News: 1710414007

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Exchange Online blocked from sending email to AOL and Yahoo

(2024/03/14)


If you're an Exchange Online user wondering why emails to Yahoo and AOL users haven't been getting through, don't worry – it isn't just you. Stricter security rules have tripped up Microsoft's email service.

The [1]issue dates back to the end of February and is related to stricter restrictions implemented by AOL and Yahoo. Microsoft created an advisory — [2]EX719348 — saying it was aware of the issue and was working with an unnamed third-party spam service to determine which range of its IP addresses was causing the problem.

[3]Crooks hook hundreds of exec accounts after phishing in Azure C-suite pond

[4]Microsoft uses carrot and stick with Exchange Online admins

[5]Want a well-paid job in tech? You just need to become a cloud-native god

[6]Deluge of of entries to Spamhaus blocklists includes 'various household names'

[7]UK NHS 850k Reply-all email fail: State health service blames Accenture

Judging by an [8]update from the UK's NHS, the problem is ongoing. As of March 13, 2024, the NHS posted that Microsoft was continuing to work with the third-party anti-spam service and, "once they have isolated the IP addresses that are causing the third-party anti-spam service to block a portion of Microsoft's email IP address ranges, they will limit the mail flow as a long-term solution to prevent the issue from reoccurring."

Spam-tracking services, such as [9]Spamhaus , maintain spam blocklists (SBL) that can block a given IP address or range from sending mail. The theory is that malicious emails can be blocked from ever troubling users' mailboxes. However, it is also all too easy to trip up and for users to find themselves on an SBL without realizing it until the emails stop being delivered.

While Microsoft works with the unnamed third-party anti-spam service, frustrated users have come up with solutions of their own. One [10]found emails were DKIM signed by the onmicrosoft.com subdomain rather than the actual sending domain. They set up DKIM for the actual sending domain, and all was well.

[11]

DKIM – DomainKeys Identified Mail – is used to ensure an email that has claimed to come from a given domain was indeed authorized by the owner of that domain. It is not a particularly new standard, though it is easy to see how email might be rejected if it is not configured and a destination is checking it.

[12]

Microsoft noted that the problem "isn't connection method specific and thus occurs in all Exchange Online connection methods." It went on to say: "Affected users receive a Non-Delivery Report (NDR) message that references the third-party anti-spam service name that has added the IP address to their block list."

Microsoft has form regarding IP blocking, although less so when it comes to being on the receiving end. In 2019, [13]it blocked TSO Host's email IPs from sending email to Hotmail and Outlook inboxes, leading one wag to comment, "So, as long as people with TSO mailboxes don't have any friends on Hotmail you're fine. D'oh!"

[14]

In this latest case, if you're an affected Exchange Online customer and don't need to talk to anyone using a service protected by the unnamed third party, you'll be fine.

Alternatively, perhaps just pick up the phone and have a chat. ®

Get our [15]Tech Resources



[1] https://www.reddit.com/r/sysadmin/comments/1bc7n6x/microsoft_o365_blocked_from_sending_to_aol_yahoo/

[2] https://answers.microsoft.com/en-us/outlook_com/forum/all/im-not-recieving-emails-from-my-work-email-to-my/95de81a3-e48e-41ec-8da8-c9a1f0c233f8

[3] https://www.theregister.com/2024/02/13/exec_accounts_phishing_campaign/

[4] https://www.theregister.com/2023/03/30/microsoft_hardening_exchange_online/

[5] https://www.theregister.com/2023/11/10/kubecon_opinion/

[6] https://www.theregister.com/2022/08/18/deluge_of_entries_to_spamhaus/

[7] https://www.theregister.com/2016/11/14/nhs_blames_supplier_accenture_850k_user_reply_all_email/

[8] https://support.nhs.net/2024/03/microsoft-365-alert-service-degradation-exchange-online-some-users-outbound-exchange-online-email-messages-may-be-marked-as-spam-and-not-delivered/

[9] https://www.theregister.com/2022/08/18/deluge_of_entries_to_spamhaus/

[10] https://www.reddit.com/r/sysadmin/comments/1bc7n6x/comment/kueei4g/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZfMtKn@9QQDde10zCjyBjwAAAEk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfMtKn@9QQDde10zCjyBjwAAAEk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://www.theregister.com/2019/08/09/microsoft_blocks_tso_host/

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfMtKn@9QQDde10zCjyBjwAAAEk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[15] https://whitepapers.theregister.com/



Korev

Maybe they confused Hotmail for Hotmale and thought it was porn spam...

Alternatively, perhaps just pick up the phone and have a chat

Rafael #872397

... talk ... with someone? In real time?

*shudder*

Re: Alternatively, perhaps just pick up the phone and have a chat

Andy Non

Or if you need to send them a file, just ensure you and the recipient each procure a device from the museum called a "dial-up modem" ;-)

Re: Alternatively, perhaps just pick up the phone and have a chat

BenDwire

Museum? Don't you mean that box of "stuff that might come in useful" in the corner of my office?

(And no, I'm not joking)

Re: Alternatively, perhaps just pick up the phone and have a chat

cookieMonster

Upvote. And I’m with you on that one. I’ve an old US Robotics in a box in a corner, somewhere.

For the youngsters here, that’s a dial-modem, the thing that lets you hear the screams on the internet

Re: Alternatively, perhaps just pick up the phone and have a chat

Dimmer

"I’ve an old US Robotics in a box in a corner"

Same here. As a test, I handed one to a new employee. I told them I would buy them lunch if they could identify it's use without looking it up.

He could not.

- I must be getting old......

Anonymous Coward

Spamhaus and the like can be a pain. When I set up a business about 15 years ago I didn't know much anything about domains. The only address I could get for my company was a .uk.com one so I took it. All was well for a couple of years then we had loads of trouble with emails bouncing due to Spamhaus periodically blacklisting virtually the whole of .uk.com and the impossibility of doing much about it because I was on a secondary domain - a thing I hadn't known or understood when I bought it. When the .uk domain came up I changed to it, only to find out that many mail systems automatically put anything .uk into spam. The .uk problem seems to have settled down now - I have a personal .uk which is sometimes, albeit rarely, problematic for some servers - but our company is on a .co.uk now. Moral of the story is that if you're setting up a company then an available web address name is more important than a snappy company name.

Yorick Hunt

Spamhaus has never blocked domains; it's always been IP-based.

Frustrating as it may seem to the uninitiated, try being on the receiving end running a mail server receiving thousands of steaming turds from the same compromised sending server.

If you're ever facing a problem with Spamhaus, complain to the operator of your mail service - they're the only ones who can get rid of the problem (by thumping the offending account).

Anonymous Coward

I had a few telecons with my ISP (in the days when they talked on the phone) and they told me that it was uk.com being blacklisted by Spamhaus and there was nothing they could do because they didn't host the main domain. Willing to believe now that they were talking shit.

Anonymous Coward

Spamhaus also blocks by domain name:

https://www.spamhaus.org/blocklists/domain-blocklist/

Coming home to roost.

Yorick Hunt

Giving every Tom, Dick, Harry, Habib et al a free Exchange account to play with to "trial" the service with a complementary .onmicrosoft.com subdomain was always a recipe for disaster.

Maybe now that larger mail services have started saying "FOaD" to them, Microsoft might actually start taking their responsibilities seriously?

Re: Coming home to roost.

Agent Zoil

I am glad to see someone has enough clout to get Microsnot to actually do something about it. MS has been the biggest spam/scammer source in my system for ages. But as just a drop in the bucket there is no way for little me to get them to give a &$@#.

The mail headers from the daily poundings I get through MS show this...

X-Ms-Exchange-Authentication-Results: spf=fail (sender IP is 45.156.21.51) smtp.mailfrom=t6DGGXCf.onmicrosoft.com; dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=t6DGGXCf.onmicrosoft.com;

Anonymous Coward

I'm sure the two dozen people with Yahoo email will be distraught at this development

Anonymous Coward

Sure it's that many?

Paul Crawford

You may laugh...yes, I know now please stop laughing...but I have found my Yahoo spam-sink email has been much less of a crap show than any attempts with MS for a free low-value email address in the past.

Korev

I still have mine, I should get around to doing this year's check...

rg287

You jest, but I recently took over as Membership Secretary for a small sports association.

Of the 70-odd email addresses in our membership list (told you it was small), the following domains showed up: 1

Gmail: 16

Yahoo: 11

btinternet: 10

Hotmail: 8 (plus an @live and @outlook, so 10 for Microsoft)

AOL: 6

Sky: 5

Plus a smattering of oddballs - protonmail, gmx, tiscali, blueyonder

I was surprised at quite how many people have custom domains. I know a couple of those are hosted on M365, so chalk up a couple more for MS. Couple of work-looking domains as well (why do people do this?).

We constantly hear that "mail is just Microsoft vs. Google", but it doesn't seem to be quite the case, at least not for this (admittedly small) sample. At least in the UK, btinternet has a sizeable chunk of the market (at least amongst the older/account-holding demographic. The youth are probably more on the gmail they got when they were 14). Yahoo is surprisingly dominant.

1. .com and .co.uk addresses are aggregated since we're really talking about providers, even though in actual mail terms they'd be treated as totally separate domains.

F. Frederick Skitty

Suspect this is similar to the cock up 123 Reg (now a GoDaddy subsidiary) made when moving their hosted email service to a new system. They didn't even implement DKIM, and every email from accounts that has been moved was blocked when sent to a Gmail email address. Took two weeks to get it sorted.

AOL

Rich 2

AOL??? That still exists???

Actually, Yahoo???….

Re: AOL

andy the pessimist

My IFA still uses AOL.com.

Yep

Snake

Yes indeed, happened to me just this week with a client. Finally got them to send me an email from their Yahoo account, to which I could respond.

tony72

One found emails were DKIM signed by the onmicrosoft.com subdomain rather than the actual sending domain. They set up DKIM for the actual sending domain, and all was well.

Microsoft was prompting to check this back in February, if not before, there was an alert either on the 365 admin centre or the Exchange admin page. I sorted ours on the 13th. No idea if that's actually the "fix", but emails to the one AOL contact that I know about seem to have been getting through fine in the last week.

Enforcing DMARC

Justin Pasher

Absolutely. AOL/Yahoo[1] and Google[2] both made announcements about stricter DMARC validation, which requires either SPF or DKIM alignment. SPF alignment can be tricky if you don't have control over the envelope sender (the "internal" address usually used for bounce backs). DKIM alignment requires the signing domain to match the From header. The article itself mentions that someone fixed their problem by setting up proper DKIM signing. It's very unlikely to be IP address based, even though there are miscreants that use Microsoft email services.

All that being said, Yahoo has always been a joke for email deliverability. Their solution to reducing spam is basically "accept fewer emails." If you are a bulk sender (and sometimes not), they will randomly start throttling you and return a generic "deferred due to user complains" message, which is completely bogus. Anyone that has a Yahoo email address should not expect reliable email delivery.

[1] [1]https://blog.postmaster.yahooinc.com/post/730172167494483968/more-secure-less-spam

[2] [2]https://blog.google/products/gmail/gmail-security-authentication-spam-protection/

[1] https://blog.postmaster.yahooinc.com/post/730172167494483968/more-secure-less-spam

[2] https://blog.google/products/gmail/gmail-security-authentication-spam-protection/

Proactive monitoring perhaps?

Keith Langmead

"However, it is also all too easy to trip up and for users to find themselves on an SBL without realizing it until the emails stop being delivered."

However, it's also all to easy to setup monitoring and alerting to check whether your outbound email IPs have appeared on certain SBLs, so you can do something about it proactively!

Hmmm, maybe that was handled in the past by the same team who tested their patches before they were publically released... so no longer gets done.

Blackjack

People still use Yahoo and AOL emails? I deleted my accounts on those years ago due to safety concerns.

Of all forms of caution, caution in love is the most fatal.