Emails being blocked by Gmail from office 365

Anonymous
2023-03-02T23:25:26+00:00

When the emails is sent to gmail its being blocked stating

Delivery has failed to these recipients or groups:

___@___.___ (***********@gmail.com)

Your message wasn't delivered because the recipient's email provider rejected it.

all my records are up to date..

gmail.com suspects your message is spam and rejected it.

natasha.daniel Office 365 gmail.com
Sender Action Required
<br> --- --- --- --- ---
Messages suspected as spam
How to Fix It
Try to modify your message, or change how you're sending the message, using the guidance in this article: Bulk E-mailing Best Practices for Senders Using Forefront Online Protection for Exchange. Then resend your message.
If you continue to experience the problem, contact the recipient by some other means (by phone, for example) and ask them to ask their email admin to add your email address, or your domain name, to their allowed senders list.

Was this helpful?Send feedback to Microsoft.


More Info for Email AdminsStatus code: 550 5.7.350

When Office 365 tried to send the message to the recipient (outside Office 365), the recipient's email server (or email filtering service) suspected the sender's message is spam.

If the sender can't fix the problem by modifying their message, contact the recipient's email admin and ask them to add your domain name, or the sender's email address, to their list of allowed senders.

Although the sender may be able to alter the message contents to fix this issue, it's likely that only the recipient's email admin can fix this problem. Unfortunately, Office 365 Support is unlikely to be able to help fix these kinds of externally reported errors.

Original Message Details

Created Date: 3/2/2023 11:29:38 PM
Sender Address: *********@*****.com
Recipient Address: *********@gmail.com
Subject: Email check

Error Details

Reported error: 550 5.7.350 Remote server returned message detected as spam -> 550 5.7.1 [2a01:111:f403:700f::715 19] Our system has detected that this;message is likely suspicious due to the very low reputation of the;sending domain. To best protect our users from spam, the message has;been blocked. Please visit; https://support.google.com/mail/answer/188131 for more information. c23-20020aa7c997000000b004ace5dc6b61si945041edt.369 - gsmtp
DSN generated by: PN3P287MB0113.INDP287.PROD.OUTLOOK.COM
Outlook | Windows | Classic Outlook for Windows | For home

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

100 answers

Sort by: Newest
  1. Anonymous
    2023-09-25T17:12:05+00:00

    Okay backstory on my environment. We use a third party email filter cloud service called Forcepoint. They originally had us create a connector for outbound emails to be filtered through their server. I tried to recreate this connector since our environment is having a similar issue with Google emails. When I hit the Validate button, the email errors out saying that our "outbound Forcepoint connector" is causing an issue for this connector to work in our environment. I'm sorry this is kind of vague but I can go into more detail if you need me. Thank you.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2023-09-18T04:14:54+00:00

    Hi Michael,
    The IPv6 address you gave in your example is setup correctly, it resolves to

    IP address: 2a01:111:f400:7eaa::61a
    Reverse DNS: OK mail-dm6nam11on2061a.outbound.protection.outlook.com
    Reverse DNS Authenticity: OK Verified
    Reverse DNS Domain: a.1.6.0.0.0.0.0.0.0.0.0.0.0.0.0.a.a.e.7.0.0.4.f.1.1.1.0.1.0.a.2.ip6.arpa
    Country: United States Of America United States Of America
    Link to IP Information: IP Information for 2a01:111:f400:7eaa::61a
    Direct Link to Reverse DNS: Reverse DNS for 2a01:111:f400:7eaa::61a

    The address that was used by for my tenant was 2603:10b6:408:114::7 if you try to resolve that address you get

    IP address: 2603:10b6:408:114::7
    Reverse DNS: Error No Reverse DNS found!
    Reverse DNS Authenticity: Warn Unknown
    Reverse DNS Domain: Not Found
    Country: United States Of America United States Of America
    Link to IP Information: IP Information for 2603:10b6:408:114::7
    Direct Link to Reverse DNS: Reverse DNS for 2603:10b6:408:114::7

    This is not a google issue, this is an issue, I agree using connectors works to force IPv4 and I agree you can use another emailer service to send emails on your behalf.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2023-09-18T00:36:03+00:00

    No Xavier that is not what I said about a smtp relay, to use it to relay "microsoft.com" emails. That will not work at all.

    I was giving options on how to bypass sending thru MSFT servers completely for bulk email only; where you can control the rate limit. But, why would you think that using your own SMTP server to send from a domain that you own would be an issue????

    With regards to IPV6, yes that is a known issue but it is NOT "technically" on the Microsoft side. Microsoft is doing it correctly.

    Its Gmail's implementation of SPF checking that does not correctly identify the IPv6 address that Microsoft is sending from as being allowed.

    MSFT DOES THOUGH have their include statement correct. And since gmail publishes IPv6 records to their MX servers, and MSFT gives preference to ipv6 routing. MSFT logically in turn sends from an server from their IPv6 network and hence an IPv6 address.

    For example, here is what gmail saw when I send normally without a connector:

    Received: from NAM11-DM6-obe.outbound.protection.outlook.com (mail-dm6nam11on2061a.outbound.protection.outlook.com. [2a01:111:f400:7eaa::61a] <---- notice the sending server was an ipv6 one

    Now look at these IPv6 addresses in the MSFT include record:

    ip6:2a01:111:f400::/48 ip6:2a01:111:f403::/49 ip6:2a01:111:f403:8000::/50 ip6:2a01:111:f403:c000::/51 ip6:2a01:111:f403:f000::/52

    The sending address of 2a01:111:f400:7eaa::61a is well within that ipv6 subnet. So there should not be an issue, right? But there is, and it is broken on the gmail side, not the msft side.

    Why does the connector work? Because by using the connector, you are forcing the MSFT servers to not resolve ipv6 and only use ipv4. In turn they send to an ipv4 IP rather than the gmail ipv6 addresses.

    (I usually don't include my alphabet soup, but since it was questioned about why use an smtp relay....)

    Michael B. Morell, CISSP #431307 CCSK CCNP RHCE MCSE+I (he/him/his/sir)

    DirectionWeb Inc.

    Owner and Information Security Professional

    =============

    MX records of gmail

    =============

    > set type=mx

    > gmail.com

    Server: dns.google

    Address: 8.8.8.8

    Non-authoritative answer:

    gmail.com MX preference = 40, mail exchanger = alt4.gmail-smtp-in.l.google.com

    gmail.com MX preference = 20, mail exchanger = alt2.gmail-smtp-in.l.google.com

    gmail.com MX preference = 5, mail exchanger = gmail-smtp-in.l.google.com

    gmail.com MX preference = 10, mail exchanger = alt1.gmail-smtp-in.l.google.com

    gmail.com MX preference = 30, mail exchanger = alt3.gmail-smtp-in.l.google.com

    alt1.gmail-smtp-in.l.google.com internet address = 172.217.197.27

    alt1.gmail-smtp-in.l.google.com AAAA IPv6 address = 2607:f8b0:400d:c0f::1a

    alt3.gmail-smtp-in.l.google.com internet address = 172.253.62.26

    alt3.gmail-smtp-in.l.google.com AAAA IPv6 address = 2607:f8b0:4004:c07::1b

    alt4.gmail-smtp-in.l.google.com internet address = 64.233.186.27

    alt4.gmail-smtp-in.l.google.com AAAA IPv6 address = 2800:3f0:4003:c00::1b

    alt2.gmail-smtp-in.l.google.com internet address = 108.177.12.27

    alt2.gmail-smtp-in.l.google.com AAAA IPv6 address = 2607:f8b0:400c:c08::1a

    gmail-smtp-in.l.google.com internet address = 74.125.138.27

    gmail-smtp-in.l.google.com AAAA IPv6 address = 2607:f8b0:4002:c00::1b

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2023-09-17T22:53:27+00:00

    The issue is with the IPv6 address the Microsoft server is using failing SPF, see my post on page 4

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2023-09-17T22:53:01+00:00

    You are setting up an email server to relay emails from Micosoft? Seems like you are opening yourself to a whole lot of issues by self hosting an SMTP server. The issue can be band-aided by setting up connectors, however the issue is with the IPv6 address the Microsoft server is using failing SPF, see my post on page 4

    Was this answer helpful?

    0 comments No comments