1 (edited by ifssg 2024-02-17 13:34:37)

Topic: Deliverability issues with Hotmail/Live/Outlook

Hi we are experiencing deliverability issues with Hotmail/Live/Outlook.

Some of our customers have recently reported they are no longer receiving emails from us.

We have checked (double checked and triple checked) our SPF, DKIM and DMARC settings and they look fine (they were fine before and nothing has changed on our end)...

When we look at the logs however we can see this:

The mail server [xxx.xxx.xxx.xxx] has been temporarily rate limited due to IP reputation. For e-mail delivery information, see (URL can't be posted here)

So we contacted Microsoft and this is what they replied:
"Nothing was detected to prevent your mail from reaching Outlook.com customers. Please follow the instructions below."

We checked all our reputation scores in various place and nothing wrong was noted. Our records seem clean...

However the problem remained, so we contacted Microsoft again and this is what they said:

"Thank you for contacting the Outlook.com Deliverability Support Team.
I do apologize, but I am unable to provide any details about this situation since we do not have the liberty to discuss the nature of the block. Also your IP (xxx.xxx.xxx.xxx) already been mitigated. At this point, I would suggest that you review and comply with Outlook.com’s technical standards. This information can be found at (URL can't be posted here). We regret that we are unable to provide any additional information or assistance at this time.

Obviously we have carefully read all they information we could find from Microsoft in order to comply and we believe we comply, however we could not find anything specific about rate and limits parameters.

In particular we would be very much interested if our Webmin parameters are good:

At the moment this is the kind of message we can see in our mail logs:
Feb 17 12:54:39 smtp2 postfix/smtp[2705]: 4Tb1H75DZWz1x8Q: to=<xxxxxxx@hotmail.com>, relay=hotmail-com.olc.protection.outlook.com[104.47.55.33]:25, delay=176811, delays=176808/0.06/3.5/0.16, dsn=4.7.650, status=deferred (host hotmail-com.olc.protection.outlook.com[104.47.55.33] said: 451 4.7.650 The mail server [xxx.xxx.xxx.xxx] has been temporarily rate limited due to IP reputation. For e-mail delivery information, see (URL can't be posted here) (S775) [MW2NAM10FT113.eop-nam10.prod.protection.outlook.com 2024-02-17T04:54:39.093Z 08DC2EB51928BF6A] (in reply to MAIL FROM command))

Not sure what deferred means...

When we checked in Webmin > Servers > Postfix Mail Server > Delivery rates, this are our settings:

Max number of parallel deliveries to the same destination : 20
Initial concurrency level for delivery to the same destination : 5
Min time (secs) between attempts to deliver a deferred message : 300s
Time (secs) between scanning the deferred queue : 300s
Max number of recipients per message delivery : 50
Max time (days) in queue before message is undeliverable : 5d
Max time (secs) between attempts to deliver a deferred message : 4000s
Transports that should not be delivered :    (empty)

Any advice that could help improve our posture towards Hotmail/Live/Outlook?

Any advice our pointers will be very much appreciated.

==== REQUIRED BASIC INFO OF YOUR IREDMAIL SERVER ====
- iRedMail version (check /etc/iredmail-release): 1.6.1
- Deployed with iRedMail Easy or the downloadable installer? not sure
- Linux/BSD distribution name and version: Ubuntu 18.04.6
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): MySQL
- Web server (Apache or Nginx): not sure
- Manage mail accounts with iRedAdmin-Pro? no
- [IMPORTANT] Related original log or error message is required if you're experiencing an issue.
====

----

Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.

2 (edited by ifssg 2024-02-17 13:38:08)

Re: Deliverability issues with Hotmail/Live/Outlook

Is it possible to find any guidelines about these settings:

Max number of parallel deliveries to the same destination
default_destination_concurrency_limit
The parameter specifies a default limit on the number of parallel deliveries to the same destination. This is the default limit for delivery via SMTP, via the local delivery agent and via the pipe mailer.

Initial concurrency level for delivery to the same destination
initial_destination_concurrency
This parameter specifies the initial per-destination concurrency level for parallel delivery to the same destination. This limit applies to delivery via SMTP, via the local delivery agent and via the pipe mailer.
With concurrency of 1, one bad message is enough to block all mail to a site. A concurrency of 2 seems a reasonable choice.

Min time between attempts to deliver a deferred message
minimal_backoff_time
This parameter specifies the minimal time in seconds between attempts to deliver a deferred message. This parameter also limits the time an unreachable destination is kept in the short-term, in-memory destination status cache.

Time (secs) between scanning the deferred queue
queue_run_delay
This parameter specifies the time in seconds between deferred queue scans by the queue manager.

Max number of recipients per message delivery
default_destination_recipient_limit
The parameter specifies a default limit on the number of recipients per message delivery. This is the default limit for delivery via SMTP, via the local delivery agent and via the pipe mailer.

Max time in queue before message is undeliverable
maximal_queue_lifetime
This parameter specifies the maximal time in days a message is queued before it is sent back as undeliverable.

Max time between attempts to deliver a deferred message
maximal_backoff_time
This parameter specifies the maximal time in seconds between attempts to deliver a deferred message.

Transports that should not be delivered
defer_transports
This parameter specifies the names of transports that should not be delivered to unless someone issues "sendmail -q" or equivalent. Specify zero or more names of mail delivery transports names that appear in the first field ofmaster.cf.

3 (edited by Cthulhu 2024-02-18 04:23:14)

Re: Deliverability issues with Hotmail/Live/Outlook

iRedMail doesn't use Webmin nor any of those settings,aaswell your system is not supported anymore, but this problem is not related with iredmail at all

beeing on an IP block which is used by spammers literally disables you from sending mail to any microsoft realted or hosted mail address, so there is not much you can do at all

4

Re: Deliverability issues with Hotmail/Live/Outlook

Thanks what do you mean by "your system is not supported anymore"

Where are we supposed to look for the settings in iRedMail?

Please take note that our SMTP use it's own reserved IP address which is used only exclusively by our organisation. Our IP is not showing in any blacklist. Our IP is not use by any spammers.

What would you suggest we do to resolve this? Can we engage an email expert?

5

Re: Deliverability issues with Hotmail/Live/Outlook

Hello,

Microsoft maintains its own internal blacklist to reject emails from specific IP addresses. This is why publicly available IP Reputation Check lists often do not show any errors.

At least every IP blacklisted by Spamhaus is also on Microsoft's blacklist. As far as we know, this is the only external (DNS-based) blacklist that Microsoft uses. The remaining IPs are listed based on Microsoft's own criteria. (Email volume, timeframe, header and content checks for signs of spam, count of emails in bcc, reply rate to your sent emails, and many many more things...)

These lists are not particularly transparent and include a high number of false positives since Microsoft often lists larger ranges.

There are two separate blacklists that Microsoft uses for different platforms. One is for OLC (Outlook Consumer), used by outlook.com, hotmail.com, live.com, and msn.com. The other is for Office365.

However, there is some insight into how Microsoft currently classifies your IP. You can sign up for the SNDS program to monitor the "health" and reputation of your registered IPs. This program provides data about your traffic, such as email volume and the number of user complaints. These data are only provided for IPs that send more than 100 emails per day to Microsoft accounts.

To sign up, please visit: hxxps://sendersupport.olc.protection.outlook.com/snds/

You will need to request authorization for the IPs you want to access. Microsoft uses a combination of WHOIS and rDNS to determine the owner of a specific IP.

BR

6 (edited by ifssg 2024-02-22 22:37:08)

Re: Deliverability issues with Hotmail/Live/Outlook

Thanks any idea what Throttle Settings we could use in iRedMail to be more "polite" towards Microsoft servers?

We got this email from them today, I thought I could share this here as it is quite insightful:

The connection and throttling limitation against your IP [xxx.xxx.xxx.xxx] has been set to a more appropriate level based on your reputation. Please note that this does not guarantee that your mail will be delivered to a user’s inbox, only that it will no longer be subject to the previous thresholds unless your IP/domain reputation degrades (or) until it exceeds its revised thresholds.
The troubleshooting steps in this email are recommendations only. Microsoft makes no guarantees that following these steps will guarantee deliverability to MSN or Outlook.com customers.
For more detailed information about best sending practices to Outlook.com users, please review Outlook.com Enhanced Deliverability white paper:
download.microsoft.com/download/e/3/3/e3397e7c-17a6-497d-9693-78f80be272fb/enhance_deliver.pdf
I hope that the information I provided you was helpful. You may also find additional information on common delivery questions at the Outlook.com Postmaster:
sendersupport.olc.protection.outlook.com/pm/