Microsoft to tackle spam by restricting Exchange Online bulk email
- Reference: 1713283211
- News link: https://www.theregister.co.uk/2024/04/16/microsoft_external_recipient_limit/
- Source link:
Starting from January 1, 2025, Exchange Online will begin [1]enforcing an External Recipient Rate (ERR) limit of 2,000 recipients in 24 hours for cloud-hosted mailboxes of all newly created tenants. Between July and December 2025, Microsoft will start applying the limit to the cloud-hosted mailboxes of existing tenants.
Microsoft emphasized that the limit applies to external recipients. The existing recipient rate limit of 10,000 recipients is unchanged.
[2]
"Exchange Online does not support bulk or high-volume transactional email," Microsoft said. "We have not enforced limiting of bulk email until now, but we plan on doing so with the introduction of an External Recipient Rate limit. The ERR limit is being introduced to help reduce unfair usage and abuse of Exchange Online resources."
[3]
[4]
Customers who exceed the limit will be directed to the Azure Communication Services for Email, which, according to Microsoft, "is designed specifically for high volume email sent to recipients external to your tenant."
According to Microsoft's [5]documentation , the recipient rate limit applies per user, and the company advises customers who need to send "legitimate bulk commercial email," such as newsletters, to use a third-party tool.
[6]Happy 20th birthday Gmail, you're mostly grown up – now fix the spam
[7]Spam crusade lands charity in hot water with data watchdog
[8]Microsoft takes another run at closing Exchange brute-force security hole
[9]'Millions' of spammy emails with no opt-out? That'll cost you $650K, Experian
Exchange Online has tripped over newly applied spam rules in recent months. In March, some emails from the service were [10]blocked for Yahoo and AOL users after stricter restrictions were applied. Earlier this month, users with Outlook.com country domains found their emails [11]treated as spam and prevented from reaching Gmail destinations.
From February 1, Google [12]added rules aimed at email senders who dispatch more than 5,000 messages per day to Gmail accounts. As well as requiring SPF (Sender Policy Framework) and DKIM (DomainKeys Identified Mail) email authentication for the domain, Google also said that marketing messages must support one-click unsubscribe.
[13]
One Exchange Online user [14]described the update as a "major change," while others sought clarification over where the rule would be applied. There are also legitimate integration scenarios that might breach the limit.
We contacted Microsoft for more details and will update this piece with any new information. ®
Get our [15]Tech Resources
[1] https://techcommunity.microsoft.com/t5/exchange-team-blog/exchange-online-to-introduce-external-recipient-rate-limit/ba-p/4114733
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zh70@F-iCBXwrmjWvGWRFwAAAMk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zh70@F-iCBXwrmjWvGWRFwAAAMk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zh70@F-iCBXwrmjWvGWRFwAAAMk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://learn.microsoft.com/en-us/office365/servicedescriptions/exchange-online-service-description/exchange-online-limits#sending-limits
[6] https://www.theregister.com/2024/04/02/gmail_turns_20/
[7] https://www.theregister.com/2024/03/05/penny_appeal_ico_investigation/
[8] https://www.theregister.com/2023/10/11/microsoft_exchange_bug_fix/
[9] https://www.theregister.com/2023/08/22/experian_doj_ftc/
[10] https://www.theregister.com/2024/03/14/exchange_online_blocked_from_sending/
[11] https://www.theregister.com/2024/04/03/outlookcom_blocked_by_gmail/
[12] https://support.google.com/a/answer/81126
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zh70@F-iCBXwrmjWvGWRFwAAAMk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[14] https://techcommunity.microsoft.com/t5/exchange-team-blog/exchange-online-to-introduce-external-recipient-rate-limit/ba-p/4114733
[15] https://whitepapers.theregister.com/
Re: 28 Years late
I think when I was in charge of an on-premises exchange server some years back, I'd made an alteration to limit email sending rate. Or that could be wishful remembering.
Becase slowing down the individual hosts is obviously the answer
M$ has configured it's tenants to unintentionally allow DKIM and ARC whitewashing. That and the huge number of corporates addicted to exchange made it a popular resource for spammers. Now with Google and others forcing DMARC the floodgates were thrown open as DMARC overrides SPF(itself no silver bullet if your not very very careful about trusting recursive policies from third parties).
So instead of fixing how they have their mail system rigged they just slapped leg irons on everyone's tenants. M$ needs to fix it's relaying and whitewashing problems, not just choke it's larger clients from sending mail directly.
The cynical will notice this won't impact spearphishers much, and general phishers can just spin up more tenants. Of course more tenants mean more spammers paying more M$ tax in hosting fees...
Need to fix DKIM, SPF, ARC and DMARC
Each of them has unclosed loopholes that allow stuff to slip past. DKIM is still vulnerable to replay attacks, ARC can be whitewashed, and DMARC can't set explicit enforcement to demand that mail pass all three, instead it passes if either SPF or DKIM passes and doesen't check ARC. Most have DNS trust issues as well.
All of that is fixable, but a wall of aggressive and obstructionist lobbying kicks up whenever email security might get improved.
Don't believe me? How long has SMIME been left broken in the majority of email platforms?
"legitimate bulk commercial email," such as newsletters,
Sounds like spam to me. Can't these people just put the newsletter on their website?
Could do. Though they'd probably want to send people an email to let them know about it.....
Fine, if they've opted-in to being told. Otherwise it's spam and the sender should be nuked from orbit.
28 Years late
Better late than never I suppose..