From: "Massimo S." Received: from [192.168.100.201] (HELO mail.2rosenthals.com) by 2rosenthals.com (CommuniGate Pro SMTP 5.4.10) with ESMTP id 12901361 for ecs-isp@2rosenthals.com; Thu, 24 Apr 2025 14:53:20 -0400 Received: from secmgr-va.2rosenthals.com ([50.73.8.217]:41536 helo=mail2.2rosenthals.com) by mail.2rosenthals.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.97.1) (envelope-from ) id 1u81hA-000000001fJ-2630 for ecs-isp@2rosenthals.com; Thu, 24 Apr 2025 14:53:13 -0400 Received: from mail2.quasarbbs.net ([80.86.52.115]:10109) by mail2.2rosenthals.com with esmtp (Exim 4.97.1) (envelope-from ) id 1u81h3-000000007Wx-0haD for ecs-isp@2rosenthals.com; Thu, 24 Apr 2025 14:53:06 -0400 X-SASI-Hits: BODY_SIZE_4000_4999 0.000000, BODY_SIZE_5000_LESS 0.000000, BODY_SIZE_7000_LESS 0.000000, CTE_8BIT 0.000000, DKIM_ALIGNS 0.000000, DKIM_SIGNATURE 0.000000, ECARD_KNOWN_DOMAINS 0.000000, HTML_00_01 0.050000, HTML_00_10 0.050000, IN_REP_TO 0.000000, LEGITIMATE_SIGNS 0.000000, MSGID_SAMEAS_FROM_HEX_844412 0.100000, MSG_THREAD 0.000000, REFERENCES 0.000000, REPLYTO_SAMEAS_FROM 0.000000, SENDER_NO_AUTH 0.000000, SUSP_DH_NEG 0.000000, TO_IN_SUBJECT 0.500000, URI_WITH_PATH_ONLY 0.000000, USER_AGENT 0.000000, __ANY_URI 0.000000, __BANNER_TRUSTED_SENDER 0.000000, __BODY_NO_MAILTO 0.000000, __BOUNCE_CHALLENGE_SUBJ 0.000000, __BOUNCE_NDR_SUBJ_EXEMPT 0.000000, __COURIER_PHRASE 0.000000, __CP_URI_IN_BODY 0.000000, __CT 0.000000, __CTE 0.000000, __CT_TEXT_PLAIN 0.000000, __DC_PHRASE 0.000000, __DKIM_ALIGNS_1 0.000000, __DKIM_ALIGNS_2 0.000000, __DQ_NEG_DOMAIN 0.000000, __DQ_NEG_HEUR 0.000000, __DQ_NEG_IP 0.000000, __FORWARDED_MSG 0.000000, __FROM_DOMAIN_NOT_IN_BODY 0.000000, __FROM_NAME_NOT_IN_ADDR 0.000000, __FROM_NAME_NOT_IN_BODY 0.000000, __FUR_HEADER 0.000000, __HAS_FROM 0.000000, __HAS_MSGID 0.000000, __HAS_REFERENCES 0.000000, __HAS_REPLYTO 0.000000, __HEADER_ORDER_FROM 0.000000, __HTTPS_URI 0.000000, __INVOICE_MULTILINGUAL 0.000000, __IN_REP_TO 0.000000, __IOC_PHRASE 0.000000, __MAIL_CHAIN 0.000000, __MIME_BOUND_CHARSET 0.000000, __MIME_TEXT_ONLY 0.000000, __MIME_TEXT_P 0.000000, __MIME_TEXT_P1 0.000000, __MIME_VERSION 0.000000, __MOZILLA_USER_AGENT 0.000000, __MSGID_HEX_844412 0.000000, __MULTIPLE_URI_TEXT 0.000000, __MY_MAIL_BODY 0.000000, __NO_HTML_TAG_RAW 0.000000, __PASSWORD_IN_BODY 0.000000, __PHISH_SPEAR_SUBJ_SUBJECT 0.000000, __REFERENCES 0.000000, __REPLYTO_SAMEAS_FROM_ACC 0.000000, __REPLYTO_SAMEAS_FROM_ADDY 0.000000, __REPLYTO_SAMEAS_FROM_DOMAIN 0.000000, __SANE_MSGID 0.000000, __SCAN_D_NEG 0.000000, __SCAN_D_NEG2 0.000000, __SCAN_D_NEG_HEUR 0.000000, __SCAN_D_NEG_HEUR2 0.000000, __SHIPPING_BAD_ADDRESS 0.000000, __SUBJ_ALPHA_END 0.000000, __SUBJ_ALPHA_NEGATE 0.000000, __SUBJ_REPLY 0.000000, __TO_IN_SUBJECT 0.000000, __TO_MALFORMED_2 0.000000, __TO_NAME 0.000000, __TO_NAME_DIFF_FROM_ACC 0.000000, __TO_REAL_NAMES 0.000000, __URI_IN_BODY 0.000000, __URI_NOT_IMG 0.000000, __URI_NO_MAILTO 0.000000, __URI_NO_WWW 0.000000, __URI_NS 0.000000, __URI_WITH_PATH 0.000000, __USER_AGENT 0.000000 X-SASI-Probability: 10% X-SASI-RCODE: 200 X-SASI-Version: Antispam-Engine: 5.1.4, AntispamData: 2025.4.24.175728 X-SASI-Hits: BODY_SIZE_4000_4999 0.000000, BODY_SIZE_5000_LESS 0.000000, BODY_SIZE_7000_LESS 0.000000, CTE_8BIT 0.000000, DKIM_ALIGNS 0.000000, DKIM_SIGNATURE 0.000000, ECARD_KNOWN_DOMAINS 0.000000, HTML_00_01 0.050000, HTML_00_10 0.050000, IN_REP_TO 0.000000, LEGITIMATE_SIGNS 0.000000, MSGID_SAMEAS_FROM_HEX_844412 0.100000, MSG_THREAD 0.000000, REFERENCES 0.000000, REPLYTO_SAMEAS_FROM 0.000000, SUSP_DH_NEG 0.000000, TO_IN_SUBJECT 0.500000, URI_WITH_PATH_ONLY 0.000000, USER_AGENT 0.000000, __ANY_URI 0.000000, __AUTH_RES_PASS 0.000000, __BANNER_TRUSTED_SENDER 0.000000, __BODY_NO_MAILTO 0.000000, __BOUNCE_CHALLENGE_SUBJ 0.000000, __BOUNCE_NDR_SUBJ_EXEMPT 0.000000, __COURIER_PHRASE 0.000000, __CP_URI_IN_BODY 0.000000, __CT 0.000000, __CTE 0.000000, __CT_TEXT_PLAIN 0.000000, __DC_PHRASE 0.000000, __DKIM_ALIGNS_1 0.000000, __DKIM_ALIGNS_2 0.000000, __DQ_NEG_DOMAIN 0.000000, __DQ_NEG_HEUR 0.000000, __DQ_NEG_IP 0.000000, __FORWARDED_MSG 0.000000, __FROM_DOMAIN_NOT_IN_BODY 0.000000, __FROM_NAME_NOT_IN_ADDR 0.000000, __FROM_NAME_NOT_IN_BODY 0.000000, __FUR_HEADER 0.000000, __HAS_FROM 0.000000, __HAS_MSGID 0.000000, __HAS_REFERENCES 0.000000, __HAS_REPLYTO 0.000000, __HEADER_ORDER_FROM 0.000000, __HTTPS_URI 0.000000, __INVOICE_MULTILINGUAL 0.000000, __IN_REP_TO 0.000000, __IOC_PHRASE 0.000000, __MAIL_CHAIN 0.000000, __MIME_BOUND_CHARSET 0.000000, __MIME_TEXT_ONLY 0.000000, __MIME_TEXT_P 0.000000, __MIME_TEXT_P1 0.000000, __MIME_VERSION 0.000000, __MOZILLA_USER_AGENT 0.000000, __MSGID_HEX_844412 0.000000, __MULTIPLE_URI_TEXT 0.000000, __MY_MAIL_BODY 0.000000, __NO_HTML_TAG_RAW 0.000000, __PASSWORD_IN_BODY 0.000000, __PHISH_SPEAR_SUBJ_SUBJECT 0.000000, __REFERENCES 0.000000, __REPLYTO_SAMEAS_FROM_ACC 0.000000, __REPLYTO_SAMEAS_FROM_ADDY 0.000000, __REPLYTO_SAMEAS_FROM_DOMAIN 0.000000, __SANE_MSGID 0.000000, __SCAN_D_NEG 0.000000, __SCAN_D_NEG2 0.000000, __SCAN_D_NEG_HEUR 0.000000, __SCAN_D_NEG_HEUR2 0.000000, __SHIPPING_BAD_ADDRESS 0.000000, __SUBJ_ALPHA_END 0.000000, __SUBJ_ALPHA_NEGATE 0.000000, __SUBJ_REPLY 0.000000, __TO_IN_SUBJECT 0.000000, __TO_MALFORMED_2 0.000000, __TO_NAME 0.000000, __TO_NAME_DIFF_FROM_ACC 0.000000, __TO_REAL_NAMES 0.000000, __URI_IN_BODY 0.000000, __URI_NOT_IMG 0.000000, __URI_NO_MAILTO 0.000000, __URI_NO_WWW 0.000000, __URI_NS 0.000000, __URI_WITH_PATH 0.000000, __USER_AGENT 0.000000 X-SASI-Probability: 10% X-SASI-RCODE: 200 X-SASI-Version: Antispam-Engine: 5.1.4, AntispamData: 2025.4.24.175728 DKIM-Signature: v=1; q=dns/txt; a=rsa-sha256; c=relaxed/relaxed; s=default; d=ecomstation.it; bh=tb44Win7rhdxN5tTw2Bi7dNci2+rtkmtmzQadgTKc1s=; h=Return-Path:From:To:Subject:Date:Message-ID; b=B07YYrfZh3gNCgxsrlU5JR0IUWvKsRsvANVMBFseZLkveBlkrsdqaBSlfpSc+Go9FLHEh DeErQlVYusnMf+2Bz3fW1hTss7mVG0yTg3k8AI8q/cYwZ8B7BIaH953VgHL1DMG1zVLYsUg 8ZM9Hvr+wZPxUVfvEvYm/GML2h5TpnOd9Ip3jLOU+pz4PEQsZ4X+stYttXGPKPQqUvLz/cF Rbdp7F02vVsNOzIlFzD57984XW9g/kWL4k+2YCvGKIApuDShz4YBHNQQbyfqge+/JnZk4H6 ZTOK6HQpaAtig6j1GV8n0yuwdUZw4OqX6WL8wwY5uelgUryABXvK+g+ZhWkQ== Received: from [192.168.10.199] (dtp [192.168.10.199]) by srv2 (Weasel v3.03) for ; Thu, 24 Apr 2025 20:53:00 -0000 Reply-To: ml@ecomstation.it Subject: Re: [eCS-ISP] Trouble getting mail delivered to Office365 (outlook.com), ProofPoint, and Barracuda protected domains To: eCS ISP Mailing List References: Organization: Massimo S. Message-ID: Date: Thu, 24 Apr 2025 20:52:57 +0200 User-Agent: Mozilla/5.0 (OS/2; U; Warp 4.5; it-IT; rv:1.7.13) Gecko/20060424 Thunderbird/1.0.8 Mnenhy/0.7.4.0 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8; format=flowed Content-Language: it Content-Transfer-Encoding: 8bit Il 24/04/2025 20:37, Lewis G Rosenthal ha scritto: > Hi, Max... > > On 04/24/25 03:17 am, Massimo S. wrote: >> >> >> Il 23/04/2025 21:03, Lewis G Rosenthal ha scritto: >>> Hi, Max... >>> >>> On 04/23/25 01:28 pm, Massimo S. wrote: >>>> Il 22/04/2025 22:50, Lewis G Rosenthal ha scritto: >>>>> Hi, all... >>>>> >>>>> For the past few days, I've been dealing with an issue of mail from 2rosenthals.com apparenly getting >>>>> blackholed by certain providers. We do not receive any kind of DSN. From all accounts, the email is going >>>>> out for delivery and that's that. However, on the other end, recipients aren't seeing the messages, nor >>>>> are they getting any kind of spam notification or other warning that a message could not be delivered. >>>>> >>>>> Affected domains seem to be hosted with a handful of providers, Office365 among them, which uses >>>>> outlook.com. Naturally, I've checked both the outlook.com and live.com internal lists, and both show that >>>>> neither of our IPs is listed. >>>>> >>>>> Other MXs which seem to be behaving similarly are: >>>>> >>>>> gpphosted.com (ProofPoint) >>>>> barracudanetworks.com >>>>> >>>>> Multiple multiple-RBL checks come up clean for both IPs and our domain. SPF, DKIM, and DMARC >>>>> configurations all look fine (read: pass specific checks by various third parties, including mxtoolbox.com). >>>>> >>>>> Mail flows without incident to gmail.com and yahoo.com. >>>>> >>>>> Is anyone else seeing anything like this? >>>>> >>>>> TIA >>>> >>>> Hi Lewis, >>>> >>>> yes, since i use Weasel as MTA and some european domain is start to refusing SMTP plain, >>>> they only accept STARTTLS. >>>> >>>> Anyway Peter plans to add TLS in the next months. >>>> >>>> Here i had to use external SMPTs as intermediary SMTP to keep on receiving emails >>>> from this domain. >>>> >>> >>> STARTTLS has been enabled at the firewall for years, requiring a minimum of TLS v1. I just bumped that up >>> to 1.2, in case that was some cause for concern (though I don't see why; negotiation always takes place at >>> the highest level agreed upon by both parties). >>> >>> I've also disabled outbound AV and spam scanning (I already added affected domains to the list to skip >>> adding the "Scanned by..." footer), just to exclude any additional headers which may be misconstrued. >>> >>> So far, no positive results sending to domains hosted behind outlook.com (and I have not re-tested the >>> others, as yet, except to confirm that we are getting through Barracuda's scanners). >> >> that's strange >> >> here my emails sent to my outlook account or to other ppl/firms emails using 365 >> arrive directly into the inbox folder >> >> i had an issue in the past that they were being put in the spam folder >> since i had a problem the reverse zone on bind >> >> anyway there is an MS website to test this kind of issues that may help you >> >> https://testconnectivity.microsoft.com/tests/O365InboundSmtp/input >> > > That's an interesting link, however, I think what it wants to test is an email address from a domain hosted > behind Microsoft's servers. My 2rosenthals.com address failed with the following explanation about my MX: > >    MX Records don't exist or aren't correctly configured for your domain in >    Microsoft 365. The MX value 'secmgr-va.2rosenthals.com' doesn't match >    one of the allowed values: mail.eo.outlook.com, >    mail.protection.outlook.com, mail.messaging.microsoft.com, >    invalid.outlook.com, mx.microsoft > > > Clearly, my MX will never be any of those "allowed values." I don't see another tool there which would let me > test an outside sender's address against a recipient on Office365 for Business (i.e., one of their hosted > domains). > > I'll add the link to my bookmarks, though. Thanks for that. there are a number of tests https://testconnectivity.microsoft.com/tests/exo there is also incoming SMTP that it test if you are "compatible" with 365/Exchange online massimo