Protection.outlook.com is Office365, and *NOT* "HotMail". If you have samples of the malicious NDRs, please send them to me, and I'll see if there's a way to squelch it.
Aloha, Michael. -- Sent from my Windows Phone ________________________________ From: Benoit Panizzon<mailto:[email protected]> Sent: 4/29/2016 6:36 AM To: [email protected]<mailto:[email protected]> Cc: Renaud Allard<mailto:[email protected]> Subject: Re: [mailop] Bounces from outbound.protection.outlook.com Hi Renaud > I am seeing in my logs some bounces messages (empty sender) from > various outbound.protection.outlook.com servers. All those bounce > messages are directed towards one specific email address which is > probably used as an envelope field in a spam run. > > Now my question is: if it comes from outbound servers for outlook.com, > shouldn't the mails also pass through some kind of inbound servers at > outlook.com? If that's the case, how comes that those messages which > surely have a wrong DMARC, SPF and DKIM pass through the incoming > gateways? We have exactly the same problem. We sometimes observe that some of our customers get DOSed by large volumes of outbound.protection.outlook.com bounces. The 'Attacker' apparently is a botnet (aka many different ip addresses) that fakes the sender@our-domain and sends very small emails to various non existing recipients hosted on outbound.protection.outlook.com servers. Our domains are protected by SPF. In the first place, the outlook.com services should not accept emails to non existent recipients and then send 'late' bounces to the fake sender, resulting in some kind of amplificator attack. Secondly if the sender domains is protected by SPF with -all that email should be rejected my Microsoft right away during SMTP handshake. None of both is done. I documented the case and how to reproduce. I did try to open a trouble ticket with the Microsoft Security. It was impossible, because we, as an ISP do not use any outlook.com services. I did try to explain the microsoft security agent for long time, that his handling of the issue was completely wrong and that it was not a question what M$ product we use, but he did not want to connect me to his supervisor as we are no M$ customer and therefore there is no way to open an abuse/security trouble ticket. WTF! I contacted [email protected] several times about the issue, without reply. I even went so far to notify the Heise Journal security team with the hint that kind of an mail traffic amplificator attack was possible via outlook.com, to try to increase the pressure on Microsoft to look into the issue, but they unfortunately considered this not serious enough. We cannot block the IP Addresses of the outbound.protection.outlook.com as this would also affect a lot of legitimate email. So I have no solution here and don't know how I can make Microsoft take my reports seriously. Kind regards -Benoît Panizzon- -- I m p r o W a r e A G - Leiter Commerce Kunden ______________________________________________________ Zurlindenstrasse 29 Tel +41 61 826 93 00 CH-4133 Pratteln Fax +41 61 826 93 01 Schweiz Web https://na01.safelinks.protection.outlook.com/?url=http%3a%2f%2fwww.imp.ch&data=01%7c01%7cmichael.wise%40microsoft.com%7cbf15b19f23464662df1a08d370333fb2%7c72f988bf86f141af91ab2d7cd011db47%7c1&sdata=y9bqFQT5oMBwRIrybjbeFlEZwQQP80z0mNZy%2bZCCPdE%3d ______________________________________________________
_______________________________________________ mailop mailing list [email protected] https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop
