Live data from Hacker News

Outlook/Hotmail is no longer blocking my mail server

taoshu.in

251–257 of 257 posts

Re: Outlook/Hotmail is no longer blocking my mail server

#251

Earlier quoted context omitted.

Yo I’m not even gonna apologize about this, it would be so wack if we didn’t do that: a) if a mail sever looks like it’s gonna send spam, then you gotta block it. I personally have philosophical hang ups about this, like it’d be wrong to sentence someone to prison for crimes they didn’t commit just because a system added up some points and made a prediction with high confidence, but in real life, you absolutely need…

The way you implement this, low-volume senders (nerdy individuals or small projects that can't use SES/Mailgun/… for GDPR reasons), even if they manage to get off the list once (olcsupport.office.com, escalate), never get the chance to build up reputation in the long term (I'd have to contact olcsupport again in a few months and that's just not sustainable for a small-time postmaster). I get it, you're afraid that so…

> I'm obviously being naive about that approach, but I don't remember having trouble reaching Gmail inboxes or those of local providers, and at least for Gmail

There are plenty of those who do have such issues with Gmail.

The simple reason behind all this is that spammers also have near endless patience. If it takes sending 15 emails per day per IP, they'll do it. If it's a criteria you can figure out as a legitimate user, the spammer can as well. They'll "subtract one" and bypass it.

So the end result is that there's intentional fog over the methods. Just things you can try and get right and maybe that's sufficient. Eventually the good side tends to prevail, with some effort. Other than that it's one of the hardest problems out there with insane weight on both sides.

Re: Outlook/Hotmail is no longer blocking my mail server

#252

Earlier quoted context omitted.

What kind of tiers are there for filtering? Eg. Known bad domains, known bad IP addresses, incorrectly setup DKIM / SPF, no reverse DNS, non-matching reverse DNS, and that's before even looking at content to determine whether spam.

For privacy and compliance reasons (read: “oh boy wouldn’t wanna get sued, eh?” reasons) we actually don’t snoop into the message body much. Hooray, good job on not doing the maximally big brother thing for once, MS! My hot take is that this prolly won’t last because every org descends to doing a creepy level of data collection eventually so I have a textbook on privacy preserving ML downloaded for when we join the “…

I was trying to ask generically because Microsoft deals with a universe-sized quantity of email traffic in comparison to my self-hosted barely used domains.

By tiers (which may be the wrong word, maybe just 'layers'), only relating to my setup, I mean things like:

- Tier 1: Spamhaus DROP and eDROP lists are outright blocked

- Tier 2: IP addresses that have illegitimately connected to my mail server ports are outright blocked (port scans, invalid login attempts, etc. - I manually check some of these against abuseipdb.com to determine their validity)

- Tier 3: IP addresses that have scanned non-open ports on my systems are outright blocked from connecting to my mail server ports

Just running these rules for a couple of months has dropped unwanted connections to my mail server ports a heavy percentage. One theory being that if you can block known-bad and highly-likely-bad connections, then actual spam detection (through email content review) is minimised to a certain degree.

I actually want to implement additional anti-spam IP address block lists and just haven't gotten around to it yet, but the above does a good enough job for my essentially unknown domains (as I said, a universe of difference to what Microsoft has to deal with)

- Tier 4: Black-box spam detection built-in to the all-in-one mail server solution I use (I don't know how it works, I don't know how to edit the 'rules' or even if I can).

'Tiers' I would expect Microsoft to have would be:

- Their own lists of known-bad IP addresses / ranges / ASNs

- Reverse DNS lookup validation

- DKIM checks

- SPF checks

- More protocol level 'things' beyond the understanding of a simple network admin such as myself.

- Weighting the results of all of the above to determine some kind of 'spam likelihood' score.

All of this is before reviewing the content of the actual message.

Re: Outlook/Hotmail is no longer blocking my mail server

#254

Earlier quoted context omitted.

But why do you consider this good practice? It's (unnecessarily?) frustrating for senders and poses a legal risk for recipients (the sender has the logs to prove that they sent the invoice, while the recipient doesn't have any record).

Again, not the person you replied to. But some feedback mechanisms take time (so action has to be taken after a 2xx reply) and some indicators are just very very very accurate that leaving them in even just Spam is a way bigger risk. Users have a terrible tendency to dig out malware from Spam folders.

This was not the cause in my case (no attachments, no URLs, just plain text, as far as I can remember). I know how to send email (ask mail-tester.com).

Regardless, there are always better options than silently discarding the whole email: delete attachments, erase everything that looks like a URL, even erase the whole message body, but please tell the recipient that you accepted an email and from whom.

Re: Outlook/Hotmail is no longer blocking my mail server

#255

Earlier quoted context omitted.

Similar question as my sibling comments. I have rented a server with a static IP address for over ten years now. Nobody else has used this IP during this time. Yet, every few months I have to beg Microsoft to unblock the IP. In the beginning I could do this on my own, but something changed a few years ago and now I have to beg my ISP (netcup) instead to contact Microsoft on behalf of me to temporarily whitelist the d…

Aww man, not joking this actually breaks my heart, something about the way you wrote it makes it sink in how much we’ve failed you. I’m angry at how much of your time we’ve wasted and this experience is completely unacceptable. …I think this is just a systemic issue beyond my ability to comprehend, let alone solve, and— I hope I’m wrong about this but honestly when I look ahead it seems the future is only going to ge…

[deleted]

Re: Outlook/Hotmail is no longer blocking my mail server

#256

Earlier quoted context omitted.

Similar question as my sibling comments. I have rented a server with a static IP address for over ten years now. Nobody else has used this IP during this time. Yet, every few months I have to beg Microsoft to unblock the IP. In the beginning I could do this on my own, but something changed a few years ago and now I have to beg my ISP (netcup) instead to contact Microsoft on behalf of me to temporarily whitelist the d…

Aww man, not joking this actually breaks my heart, something about the way you wrote it makes it sink in how much we’ve failed you. I’m angry at how much of your time we’ve wasted and this experience is completely unacceptable. …I think this is just a systemic issue beyond my ability to comprehend, let alone solve, and— I hope I’m wrong about this but honestly when I look ahead it seems the future is only going to ge…

Exact same situation as the person you're replying to, except ~5y instead of 10 and I gave up trying getting unblocked after at one point even the mandated reply to an automatic follow-up e-mail a few steps down the line of the appeal-chain got blocked. That behavior was consistent over multiple weeks of retrying. It was truly kafkaesque but I resorted to just not being able to email Outlook/MS recipients. Getting an outreach from someone who wants to get in touch and not being able to reply is the most frustrating. So many people probably believe I ghost them.

Outgoing email volume is a handful a week, zero automation ever, and I must have spent dozens if not in the low hundreds of hours over the years on e-mail deliverability to Microsoft alone until finally giving up. Not comparable to anywhere/anyone else.

Just to say, behind every single false-positive is a story like mine and TonyTrapp. Missing out on a group tour with the local club. An old lost friend or family member not being able to get back in touch. Missed recruitment opportunities. A lawyer not receiving a time-sensitive follow-up.

Re: Outlook/Hotmail is no longer blocking my mail server

#257

I work on Microsoft's anti-spam team, AMA!

Here is the issue that most ESPs are facing.. Every 5-6 months something is being enabled or not from Outlook's side which affects either IPs or the domain name of the sender and messages land in Junk folder or in quarantine zone. Now, I do know that the IPs might be affected by complaints or spamtraps, or maybe the client sent something suspicious, but trust me most ESPs don't allow those messages to be sent. Also, when the IPs appear GREEN in SNDS, and SPF/ DKIM and DMARC are a part of DNS authentication and headers appear like this: CAT:HSPM;SFS:(13230031)(4636009)(451199024)(7596003)(356005)(7636003)(86362001)(450100002)(8676002)(1096003)(14286002)(34206002)(5660300002)(336012)(26005)(42186006)(9686003)(33656002)(83380400001)(7846003)(33964004)(564344004);DIR:INB; X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: You are expecting that quarantine zone is the last place to find a legit message. For obvious reasons I won't share more details, but I bet that from time to time someone is messing with spam filters that can easily result in false positive and angry senders. In any case, especially when we raised tickets to Outlook, at least please inform your team not to reply like robots. If they will share with us the exact reason why a message landed in junk folder that would really help us. If it is the content, we will change it. If it is related with the sender, we will block the sender. If those are complaints, we will block senders and check their subscription sources, but at least we need something especially when SNDS shows Green IP, 0 spamtraps, 0 complaints. Thank you for reading this.
Post reply on HN