Jump to content

Recommended Posts

Posted

I've had an interesting one this morning.

 

School had large number of bounce backs from parents gmail accounts (Whole School news letter) google advises spam issue.

 

I know i configured DKIM and DMARC for School domain. Check DNS records yep still there go into office 365 security yep DKIM enabled and MX toolbox advises that everything appears to be correct even the dkim selector running 2048bit encryption.

 

Get hands on original email empty dmarc and dkim entries within the header.

 

Go into O365 Tenancy into help run how to set up DKIM pop in domain expecting random message saying not correctly configured to work with nope returns message stating The DKIM signing configuration for the domain name.sch.uk has been successfully created and enabled.

 

Sent a test email from a new account check headers DKIM and DMARC are now there.

 

I'm awaiting response from office to confirm that config is now applied to bulk emails from the office account

Posted
I've had an interesting one this morning.

 

School had large number of bounce backs from parents gmail accounts (Whole School news letter) google advises spam issue.

 

I know i configured DKIM and DMARC for School domain. Check DNS records yep still there go into office 365 security yep DKIM enabled and MX toolbox advises that everything appears to be correct even the dkim selector running 2048bit encryption.

 

Get hands on original email empty dmarc and dkim entries within the header.

 

Go into O365 Tenancy into help run how to set up DKIM pop in domain expecting random message saying not correctly configured to work with nope returns message stating The DKIM signing configuration for the domain name.sch.uk has been successfully created and enabled.

 

Sent a test email from a new account check headers DKIM and DMARC are now there.

 

I'm awaiting response from office to confirm that config is now applied to bulk emails from the office account

 

do you run your own webservers? Check they havent been breached and spewing out mails from your domain, albeit unsigned etc

Posted
do you run your own webservers? Check they havent been breached and spewing out mails from your domain, albeit unsigned etc

 

All email handled by MS 365 no link to school server (primary)

Posted
We sometimes get bounces where a parent's email address autoforwards to some other account of theirs, and the delivery failure is happening after the initial delivery. Could something like that account for the email to their Gmail address not having the expected DKIM and DMARC headers?
Posted

Is your SPF record OK? We had an issue with Google accounts, and a couple of other ISPs, who had tightened their mail checks. Investigating we found that SendGrid (bulk mailer used by iSAMS) had gotten confused so our SPF, although it appeared all happy, wasn't fully correct so mails were being bounced.

 

One check you could do is use https://www.mail-tester.com/. You send an email to an address it generates and it will look at the headers and tell you any issues. It is geared towards newsletters so ignore recommendations about images or no text. If the bounceback gives you headers you can run them through MXToolbox Header Analyser .

 

Are you signed up to the NSCS mailcheck service and reporting? That way you can have a look in there at problems. You won't be able to analyse a specific email but it will show you areas that are causing issues.

  • Thanks 3
Posted
Is your SPF record OK? We had an issue with Google accounts, and a couple of other ISPs, who had tightened their mail checks. Investigating we found that SendGrid (bulk mailer used by iSAMS) had gotten confused so our SPF, although it appeared all happy, wasn't fully correct so mails were being bounced.

 

One check you could do is use https://www.mail-tester.com/. You send an email to an address it generates and it will look at the headers and tell you any issues. It is geared towards newsletters so ignore recommendations about images or no text. If the bounceback gives you headers you can run them through MXToolbox Header Analyser .

 

Are you signed up to the NSCS mailcheck service and reporting? That way you can have a look in there at problems. You won't be able to analyse a specific email but it will show you areas that are causing issues.

 

used dmarctester by uri ports but it can't do any harm in sending to another service

Posted
Sent from outlook client via O365

So it’s either your DNS was having a lie down at precisely that moment or MS were having issues. This strikes me as ‘ignore unless it happens again’ type problem

Posted

Maybe Google are starting to enforce the changes for 1st February.

 

https://support.google.com/a/answer/14229414?hl=en

 

I’m surprised there hasn’t been more noise about these changes.

 

It’s quite easy to exceed 5000 emails from a domain in a day.

 

You need SPF and DKIM setup for authentication.

 

You only need alignment for either SPF or DKIM.

 

I would comply with the criteria for 5000+ senders even if it never happens.

 

There is also a move to require p=quarantine and p=reject in the future.

 

I wouldn’t be surprised if there are mail delivery issues to consumer gmail and yahoo accounts in the coming weeks.

Posted
We have SPF & DKIM setup - Once these changes are in place, are we required to either quarantine or reject on the DMARC policy? Ours is just set to none at the moment & has been for a while
Posted

Thought about using the .gov notify service for bulk e-mailing? It's free for e-mails for schools and other public bodies. E-Mails come from the governments own bulk e-mailing service so less likely to be flagged as spam.

 

We had Edulink One sending out e-mails linked to a specific noreply e-mail address from our M365 tenant, but the number of messages going out was getting worryingly high so switch it to the .gov notify service and no problems since.

 

We use Arbor now as well, which has it's own comms system built in and they guide you setting up extra SPF and DMARC entries to facilitate e-mails coming from our domain on their behalf.

 

Pete

Posted
Thought about using the .gov notify service for bulk e-mailing? It's free for e-mails for schools and other public bodies. E-Mails come from the governments own bulk e-mailing service so less likely to be flagged as spam.

 

We had Edulink One sending out e-mails linked to a specific noreply e-mail address from our M365 tenant, but the number of messages going out was getting worryingly high so switch it to the .gov notify service and no problems since.

 

We use Arbor now as well, which has it's own comms system built in and they guide you setting up extra SPF and DMARC entries to facilitate e-mails coming from our domain on their behalf.

 

Pete

 

Does .gov Notify support file attachments yet? That was all that was preventing us from adopting it.

Posted
I think i may have got to the root cause of the issue re DKIM even though it was enabled under security i had to enable it via help topic with o365 admin console set up DKIM. another school i support when i tested against DKIM set up returned a different message (will provide at a later date) to imply an additional step i may have missed out

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...