Using Classic Outlook on Windows for personal email, calendar, and contact management
Hello Peeps,
I had this problem and got help solving. Create a DNS TXT record: v=spf1 include:spf.protection.outlook.com -all
Instant Gratification.
Good Luck
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Starting this week, our emails to yahoo and aol accounts are not being delivered, but emails to other email accounts are working. Here is one of the yahoo error message: 1/12/2024 9:27:16 PM - Server at SJ2PR02MB10076.namprd02.prod.outlook.com returned '550 5.4.300 Message expired -> 421 4.4.2 Connection dropped due to SocketError' 1/12/2024 9:26:15 PM - Server at mta5.am0.yahoodns.net (67.195.204.73) returned '421 4.4.2 Connection dropped due to SocketError'
And here is the aol error message: 1/12/2024 9:27:38 PM - Server at PH0PR02MB7367.namprd02.prod.outlook.com returned '550 5.4.300 Message expired -> 421 4.4.2 Connection dropped due to SocketError'
1/12/2024 9:15:15 PM - Server at mx-aol.mail.gm0.yahoodns.net (67.195.204.80) returned '421 4.4.2 Connection dropped due to SocketError'
Using Classic Outlook on Windows for personal email, calendar, and contact management
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
Hello Peeps,
I had this problem and got help solving. Create a DNS TXT record: v=spf1 include:spf.protection.outlook.com -all
Instant Gratification.
Good Luck
Brad, thank you for your reply. I do, usually, have access to my DNS settings, but there was a hiccup, maybe, whereby I was unable to edit for a a period of time. I seem to be able to do the edits again, now. I do have a convoluted email control situation, though. GoDaddy now has my domain, but my DNS settings are controlled by iPage who provides my web site (they are the ones who do not seem to know what to do with my DNS settings.) It's been a long story, but I'll be trying to fix the DMARC a bit later today, when things settle down with clients.
Laura
Yes, I was "off" on my comment; so sorry for the confusion! I was having problems with outgoing emails being delivered; my incoming emails are fine.
I'll just chime in here again with a few general pointers. I'm on the road most days, so I can't respond in a very timely manner most of the time, and Ron is giving good guidance.
SPF - OR ~
My apologies if this was covered, when adding a hyphen or a tilde at the end of the SPF record, tells email servers what to do when they receive email from your domain from a source not specified in the SPF. A hyphen will cause the receiving email server to reject it altogether. A tilde will cause the message to get marked as spam and usually goes into their spam filter / folder / junk email / etc. Since your regular emails you send should all come from a host that IS specified in the SPF, it really doesn't matter what you select. I use the tilde option myself, and that should work well for most.
DMARC / DKIM
Having an incorrect DMARC or DKIM record is worse than not having one at all. Yes, you should have all 3, and for people in IT, that makes sense. But if you are feeling overwhelmed and/or having a difficult time, that is when I will have people just delete the DMARC and DKIM and focus on making sure the SPF record is correct. If you do that, make sure DKIM is turned off for the onmicrosoft.com domain in the M365 Security Admin Center - Under "Email & Collaboration", click on "Policies and rules", Threat Policies, Email authentication settings, DKIM tab, make sure it is off for each domain. With those steps, and a valid SPF record, email flow will be back to normal.
CAUTION
And as Ron has cautioned, be careful who you trust to help you with this. Your IT person, Website Host, Domain Registrar, are on the short list of people who might be able to assist. If you find that you don't have access to your own domain and your own domain's DNS records, that is something you might want to address as you should always have control over your own domain. When I take on a new client, if we don't have control over their domain, I typically will set them up with a GoDaddy (or other well known registrar) account and guide them through the process of transferring their domain into their own account so they have full control. Not something you want to tackle right now while you are having issues, but something to consider for the future.
I'm subscribed to this topic and I'll chime in if I see that an issue hasn't been answered.
-Brad
>> I'm getting my emails now,
Wait... SPF, DMARC and DKIM records are for outgoing email & to protect your email domain from getting used/spoofed by spammers to fool their victims. They're not for incoming mail so to speak. Incoming email from others to you should not be affected by the records. Were you having problem with incoming mail?
Btw I have been on the receiving end of this free online help... many times. I'm just returning the favor to other strangers who need help. Good luck adding/editing your DMARC record.
If you can't add DMARC/DKIM (thanks to Brad for mentioning it below), remove them all together from your DNS database for now. Take care of them later during off season or whenever you have time.