Email blocklisting: A Christmas gift from Microsoft that Linode can't seem to return
- Reference: 1642422261
- News link: https://www.theregister.co.uk/2022/01/17/linode_microsoft_email/
- Source link:
Problems started as large chunks of the world began packing up for the festive period. Complaints cropped up on [1]Linode's support forums when customers began encountering problems sending email to Microsoft 365 accounts from their own email servers.
On that thread, a Linode staffer acknowledged there was an issue and suggested a number of alternative third-party email services as a stopgap as well as saying: "Microsoft has acknowledge
d
the problem and looking into itsic
."[2]
More recently, the Linode team has offered to swap out affected IPv4 addresses for unaffected ones – or, for a fee, it will add some new ones to users faced with the problem. "While we cannot control how long it takes for Microsoft to address the issues on their end," said Linode, "we do have potential solutions that we can offer in order to help customers avoid the current 'Banned Sender' bounces."
[3]
[4]
The question also cropped up on [5]Microsoft's own forums as users queried banned sender bounces for emails from Linode IP addresses. "Most of our clients but not all hosted with Microsoft don't get our emails because of this issue," posted one user.
Blocklisting IP addresses to prevent the delivery of unwanted emails is not a particularly complicated concept, although Microsoft has perhaps been a little more enthusiastic about this than is strictly necessary over the years. In 2019, tsoHost's bulk email domain [6]found itself on the naughty step for Outlook and Hotmail addresses and getting itself off again proved a bit of a challenge.
[7]
Linode itself is an infrastructure-as-a-service outfit, with data centres spread around the world. One can host one's applications (including email services) and data on its platform as an alternative to the bigger boys. Right up until Microsoft decides to slap the IP addresses one is sending from on to a blocklist.
It should be possible to get the addresses removed, but users have reported issues. "Requesting to delist via their automated portal doesn't work as it claims the IPs aren't blocked," said Register reader David Bennett.
"I personally have half a dozen servers with them and the only way I'm managing to get any progress is opening tickets as I'm also a 365 customer and requesting escalation until I finally find someone who has access to the super-secret list.
[8]
"It's a really hefty problem for tons of businesses, charities etc, given how many folk use 365 for their email and how many sites rely on being able to send emails to them!"
It certainly highlights just how many people have handed the pain of running their email to Microsoft in the last few years. All well and good until something gets added to the blocklist and can't be scratched off again.
The problem seems to be easing a little in recent days – some Linode users have reported that after begging, pleading, and escalating (like our reader) some IP addresses have been released. Others, however, remain resolutely out in the cold.
[9]Would you open an email from one Dr Brian Fisher? GP app staff did – and they got phished
[10]The curious case of Spamhaus, a port scanning scandal, and an apparent U-turn
[11]A slice is better than none: Apple gives in, allows third-party app billing systems in Korea, per local law
As one sad little posting on Linode's forums put it: "As
with
many things Microsoft, it seems somewhat arbitrary whatsic
they react to or not."And Bennett? "One of our ones that had been fixed is now blocked by Hotmail instead... sigh."
The Register contacted Linode for its thoughts on the matter.
A spokesman said the issue was "currently the number one priority for our Trust and Safety team. We're iterating on changes we think are going to help address this, and have been working with Microsoft to identify the issue and get it solved as quickly as possible. Our community team will update the thread as soon as there is a resolution."
We also asked Microsoft for its take. We will update this piece should it respond. ®
Get our [12]Tech Resources
[1] https://www.linode.com/community/questions/22287/550-57511-access-denied-banned-sender-office-365
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YeWgs0Wln5prDO1cuGlU4gAAAE0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YeWgs0Wln5prDO1cuGlU4gAAAE0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YeWgs0Wln5prDO1cuGlU4gAAAE0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://docs.microsoft.com/en-us/answers/questions/674558/550-57511-access-denied-banned-sender.html?page=1&pageSize=10&sort=oldest
[6] https://www.theregister.com/2019/08/09/microsoft_blocks_tso_host/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YeWgs0Wln5prDO1cuGlU4gAAAE0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YeWgs0Wln5prDO1cuGlU4gAAAE0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2019/10/24/gp_app_director_sends_out_phishing_email/
[10] https://www.theregister.com/2019/04/16/spamhaus_port_scans/
[11] https://www.theregister.com/2022/01/12/apple_third_party_payments/
[12] https://whitepapers.theregister.com/
Re: Bully boy tactics
I was just wondering whether Linode could sue. I bet they could.
Re: Bully boy tactics
See the history of spamhaus etc as to why this isn't likely to be the case.
Mark my words...
Before long, all email will have to be sent through one of the "big" providers. The days of running your own toy mailserver are numbered...
Flame on...
Re: Mark my words...
Flame on...
Not really, I doubt whether there's anyone who'd seriously disagree. (Hope is a different matter.) The problem will come when "big" becomes "very big" or even "top
Re: Mark my words...
When the "big" providers block some particular emails from you and your clients, due to business dispute, you will prefer to run your own mail server.
My domain name hosting partner offloads mail handing to a ?big? aggregate provider. Despite my domains impeccable reputation, my email to folks on Hotmail sometimes gets blocked (by Hotmail) because of the bad behaviour of others using the same provider at the IP address level of that provider. Not much to be done except moan to domain name provider and send email again in a few days when the landscape changes. I only send about 10 emails per day but the reputation of the sending domains seems to count for nothing.
Yes, the domain doesn't have anything to do with your email reputation. It's all about the sending server. This is why people who send a lot of email pay big mail providers for dedicated IP addresses.
At our place we've found that Microsoft & Google are having a spat: Emails from Office 365 to GMail are getting bounced by GMail with Google saying some of Microsoft's servers are on the naughty step.
Yes, MS seems to have difficulty getting its servers into the DNS, and does not seem to care that the SMTP RFC requires that machines sending email are in the DNS. Some of MS's servers are in the DNS, so not all emails get rejected by Gmail, and by other providers which enforce the letter of the RFC. The random nature of the problem makes testing difficult.
Strangely @work, which only recently transitioned to O365, does not think that this is an issue at all.
Same with Google
My website and email are hosted by a small company (with which I have excellent first-name relations) who are in turn hosted by Linode. During 2020 my emails to Gmail and other Google-managed addresses was going astray, with no error reports or accessible blacklist . My hosting company gave me advice but couldn't fix it, so I re-routed my outgoing email. I don't know whether Google has yet un-blacklisted this IP address.
"We've been screwing things up since April 4th, 1975. With all that practice, we've become quite good at it. We're even proud of it."
-- Microsoft Management
"We also asked Microsoft for its take. We will update this piece should it respond."
Or even respond with a
Sending email directly from a cloud-hosted server isn't the best practice. You're better off going with a reputable mass email provider because enforcing very strict policies on emailing will mostly prevent this from happening. With Linode, you could be sharing IP address ranges with any number of bad actors, but with an email provider, they watch and make sure their customers aren't sending mass scam emails and the like so you'll much less likely to have this issue.
I wonder if 365 checks if a spam email IP is one of its sender IPs before adding it to the blocklist. What happens if someone starts sending spam from a 365 account?
Oh, please. 'Starts' sending spam from 365? MS have been a hotbed of such things since they assimilated hotmail and they haven't improved anything since.
I am not surprised
The only email traffic I ever receive from Linode is SMTP auth attempts and spam attempts to non-existent accounts. In an ongoing process I am slowly gathering all of their network ranges and blocking them from making any sort of email connection to my systems. Not once have I ever had a legitimate email from any Linode host.
Re: I am not surprised
You don't say whether it a personal server or to do with business. But to say you haven't received any legitimate email from a Linode server, does not mean you won't every do so in future.
What if in the future an important email from some who does use Linode to send their email can't get through because you have blocked it?
Re: I am not surprised
So I'm supposed to leave my systems open to SMTP auth and spamming attempts from Linode hosts to allow for a maybe one day in the future I might get a legitimate email from there? In YEARS I have never received even one useful legitimate email from a Linode host. I will cross the hypothetical problem if and when I encounter it. That's my problem, not yours.
The basic problem with cheap VPSs from companies like Linode is that management of many of these systems is in the hands of people who lack the knowledge and experience to manage a UNIX (or UNIX-like) system. They have bought into (or have been sold) the idea that Linux is magically secure, and that keeping their systems secure is as easy as apt-something or yum-something. The result of this blatant miss-selling of Linux is compromised hosts used to send spam, used to make SMTP auth attempts, etc. That is what I see. For somebody knows how to manage a UNIX system, Linode is a good solution.
Re: I am not surprised
Welcome to El Reg; the home of cynical sysadmins the world around and congratulations on your first two posts.
Do you actually individually check the IP for each and every email you've ever received and if it's spamming or not? Because I have to say that running my own spam filter myself that appears like an immensely huge amount of work to go through and find all emails from a particular IP range and then determine that they are all spam, as that's going to have to be done manually and banning IP ranges is always subject to a high level of false positives.
What tools did you use to do the checking?
Bully boy tactics
While of of the reasons for the range block may be down to the use of servers for things Micrsoft doesn't approve of (pop-up servers are just as likely to be used for spam as they are for load balancing or VPNs), there's no doubt that Microsoft is keen to drive as many people as possible towards its increasingly proprietary mail service. This probably isn't the cause here but you can imagine the Microsoft support droids telling people that the problems wouldn't happen if they used Microsoft 365…