8 ms·
Outlook.com is silently discarding email messages (2015)
- stingraycharles 4y agoThis is fairly normal in today’s world of email providers, and one of the reasons it can be painful to manage your own SMTP server, right? Mail delivery is an anarchy and I’m impressed the problem of spam has been solved to the degree we currently see. Yes it’s much more centralized than before, and no that isn’t a good thing, but from a customer’s experience point of view, I couldn’t go back to the old days of manually training your email client’s spam filter and whatnot.
- Avamander 4y ago> This is fairly normal in today’s world of email providers Certainly not normal, but done sometimes, yes. > and one of the reasons it can be painful to manage your own SMTP server, right? It's part of the job, but it's more likely that the big providers are the least of your problems. They can be reached and you're usually not alone with your problems. It's the small providers who have terrible filtering, who use low-quality shit-lists like UCEProtect/Backscatter or their own "heuristics", that are the most painful.
- porbelm 4y agoWell I've gotten blocked from being delivered Outlook-hosted mail because my primary MX is on a Linode block that at times get listed with UCEProtect (level 3 even!!!) Why can't the big ones just check SPF and DKIM etc and let us responsible self-hosters do our thing
- Avamander 4y ago> Well I've gotten blocked from being delivered Outlook-hosted mail because my primary MX is on a Linode block that at times get listed with UCEProtect (level 3 even!!!) I really don't think Microsoft would ever touch that pile of shit, most likely your spammy neighbour got your neighbourhood blacklisted at both places simultaneously. > Why can't the big ones just check SPF and DKIM etc and let us responsible self-hosters do our thing Most of the spammers have valid SPF and DKIM. Quite a few have entire subnets of IP addresses to spew spam from. That's why a random IP and just those two aren't sufficient to just start blasting.
- mrb 4y ago«Most of the spammers have valid SPF and DKIM» What porbelm means is that when SPF and DKIM are valid, reputation check should be based on the sending domain, not on the sending IP. This way spammers still get thwarted (because of their domains with zero or low reputation) and legit senders can send from any IP (since their domain CAN build good reputation) Besides, it's also easier to track reputation of ~360M domains than billion of IPv6 and IPv4 ranges.
- rlpb 4y agoThat's great in theory. Unfortunately many legitimate sending domains are newly registered, so have no reputation. It's not possible to rely on age either: if requiring domains to be aged becomes commonplace, they're cheap enough that spammers would just register them and wait for a bit, maintaining a pipeline of them. So it becomes necessary to consider the reputation of whoever is enabling the sending of the email. The only way to do that is by IP. If a domain uses DKIM, has a good reputation but comes from a bad IP, then sure, you might trust it. I don't think that'll help much in practice though.
- mrb 4y agoEverything you said applies to IP-reputation as well. There is nothing that makes domain-reputation inherently harder than IP-reputation. Consider this: every legit IP address once started with the problem of having zero reputation. How you build reputation from zero is simple: you start by being allowed to send only small amount of daily emails (rest goes to spam or is outright rejected by the recipient SMTP server). Then adjust reputation based on the usual factors (observe human recipients flagging emails as spam/not spam, watch for keywords like Viagra, etc, all the exact same stuff email providers already do). You gain or loose reputation over time, which affects how much you can send: a lot, or nothing.
- rlpb 4y agoSome hosting providers have a very negative IP reputation. They seem to be unable to stop their users from sending out spam. They don't seem to react to abuse reports, let alone take action to stop abuse from their ASN generally. So I block their entire netblocks, IP-wise. I'm not aware of any legitimate emails being caught up in this. If somebody is unfortunately caught up, my response is that they should use a more reputable provider. According to your previous post, I shouldn't do that for DKIM/SPF -valid emails by IP, but I do. I hope this explains I do, and why purely domain-based reputation doesn't work.
- soneil 4y ago> Why can't the big ones just check SPF and DKIM etc and let us responsible self-hosters do our thing I self-host and frequently block entire ISPs. It's very common to get the same mail for days on end from a different IP, and often a different domain each time. Some months DO accounts for over 50% of my spam, for example. I'm sure there's more graceful ways to handle it if I was willing to put far too much of my own time into fighting a losing battle. but adding a REJECT line for a whole netblock takes seconds. I don't begrudge the big hosts for treating whole ISPs as cesspits as I do the very same thing.
- Ygg2 4y agoIt's solved? From what I see, it's just a few players exchanging mail between themselves and discarding a high percentage of traffic.
- vedranm 4y ago> This is fairly normal in today’s world of email providers, and one of the reasons it can be painful to manage your own SMTP server, right? Yes. Silently discarded e-mail is the worst thing that can happen because you can't detected it as a sender. Your message reaching the spam folder is bad, but not as bad as getting silently discarded. The best among the bad options is probably getting rejected with the SMTP return code 550 along with instructions how to delist in the return message.
- jeff_carr 4y agoIf you are running a business and have customers having emails that are silently being dropped, adding a "verify your email address" page in your process is probably a good step to have anyway.
- vedranm 4y agoWhy exactly? Would Microsoft's internal spam filter likely consider that spammers often don't provide that page so you would stand out?
- pjc50 4y agoIf they're consistently dropping mail, the user stays unverified. But a verification page is practically mandatory anyway for all sorts of reasons, not least checking the user hasn't mistyped their email.
- 55555 4y agoIf you’re being silently discarded you likely have terrible reputation, and requiring verification will help to fix that.
- cube00 4y agoIt's increasing becoming the case that "terrible reputation" now includes the low reputation self hosters who don't have enough volume to even use the tools Google and Microsoft offer. Google's Postmaster tools all show "No data to display at this time. Please come back later. Postmaster Tools requires that your domain satisfies certain conditions before data is visible for this chart." Microsoft's Safe Network Data Service shows *"No data for specified IPs on this date" for every day.
- samwillis 4y agoWe, an online store, have found deliverability to yahoo.com and btinternet.com addresses by far the worst, I don’t have statistics to hand but it’s up to a 10% failure rate. Much like the OP it seems to be silent too. We have literally no issues with other providers. The unfortunate thing is that we also find the demographic of customers here in the UK still using btinternet.com email closely aligns with customers who tend to be more problematic… (My parents have a btinternet.com email address)
- gandalfian 4y agoIt doesn't help with BT that you often have to figure out how to log into the webmail interface (often outlook/Hotmail) and only then do you seen the spam folder. If you don't do this and currate the spam folder it all get steadily worse... And you never see why if you are using an email program set up years ago on your PC.
- samwillis 4y ago> if you are using an email program set up years ago on your PC. Yes, the demographic of a btinternet email user.
- iam-TJ 4y agoIf I recall correctly didn't Yahoo used to provide the BTinternet.com email service? I seem to remember some announcements about BT eventually moving off it but not sure if the backend MTAs changed. https://home.bt.com/pages/email/index2.html https://home.bt.com/pages/email/index2.html
- connordoner 4y agoThey did indeed! I'm not sure on the infrastructure, but I'd love to know if it was run within Yahoo's data centres and white-labelled, or run in BT data centres using Yahoo Mail's application.
- rlpb 4y ago> The unfortunate thing is that we also find the demographic of customers here in the UK still using btinternet.com email closely aligns with customers who tend to be more problematic… Maybe this is just wishful thinking, but if the more problematic customers are losing you money, then isn't it a valid business case to stop doing business with them given that you can identify them in advance? Wishful thinking because it'd be really nice to create a feedback loop such that users of email providers start to understand their reputation, which would make provider reputation for deliverability matter, which might improve their behaviour. But most businesses probably aren't in a position to turn away business like that.
- ferran_r 4y agoI had same problem with deliverability of emails to Hotmail accounts a few years ago, they blocked AWS SNS IP email servers so sometimes were received but most of them directly sent to SPAM or never received. We complained Microsoft and their solution was to use one of their cloud email service or partner because the "black magic" of their AI filter. This is a shame
- cube00 4y agoMy favourite response from their so called "support" was to claim nothing was being blocked. They weren't going to let the full headers and error message from their outlook.com server convince them otherwise. Thankfully two days later it magically unblocked again. All the time enrolled in their "Smart Network Data Service" which did nothing. I probably just got an auto reply from the same bot Google uses to handle ban appeals.
- JacobSeated 4y agoIn the end it is Microsoft's problem, since they are the ones that are losing valid SMTP traffic. If a sufficient amount of users are experiencing a loss of e-mail as a result, then they will be forced to fix it. There is almost never any valid reason to block an entire ip address. Single user accounts (e-mail addresses), maybe, if compromised. E-mail, as a standard, is still pretty straight forward. Ideally you should be able to send e-mail directly from your laptop IP, if approved to send e-mail on behalf of your e-mail account / host name. Decentralization is important.
- Avamander 4y ago> There is almost never any valid reason to block an entire ip address. Single user accounts (e-mail addresses), maybe, if compromised. I'm sorry but that's just very naive.
- InCityDreams 4y ago>I'm sorry but that's just very naive. It would be fair(er) to explain why.
- Avamander 4y agoThe statement is just really quite absolute. The most trivial example would be an IP address being used by an abuser behind bulletproof hosting. Someone trying to deliver 200 000 spam letters in a minute and you rejecting each one is a significant amount of load - best case it still reduces your logs' SNR.
- int0x2e 4y agoThe issue is that domains are cheap and plentiful, and a spammer can easily claim to be sending mailflow on behalf of let's say, 1000 users, each sending 5-10 emails a day, and thus, a single IP "forwarding" (sending) mailflow "on behalf" of 10k domains, with 1k users each, with each user sending just 10 emails a day - would result in a pretty nice batch of spam making it through. As things currently stand, the only "expensive" resource that is hard to acquire or fake somehow is source IPs with good reputation. Fair? I'm not saying it is. It's just effective.
- srvmshr 4y agoI have another strange issue. The document attachments which come along with incoming email are still listed in "Documents" tab in Outlook even after they have been purged from secondary trash. The documents themselves aren't available (cannot be opened) but a list of all documents which have ever arrived (including JPGs/PNGs in signaturss) are still visible in that tab. I flagged this issue once but no resolution yet
- andix 4y agoI really don’t care anymore if my email reaches Outlook or Hotmail addresses. It’s impossible to make sure. And to some extent it’s also the users problem. With Office 365 I have far less issues. So Microsoft can do it, if they want to.
- vedranm 4y agoAre you sure that the infrastructure behind Outlook and Office 365's Outlook is sufficiently different? I was under the impression that it's similar if not the same. Compare Outlook: $ dig mx outlook.com ;; ANSWER SECTION: outlook.com. 300 IN MX 5 outlook-com.olc.protection.outlook.com. with my university that is a customer of Outlook on Office 365: $ dig mx uniri.hr ;; ANSWER SECTION: uniri.hr. 86251 IN MX 0 uniri-hr.mail.protection.outlook.com.
- andix 4y agoEven if the infrastructure is very similar, it can be set up with completely different configurations. The free version has probably a lot of features turned off.
- zinekeller 4y agoYou're not wrong, but Microsoft's Exchange 365 does have a lot of knobs to control (https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/exchange-online-protection-overview https://docs.microsoft.com/en-us/microsoft-365/security/offi...) and the defaults are more relaxed, probably as concession to those migrating from on-premise solutions. I'm guessing that they turn the knobs into the most aggressive position for their personal services.
- cube00 4y agoEven Microsoft understands what it means for their business if a paying customer with access to legal representation such as a lawyer or a medical professional randomly started losing correspondence. If it was proven in court that they were silently discarding correspondence of paying customers because they were over confident in their spam filtering, everyone would jump ship in a heartbeat. Mail is a very resilient protocol, this isn't UDP, this is the result of a deliberate decision being taken.
- thedougd 4y agoBarracuda ESS appears to block everything from Amazon SES even with valid DKIM and SPF. Of course they can’t be bothered with DMARC reports. This really sucks for users trying to receive Cognito password reset emails.
- soneil 4y agoI block SES too. I couldn't find a reasonable way to report abuse, and the system does nothing to enforce opt-outs/unsubscribe. It's an absolutely horrible service to be on the receiving end of.
- thedougd 4y agoIt handles standard complaints or bounces while adding to global or account supression lists. If an account exceeds a complaint ratio, it is suspended. What are you aiming to accomplish by blocking a cloud services provider and not a particular sender domain?
- throwaway67743 4y agoI'm intrigued, what sort of abuse ratio were you seeing compared to other esps?
- soneil 4y agoSo I should point out unfair sample set - self-host me, myself and I, and no-one else. When I gave up on SES, I was getting annoyed by a commercial list that had no unsubscribe (it did, but went to a domain that didn't exist). So I had a grep through to see what I'd be missing, and it was 100% worth missing. I don't think I've seen any other provider that'd be 100% - usually when they get that bad it's just here-today-gone-tomorrow hosts. The impression I get is that providers like mailchimp where they're actually packaging it as a service, so they handle unsubscribe, campaigns, they have an abuse@ contact that actually works .. these services deliver content. Dumb pipes that only exist because the cloud provider's regular IP space has a trash reputation, tends to carry everything that gave the regular IP space that reputation in the first place. They're just weaponising the idea that no-one would be dumb enough to block amazon. I'm dumb enough.
- bluedino 4y agoTrying to get detailed logs from Outlook365 hosted accounts is near impossible. You'd think you'd be able to log in to your Exchange dashboard and just look at them. They hide it from you and only show you abbreviated logs. You can go through support, and if you pay enough money you'll get an cryptic answer within a week (if you're really lucky the support person might show you the real logs). Pain in the ass when you're trying to figure out why your users aren't getting email from someone. You can pry the mail logs from my cold dead hands.
- FuriouslyAdrift 4y agoI've found better information on 365 from Defender's Threat Explorer (https://security.microsoft.com/threatexplorer https://security.microsoft.com/threatexplorer). You'll need everything set up and E5 licenses if I remember correctly. Tons and tons of good info though.
- cma 4y agoAnother one to watch out for is Gmail silently truncated emails (if the unsubscribe button is missing, often it is in the truncated part). You can't get to the missing parts easy on mobile I think.
- dddddddd111 4y agoI get a lot of false positive in my spam folder when using Microsoft's email service.
- Arainach 4y agoI worked at MS during the launch of outlook.com, got some good email addresses without numbers on it, and used them for years. This and other issues caused me to give up and change to a different provided within the last few months. The Outlook teams are weird. They all have their own special feedback mechanisms that are different from the rest of Office, and they for the most part ignore them. Earlier this year, for some reason the SMTP servers were changed from smtp.live.com to smtp.office365.com, breaking a number of my workflows and integration with other tools. This is meaningless pain that served no point - you could just point the DNS records for smtp.live.com to the exact same servers smtp.office365.com points to. Combined with other things Microsoft has done (breaking decades of links to MSDN blogs and support pages without providing redirects) I have no faith in the stability of the product in the future. Their web view generally sucks. It doesn't play nicely with the back button - selections are lost, search results are bypassed. It gets randomly stuck where it won't load or will load the wrong CSS for hours at a time on multiple of my machines. The Android and iOS apps have largely not changed since they used to be Accompli. I can't name a new feature in the last decade. Why, in the left nav bar, is there an icon with an envelope and a plus button that is "connect a GMail account"? That icon suggests "write a new mail", which is a function I would do quite often. I never want to connect a GMail account - much less have it take up a dedicated button that's always present in the UI. Outlook on Android has its section buttons (mail, calendar, etc.) on the bottom. Mail for Windows has them on the bottom. Outlook 2016 and 2019 have them in the lower left. Outlook.com for many years had them in the lower left (if vertical). At some point they've moved to the upper-left, which is inconsistent with every other Microsoft-provided way that I check my mail and a regular source of frustration when I throw my mouse and eyes to the lower left corner and find nothing there. I could go on and on (my favorite bug is that they removed the Send Feedback button that their docs refer to so I can't tell them any of this). I was an Outlook fan for several years, but I could have written most of this feedback in 2015 and nothing's changed; at this point I would encourage anyone still using it to just forward their mail to some other provider and be done with it.
- tpoacher 4y agoI think at least part of the solution should be replying to all such instances with "Hello your client is broken. Would you mind using a different client." It's a ridiculous and easily dismissible statement at first, but not so ridiculous if it becomes commonplace/familiar/canon (it worked for internet explorer!)