Emails are delayed or fail from bigfish.com


Warning: Use of undefined constant user_level - assumed 'user_level' (this will throw an Error in a future version of PHP) in /homepages/13/d121821522/htdocs/mvt/wp-content/plugins/ultimate-google-analytics/ultimate_ga.php on line 524

PROBLEM:  When a user tries to send my organization an email, they will get an error message stating the the email has been delayed.  The exact message: “This message hasn’t been delivered yet. Delivery will continue to be attempted.”

After a few days, the user would get an error that the message has failed stating that the “Delivery has failed to these recipients or groups”

The frustrating part of this issue is that it doesn’t happen consistently.  The emails will successfully be delivered for days or even weeks and then the errors will rear their ugly heads once again.

Observations and what I have done to troubleshoot the issue:

  1. In all of the failed emails, the generating server was from the domain bigfish.com.  After a couple of google searches, I found out that this is part of the Office365 services.  In particular, the Forefront portion of the service.
  2. I whitelisted the email of the sender in our spam filter to make sure it wasn’t getting blocked on accident.  This did not fix our issue.  (our spam filter is a Mail Foundry appliance).
  3. I removed some outdated blacklist sites on the spam filter to improve SMTP response time.  Did not fix
  4. I put our spam filter in a DMZ to rule out our firewall.  Did not fix
  5. Per a suggestion from a fellow admin, I checked our DNS and made sure that our SPF record was setup setup properly.  Did not fix
  6. Worked with Mail Foundry tech support and confirmed with them that the email wasn’t even getting to the appliance, let alone rejecting the message.
  7. Changed ISPs.  We switched out ISP’s not because of this issue but just to change service and this didn’t fix the issue as well.

I have tried everything that I could think of so now I turn to anyone who might stumble on this post.  Hopefully, someone might be able to give me a suggest that I haven’t thought of yet.  So if you have a suggestion, please leave a comment.

SOLUTION:

UPDATE 4.13.14:  After working with another engineer who was working with Microsoft Forefront’s tech support, we found out that my firewall was blocking some of the originating servers.  This would explain why some mails would go through and some wouldn’t.  We had some Geographic/country related rules to block unwanted traffic.  Problem is that MS has servers all over the world.  So I created a white list for all the IP’s that Forefront uses(see below).  Once we did that, email seems to be passing much better.

Forefront IP ranges to white list:

65.55.88.0/24
94.245.120.64/26
207.46.51.64/26
207.46.163.0/24
213.199.154.0/24
213.199.180.128/26
216.32.180.0/24
216.32.181.0/24

Technet article regarding this fix…

Leave a comment

Your email address will not be published. Required fields are marked *