On Thu, 3 Apr 2025 01:08:19 +0200 Marco d'Itri <md@linux.it> wrote:
> Package: lists.debian.org
> Severity: important
>
> Please create a record with p=none:
>
>
https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/strengthening-email-ecosystem-outlook%e2%80%99s-new-requirements-for-high%e2%80%90volume-senders/4399730
>
> --
> ciao,
> Marco
Today, I got a "lists.debian.org has received bounces from <email>"
message, because an email from debian-security-announce was bounced by
Microsoft for this reason. It also seems that neither SPF nor DKIM are
set up. There is a DKIM signature from seger.debian.org; however, the
header is renamed to "Old-DKIM-Signature".
Here are links to official pages stating that Microsoft and Google
require all three to pass if they receive 5,000 or more emails per day
from a domain (even with DMARC p=none):
https://support.microsoft.com/en-us/topic/fix-ndr-error-550-5-7-515-in-outlook-com-34cfe8f8-6fbf-457e-9e8b-9e4dbaf4e0ef
https://support.google.com/a/answer/81126?hl=en
Yahoo is similar, though does not specify a particular threshold:
https://senders.yahooinc.com/best-practices/
Can this work be prioritized? Users should not miss important security
announcements because they use one of the largest email providers.
Attached is a copy of the bounce just in case it would be useful.