it is limited to few regions. us-east-2 region for example api.ec2.us-east-2.aws https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Using_Endpoints.html#ipv6 https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Using...
- colmmacc 5y agoOur reason for this is that customers may have IP-based rules in their IAM policies. If we silently turned on IPv6 for existing endpoints, those policies would suddenly break without notice. Hence new names and SDK options for dual-stack.
- corty 5y agoSame with GCP, they just announced IPv6 availability for VMs in the last few days. Unbelievably you couldn't even get a IPv6 address for a GCP instance up to now! APIs don't work over IPv6, and lots of other stuff doesn't as well.
- PedroBatista 5y agoMicrosoft + Email has been a combo from Hell for many years, blocking IPv6 addresses, deliverability issues all the time, psychotic Spam detector, complete disregard for the most basic rules on how Email works and the list goes on.
- xroche 5y agoMy first experience with MS Exchange long time ago was that the team responsible for the infrastructure (company with more than 100k employees) committed to reboot the server once a week, because otherwise it would blow up. So yes, this is a long story.
- marcosdumay 5y agoOh, my first contact with Exchange was discovering that the recently updated server couldn't read any of the backups on the proprietary format of the pre-update version of it. It seemed to be a common enough occurrence, because the email people just shrugged and started hacking the backup. I don't think that group was ever capable of restoring any Exchange backup, normally because of Exchange's problems. But that was a long time ago. From what I hear, things are different now.
- jcpham2 5y agoSounds like unchecked IIS SMTP transport logs but hey it's been years since I maintained an on-premises Exchange server
- kureikain 5y agoAnd icloud too. They are very sensitive to ipv6. In case of icloud, I attribute it to the Proofpoint spam filtering system, which also sell service to ups.com. And even gmail, but at least gmail accept the email, then just flagged it as spam.
- zahllos 5y agoYes, I remember seeing this as well. The irony here is that much of the inter-service traffic on the internet could already be sent over IPv6 without anyone noticing. Getting end users onto IPv6 is always going to be a challenge as, well, ISPs, but when my mail server talks to your mail server there's no need for this to be IPv4.
- fomine3 5y agoAlso it can be said that connection between mail servers can be IPv4 even if IPv6 is mostly used in the world. It seems that there are pros to keep IPv4 reputation from GP, so possibly it happens.
- 55555 5y agoIPv6s are too cheap for most mailbox providers to take seriously. If someone sends spam, you need to block their IP, but they also need to lose money. Spammers don't care if they lose an IPv6. They'll just send spam from another. (I don't really know what I'm talking about.)
- thayne 5y agoThat's where DKIM and SPF come in.
- ikiris 5y agoNot really. If you look at the numbers, spam almost always has these.
- corty 5y agoYes really. With DKIM, you blacklist domains, not IPs. Of course, only if you do it properly. Hotmail doesn't...
- Avamander 5y agoYou're pretending that domains aren't a cheap disposable commodity, they are.
- ATsch 5y agoThat's to be expected. All it does is ensure the accuracy of the email sender. Which finally lets you attach reputation to domains instead of addresses.
- ikiris 5y agoNo, I mean its to the point that mail with this signature is almost always (multiple 9s) spam.
- thayne 5y ago
- kmeisthax 5y agoI wouldn't be surprised if that's intentional. There's an explicit hesitance on the part of mail providers to accept v6 mail, since they use IP addresses as a reputation mechanism. IPs that originate spam mail get summarily executed, and getting new IPs that have a high antispam reputation is actually quite expensive. In other words, it's a Sybil-resistance mechanism, called Proof-of-IPv4. It works specifically because v4 addresses are scarce. v6 addresses are not nearly as such. Everything that makes IPv6 great for the Internet at large makes it terrible for mail providers. For example, because the original v6 design wanted to eat lower link layers, it reserves half the v6 address for an embedded MAC64. This never really panned out, but it's terrible for security, so every v6-capable OS nowadays will rotate addresses every few hours. The average machine will have hundreds of addresses. How do you assign a usable notion of per-IP reputation to that? You could use v6 subnets for reputation, but there's still 64 subnet bits - enough to stick an entire IPv4 subnetwork inside of each IPv4 address. Some ISPs actually will assign a /64 per customer (because Comcast needs something to sell to Business customers), while others assign /56s or /48s. So there isn't even one granularity of subnetting that you can use for reputation tracking on v6. Meanwhile, v4 pricing is getting worse and worse, which is great for mail providers. They don't necessarily need to turn a profit on incoming mail, but they do need to make it expensive for people who want to send lots of spam.
- adevx 5y agoThis could likely be the reason for poor IPv6 support but highlights the importance of shifting (much more) to domain based reputation. If a domains reputation is at risk, you can bet domain holders will be extremely careful not to allow outgoing spam.
- syshum 5y agoOr more strict enforcement by the world on SPF, DMARC and DKIM policies The problem of spam is actually solved, the problem is no one setups any of these security parameters correct, large and small companies alike all have bad SPF Records, bad or no DMARC, etc etc etc
- 5y ago
- Dunedan 5y agoNot that this matters much, as the chance to get an IP address delisted is pretty slim anyway. I've completely given up to try to get my personal mail server delisted, as I can't even get Microsoft to tell me why they blacklisted it in the first place. Instead I'm nowadays just rejecting all incoming emails originating from Microsoft with a message telling the sender to use another non-Microsoft email account. It's just stupid. I never had problems with any other mail provider, but trouble with Microsoft as long as I can think of.
- z3t4 5y agoI think they only block /16 or maybe /24 blocks... Meaning they block entire ISP networks... What I do is to simply sign up to many cheap VPS until I get an IP that is not blocked... Then relay all e-mails via that server. I guess spammers have the same tactic, but it does work.
- dndx 5y agoSame with Google's Report IP problems form, if you tries to put an IPv6 address it will always return: "Invalid IP address" and wouldn't let you submit the form. Link: https://support.google.com/websearch/workflow/9308722?hl=en https://support.google.com/websearch/workflow/9308722?hl=en
- dathinab 5y agoMicrosoft has been ab-using IPv4 in context of Mail to target-specific hinder competition, so they have a lot of reasons to not support IPv6 well where this isn't as much doable. (For example Microsoft has blocked whole IPv4 ranges of cloud providers (i.e. Microsoft Azure competition) for E-Mail, supposedly because of abuse. But all cloud providers are used by people "producing bad mails" and somehow only small to mid-sized ones are blacklisted while e.g. Google or Amazon are not and to be clear that had not been cloud providers in some arbitrary small country but e.g. the EU).
- gowthamgts12 5y agoexactly, we're operating a fleet of SMTP servers and IPv4 procurement is big problem. We do by asking AWS to allocate a block and send email traffic via those IPs. We want to adopt IPv6 but the current email infrastructure doesn't support this.
- Lex-2008 5y agoBut how can you possibly deliver email via IPv6 if their MX host doesn't have IPv6 address at all? $ host hotmail.com hotmail.com has address 204.79.197.212 hotmail.com mail is handled by 2 hotmail-com.olc.protection.outlook.com. $ host hotmail-com.olc.protection.outlook.com. hotmail-com.olc.protection.outlook.com has address 104.47.57.161 hotmail-com.olc.protection.outlook.com has address 104.47.58.161 On the other side, if a host announces that they have an IPv6 address - do you think they do it mostly for spamers? $ host gmail.com | grep handled | head -n1 gmail.com mail is handled by 5 gmail-smtp-in.l.google.com. $ host gmail-smtp-in.l.google.com. gmail-smtp-in.l.google.com has address 173.194.73.27 gmail-smtp-in.l.google.com has IPv6 address 2a00:1450:4010:c1c::1a