Microsoft issued an advisory (EX765789) affecting Exchange Online users: "Ensure your email authentication records are set up to avoid mail flow issues to third-party email accounts". Emails to some third-party providers are failing, showing a "550 5.0.350 Remote server returned an error -> 554 Message not allowed" error. This stems from tighter security by these providers, now requiring domains to have a DMARC policy (even if it is p=none initially) as well as DKIM and SPF authentication to combat spam and malicious emails. The issue started on April 3, 2024, at 10:26 GMT+13, with ongoing investigations.
We think advisory EX765789 could provide clearer advice, while it doesn't name a particular provider it should note that Google now requires senders who send 5,000 or more messages per day to have a DMARC record setup for their domain, even if it is not set to an enforcement action (p=none
) - as well as valid SPF and DKIM setup.
Google Email Sender Guidelines
To setup DMARC in a pinch without any enforcement action or reporting, add this TXT record to your domain DNS manager:
Hostname: _dmarc.yourdomain.com
Type: TXT
Value: v=DMARC1; p=none;
For visibility of mail source SPF and DKIM compliance, sign up for a free trial of VerifyDMARC and use our DNS record generator to start collecting actionable insights.
This advisory underscores the importance of addressing proper email authentication practices. As an MSP or IT team, ensuring your organization's email traffic complies with the latest security requirements is not just about preventing attacks; it's also about email deliverability.
For those looking to navigate these changes with ease, our DMARC reporting offers a streamlined solution to manage and monitor your email authentication effectively. It shows you at a glance if SPF and DKIM are setup correctly and aligned for DMARC. Sign up for a free trial to get DMARC setup quickly and get emails delivering to inboxes.
Learn how to stop email spoofing and improve delivery of order confirmations with DMARC. Implementation guide for Shopify, WooCommerce and Adobe Marketo.
Even with p=none, DMARC without report monitoring is like driving blindfolded. Mail servers still check authentication, impacting your deliverability.
VerifyDMARC now offers SMTP TLS Reporting capabilities, enabling monitoring of MTA-STS and DANE policy performance for improved email transport security.