Outlook emails not deliverable to yahoo and aol

Anonymous
2024-01-13T17:14:45+00:00

Starting this week, our emails to yahoo and aol accounts are not being delivered, but emails to other email accounts are working. Here is one of the yahoo error message: 1/12/2024 9:27:16 PM - Server at SJ2PR02MB10076.namprd02.prod.outlook.com returned '550 5.4.300 Message expired -> 421 4.4.2 Connection dropped due to SocketError' 1/12/2024 9:26:15 PM - Server at mta5.am0.yahoodns.net (67.195.204.73) returned '421 4.4.2 Connection dropped due to SocketError'

And here is the aol error message: 1/12/2024 9:27:38 PM - Server at PH0PR02MB7367.namprd02.prod.outlook.com returned '550 5.4.300 Message expired -> 421 4.4.2 Connection dropped due to SocketError'
1/12/2024 9:15:15 PM - Server at mx-aol.mail.gm0.yahoodns.net (67.195.204.80) returned '421 4.4.2 Connection dropped due to SocketError'

Outlook | Windows | Classic Outlook for Windows | For home

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

221 answers

Sort by: Most helpful
  1. Anonymous
    2024-01-30T17:36:28+00:00

    I'll just chime in here again with a few general pointers. I'm on the road most days, so I can't respond in a very timely manner most of the time, and Ron is giving good guidance.

    SPF - OR ~

    My apologies if this was covered, when adding a hyphen or a tilde at the end of the SPF record, tells email servers what to do when they receive email from your domain from a source not specified in the SPF. A hyphen will cause the receiving email server to reject it altogether. A tilde will cause the message to get marked as spam and usually goes into their spam filter / folder / junk email / etc. Since your regular emails you send should all come from a host that IS specified in the SPF, it really doesn't matter what you select. I use the tilde option myself, and that should work well for most.

    DMARC / DKIM

    Having an incorrect DMARC or DKIM record is worse than not having one at all. Yes, you should have all 3, and for people in IT, that makes sense. But if you are feeling overwhelmed and/or having a difficult time, that is when I will have people just delete the DMARC and DKIM and focus on making sure the SPF record is correct. If you do that, make sure DKIM is turned off for the onmicrosoft.com domain in the M365 Security Admin Center - Under "Email & Collaboration", click on "Policies and rules", Threat Policies, Email authentication settings, DKIM tab, make sure it is off for each domain. With those steps, and a valid SPF record, email flow will be back to normal.

    CAUTION

    And as Ron has cautioned, be careful who you trust to help you with this. Your IT person, Website Host, Domain Registrar, are on the short list of people who might be able to assist. If you find that you don't have access to your own domain and your own domain's DNS records, that is something you might want to address as you should always have control over your own domain. When I take on a new client, if we don't have control over their domain, I typically will set them up with a GoDaddy (or other well known registrar) account and guide them through the process of transferring their domain into their own account so they have full control. Not something you want to tackle right now while you are having issues, but something to consider for the future.

    I'm subscribed to this topic and I'll chime in if I see that an issue hasn't been answered.

    -Brad

    Was this answer helpful?

    0 comments No comments
  2. Ron-6928 4,991 Reputation points
    2024-01-30T17:19:59+00:00

    >> I'm getting my emails now,

    Wait... SPF, DMARC and DKIM records are for outgoing email & to protect your email domain from getting used/spoofed by spammers to fool their victims. They're not for incoming mail so to speak. Incoming email from others to you should not be affected by the records. Were you having problem with incoming mail?

    Btw I have been on the receiving end of this free online help... many times. I'm just returning the favor to other strangers who need help. Good luck adding/editing your DMARC record.

    If you can't add DMARC/DKIM (thanks to Brad for mentioning it below), remove them all together from your DNS database for now. Take care of them later during off season or whenever you have time.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2024-01-30T17:02:07+00:00

    Ron, thanks... I feel relieved because I really didn't want to upset you! You are volunteering your time to total strangers!

    I saw your other post about the DMARC... thanks, I will try this next!

    As an aside, I found that it did not take 48 hours to see something happen this last time... I'm getting my emails now, slowly though; instead of instantly, they're taking about 4 hours to show up. Nevertheless, I'm getting some now!

    Thank you, thank you, thank you!

    Laura

    Was this answer helpful?

    0 comments No comments
  4. Ron-6928 4,991 Reputation points
    2024-01-30T16:04:34+00:00

    How about keeping it simple?

    v=DMARC1; p=none; rua=mailto:<email address where you want DMARC reports sent to>

    Your DMARC is still not found when I search for it. I suspect it is entered incorrectly.

    I think this clip can help (the clip shows how to add SPF record which you've already done): https://www.ipage.com/help/article/what-is-txt-record

    DMARC record should look something like this:

    Set TTL to 1 or 2 hours (or 60 to 120 minutes). Don't forget the underscore character before dmarc.

    Was this answer helpful?

    0 comments No comments
  5. Ron-6928 4,991 Reputation points
    2024-01-30T15:53:35+00:00

    >> It seems that you are under the impression I haven't done what you asked me to do, but I did! The SPF record was changed correctly except for the tilde vs hyphen question.

    No, that wasn't what I meant. I wanted you to decide for yourself whether to use ~ or -

    That's why I asked you to read it again to decide which one to use. As I said before, it can be tilde or dash/hyphen or question mark. You decide.

    Btw, your SPF now shows up as valid.

    >> I'm really sorry if I have upset you with trying to help me. I would pay someone here to fix it for me but the first place I would consider is a half hour away from my office.

    Whoooaaaa.... I am not upset at all and apology is not necessary. I'm more comfortable offering free help online where the public (and other experts) can read/see it. The reason? If I lead you astray (by trying to scam you if I were a bad guy) or if I'm wrong (I don't claim myself to know everything), other experts can jump in to stop me or correct me. Be very careful accepting help from strangers online. There are many wolves in sheep's clothing on the internet. Never give strangers permission to edit your DNS. They can do serious damage to your domain name.

    Was this answer helpful?

    0 comments No comments