Hotmail users worldwide have problems sending emails, with messages flagged as spam or not delivered after Microsoft misconfigured the domain’s DNS SPF record.

The email issues began late last night, with users and admins reporting on Reddit, Twitter, and Microsoft forums that their Hotmail emails were failing due to SPF validation errors.

A Hotmail user explained in a post on Microsoft’s forum that their Microsoft Outlook Hotmail accounts were failing to send with the following error:

For Email Administrators
This error is related to the Sender Policy Framework (SPF). The destination email system’s evaluation of the SPF record for the message resulted in an error. Please work with your domain registrar to ensure your SPF records are correctly configured.

exhprdmxe26 gave this error:
Message rejected due to SPF policy – Please check policy for”

The Sender Policy Framework (SPF) is an email security feature that reduces spam and prevents threat actors from spoofing domains in phishing attacks.

To configure SPF, admins create a special DNS TXT (text) record for a domain that specifies the specific hostnames and IP addresses allowed to send emails under that domain.

When a mail server receives an email, it will verify that the hostname/IP address for the sending email servers is part of a domain’s SPF record, and if it is, allows the email to be delivered as usual.

However, if the IP address or domain of the sending mail server is not listed in the sender domain’s SPF record, it will either bounce the email back to the sender with an error or put it in the recipient’s SPAM folder.

After analyzing what was causing email delivery errors, admins noted that Microsoft removed the ‘‘ record from’s SPF record.

To illustrate the issue, the previous SPF record for was:

v=spf1 ip4: ~all

Hotmail’s current SPF record with removed is now:

v=spf1 ip4: -all

The SPF record contains a large list of hosts allowed to send an email for the domain, and with that record missing, any email from those senders will fail SPF checks.

BleepingComputer tested sending an email from an Hotmail account and replicated the problem, with our email going to Gmail’s SPAM folder instead due to its SPF record failing.

       dkim=pass header.s=selector1 header.b=Aoix6uEm;
       arc=pass (i=1);
       spf=fail ( domain of does not designate 2a01:111:f400:fe5b::808 as permitted sender);
       dmarc=pass (p=NONE sp=NONE dis=NONE)

This is because the allowed IPv6 address (2a01:111:f400) associated with that was used to send my email is designated in the record and, with its removal, is no longer accepted as valid.

Other hosts that will now fail SPF checks due to the removal of are:

Unfortunately, there is nothing that Hotmail users can do to fix this problem on their own, and they will have to wait for Microsoft to fix the DNS entry.

BleepingComputer has asked Microsoft about this change, but a reply was not immediately available.

Source link