Remix.run Logo
wccrawford 11 hours ago

It feels like there's quite a lot of spin on this. There's no hint as to how many users were actually affected. It only really seems to mention Estonia, and probably only a region of it.

The ISP there claims they haven't received any reports of SPAM. But that sounds wrong. No reports probably means your reporting system is broken.

So putting that together, it seems like a small ISP screwed up and let spammers go wild, and Outlook blocked them for it. I can't really fault Outlook for that.

chao- an hour ago | parent | next [-]

One IP address (exclusively ours) among our email IPs at my place of employment was affected. We have used that IP for nine years. Emails are strictly transactional (receipts, password resets, et cetera).

The "rate limiting" started two weeks ago, giving us a code that Microsoft's documentation doesn't even list. It remains unresolved. Never had critical issues like this on our transactional IPs prior to this, and this particular IP address is still delivering just fine to other consumer and corporate email systems.

thedanbob 11 hours ago | parent | prev | next [-]

My org (USA) was affected. I wasn't the primary person dealing with it, but from what I gather one user marked one of our emails as junk, and then suddenly all of our emails to Outlook users started getting blocked.

jeroenhd 10 hours ago | parent | prev | next [-]

Someone recently leveraged some kind of automated spam attack against my domain using Zendesk's email servers. For some reason, Zendesk doesn't enforce SPF and DKIM checks when opening new tickets, so I got flooded with "your new account has been registered" and "thank you for filing a ticket" emails.

I blocked off Zendesk entirely because they didn't fix their shitty email system. The other newsletter mail services (mailgun/sendgrid/etc.) are just as bad for this.

There are plenty of reasons why large email senders could (and should) be on reputation blacklists. None of these email delivery companies seem to care very much about the spam they send until shit hits the fan, and now that it did it seems everyone blames the people maintaining the blacklists.

jamespo 5 hours ago | parent [-]

This was widespread, I was also affected. I think you can create spoof tickets / accounts over Https with no verification and zendesk don't want to do anything which adds friction.

shevy-java 11 hours ago | parent | prev | next [-]

> There's no hint as to how many users were actually affected.

How many users would you see as the threshold then?

Since you stated that there is a spin to this, how many users would go over your defined threshold level?

dqv 2 hours ago | parent | prev | next [-]

Your intuition is way off, like dangerously off. But your comment is a great example to show a smug lawyer at Microsoft when they try to say there is no basis for the claim that these blocks against legitimate senders are defamatory.

This has been affecting reputable senders who take spam reporting seriously, including MXRoute and Discourse.

> No reports probably means your reporting system is broken.

"No reports" can mean a lot of things. There is no "probably".

The "you" in "your" is Microsoft because under a certain volume of email, they don't even send reports. I regularly test the abuse contact address for my server because of this exact unfair assumption - that it must be my fault. I have never once gotten an abuse report notification from Microsoft, but I have gotten a bounce message saying that I'm blocked because I apparently send spam! Btw, this was in reply to an email from a Microsoft user.

Worse, I figured I'd just disallow any email from a Microsoft property - if an outlook (or hotmail or live or anyone else) sends an email, I can just bounce it and tell them to use a different service to reach me since I can't reply. Nope! Microsoft won't surface the bounce message to the user.

So, I am barred from replying to Microsoft emails. I am also barred from informing the sender that their email won't reach me.

It's defamation - the sender is always going to assume that it is my fault if I didn't reply even if the reason I "didn't reply" is outside of my control.

> So putting that together, it seems like a small ISP screwed up and let spammers go wild, and Outlook blocked them for it. I can't really fault Outlook for that.

Yes, in your imagined scenario, you can't really fault outlook. In the real world, however, outlook is very much to blame.

shiftpgdn 4 hours ago | parent | prev | next [-]

This is an extremely widespread issue. I send close to a million emails per month across dozens of different providers (all newsletters.) These are all from high reputation domains and email accounts. We are completely unable to make anything happen with Microslop. It is infuriating.

cromulent 11 hours ago | parent | prev [-]

The article has hyperlinks in it, e.g. to this:

https://learn.microsoft.com/en-us/answers/questions/5786144/...

which comes from an ESP serving millions of users.