#1101957#10
Date:
2026-02-12 21:59:35 UTC
From:
To:
On Thu, 3 Apr 2025 01:08:19 +0200 Marco d'Itri <md@linux.it> wrote:
 > Package: lists.debian.org
 > Severity: important
 >
 > Please create a record with p=none:
 >
 >
https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/strengthening-email-ecosystem-outlook%e2%80%99s-new-requirements-for-high%e2%80%90volume-senders/4399730
 >
 > --
 > ciao,
 > Marco

Today, I got a "lists.debian.org has received bounces from <email>"
message, because an email from debian-security-announce was bounced by
Microsoft for this reason. It also seems that neither SPF nor DKIM are
set up. There is a DKIM signature from seger.debian.org; however, the
header is renamed to "Old-DKIM-Signature".

Here are links to official pages stating that Microsoft and Google
require all three to pass if they receive 5,000 or more emails per day
from a domain (even with DMARC p=none):

https://support.microsoft.com/en-us/topic/fix-ndr-error-550-5-7-515-in-outlook-com-34cfe8f8-6fbf-457e-9e8b-9e4dbaf4e0ef

https://support.google.com/a/answer/81126?hl=en

Yahoo is similar, though does not specify a particular threshold:

https://senders.yahooinc.com/best-practices/

Can this work be prioritized? Users should not miss important security
announcements because they use one of the largest email providers.

Attached is a copy of the bounce just in case it would be useful.