There are discussions internally on it as well.
It's a known issue.

Aloha,
Michael.
-- 
Michael J Wise | Microsoft | Spam Analysis | "Your Spam Specimen Has Been 
Processed." | Got the Junk Mail Reporting Tool ?

-----Original Message-----
From: mailop [mailto:[email protected]] On Behalf Of Michael Peddemors
Sent: Friday, April 29, 2016 7:27 AM
To: [email protected]
Subject: Re: [mailop] Bounces from outbound.protection.outlook.com

This has been going on for some time now, there was discussion on this list 
regarding the topic, we ended up putting a policy in our platforms just to deal 
with this issue. "Reject messages from senders forging bounce messages".



On 16-04-29 06:25 AM, Benoit Panizzon wrote:
> Hi Renaud
>
>> I am seeing in my logs some bounces messages (empty sender) from 
>> various outbound.protection.outlook.com servers. All those bounce 
>> messages are directed towards one specific email address which is 
>> probably used as an envelope field in a spam run.
>>
>> Now my question is: if it comes from outbound servers for 
>> outlook.com, shouldn't the mails also pass through some kind of 
>> inbound servers at outlook.com? If that's the case, how comes that 
>> those messages which surely have a wrong DMARC, SPF and DKIM pass 
>> through the incoming gateways?
>
> We have exactly the same problem. We sometimes observe that some of 
> our customers get DOSed by large volumes of 
> outbound.protection.outlook.com bounces.
>
> The 'Attacker' apparently is a botnet (aka many different ip
> addresses) that fakes the sender@our-domain and sends very small 
> emails to various non existing recipients hosted on 
> outbound.protection.outlook.com servers.
>
> Our domains are protected by SPF.
>
> In the first place, the outlook.com services should not accept emails 
> to non existent recipients and then send 'late' bounces to the fake 
> sender, resulting in some kind of amplificator attack.
>
> Secondly if the sender domains is protected by SPF with -all that 
> email should be rejected my Microsoft right away during SMTP handshake.
>
> None of both is done.
>
> I documented the case and how to reproduce.
>
> I did try to open a trouble ticket with the Microsoft Security. It was 
> impossible, because we, as an ISP do not use any outlook.com services.
> I did try to explain the microsoft security agent for long time, that 
> his handling of the issue was completely wrong and that it was not a 
> question what M$ product we use, but he did not want to connect me to 
> his supervisor as we are no M$ customer and therefore there is no way 
> to open an abuse/security trouble ticket. WTF!
>
> I contacted [email protected] several times about the issue, without 
> reply.
>
> I even went so far to notify the Heise Journal security team with the 
> hint that kind of an mail traffic amplificator attack was possible via 
> outlook.com, to try to increase the pressure on Microsoft to look into 
> the issue, but they unfortunately considered this not serious enough.
>
> We cannot block the IP Addresses of the 
> outbound.protection.outlook.com as this would also affect a lot of legitimate 
> email.
>
> So I have no solution here and don't know how I can make Microsoft 
> take my reports seriously.
>
> Kind regards
>
> -Benoît Panizzon-
>
>
>
> _______________________________________________
> mailop mailing list
> [email protected]
> https://na01.safelinks.protection.outlook.com/?url=https%3a%2f%2fchill
> i.nosignal.org%2fcgi-bin%2fmailman%2flistinfo%2fmailop&data=01%7c01%7c
> michael.wise%40microsoft.com%7c3fc434694f8e4074848608d370405fad%7c72f9
> 88bf86f141af91ab2d7cd011db47%7c1&sdata=7Eum6zY7yX4NG1ow7WJtLB4fxEl2ts7
> sORPom8QPnVI%3d
>



--
"Catch the Magic of Linux..."
------------------------------------------------------------------------
Michael Peddemors, President/CEO LinuxMagic Inc.
Visit us at 
https://na01.safelinks.protection.outlook.com/?url=http%3a%2f%2fwww.linuxmagic.com&data=01%7c01%7cmichael.wise%40microsoft.com%7c3fc434694f8e4074848608d370405fad%7c72f988bf86f141af91ab2d7cd011db47%7c1&sdata=EJdTxj5ll%2b64Ete01z9ia16yraNQeU2oRzmSS77UNxU%3d
 @linuxmagic
------------------------------------------------------------------------
A Wizard IT Company - For More Info 
https://na01.safelinks.protection.outlook.com/?url=http%3a%2f%2fwww.wizard.ca&data=01%7c01%7cmichael.wise%40microsoft.com%7c3fc434694f8e4074848608d370405fad%7c72f988bf86f141af91ab2d7cd011db47%7c1&sdata=WThx%2bu882V%2bo%2bm470Frr3cj1xaV%2fC%2b37Lt0jrQVIVbk%3d
"LinuxMagic" a Registered TradeMark of Wizard Tower TechnoServices Ltd.
------------------------------------------------------------------------
604-682-0300 Beautiful British Columbia, Canada

This email and any electronic data contained are confidential and intended 
solely for the use of the individual or entity to which they are addressed.
Please note that any views or opinions presented in this email are solely those 
of the author and are not intended to represent those of the company.

_______________________________________________
mailop mailing list
[email protected]
https://na01.safelinks.protection.outlook.com/?url=https%3a%2f%2fchilli.nosignal.org%2fcgi-bin%2fmailman%2flistinfo%2fmailop&data=01%7c01%7cmichael.wise%40microsoft.com%7c3fc434694f8e4074848608d370405fad%7c72f988bf86f141af91ab2d7cd011db47%7c1&sdata=7Eum6zY7yX4NG1ow7WJtLB4fxEl2ts7sORPom8QPnVI%3d
_______________________________________________
mailop mailing list
[email protected]
https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop

Reply via email to