NDR and failed forward

%3CLINGO-SUB%20id%3D%22lingo-sub-1487533%22%20slang%3D%22en-US%22%3ENDR%20and%20failed%20forward%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1487533%22%20slang%3D%22en-US%22%3E%3CP%3EGetting%20lots%20of%20failed%20e-mail%20from%20the%26nbsp%3B%3CA%20href%3D%22mailto%3Ano-reply%40sharepointonline.com%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Eno-reply%40sharepointonline.com%3C%2FA%3E%26nbsp%3B.%3C%2FP%3E%3CP%3EWe%20have%20SharePoint%20Lists%20that%20generate%20notifications%20when%20items%20are%20changed%20as%20part%20of%20Employee%20notifications.%3C%2FP%3E%3CP%3ESeems%20to%20be%20mostly%20from%20the%20mail%20forwards%20some%20of%20our%20staff%20have%20set%20up%20going%20to%20Yahoo%20and%20other%20organizations.%20I%20believe%20that%20it%20is%20related%20to%20improper%20DMARC%20or%20DKIM%20records.%3C%2FP%3E%3CP%3EAccording%20to%20the%20%3CA%20href%3D%22https%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fmicrosoft-365%2Froadmap%3Ffilters%3D%26amp%3Bsearchterms%3D56361%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3EMicrosoft%20Roadmap%3C%2FA%3E%26nbsp%3Bthere%20are%20changes%20coming%20to%20change%20the%20sender%20ID%20%3CSTRONG%3EBUT%20it%20will%20not%20be%20enabled%20for%20Legacy%20SharePoint%20which%20is%20what%20we%20have.%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3EDoes%20anyone%20have%20any%20ideas%20on%20how%20to%20get%20the%20notifications%20from%20SharePoint%20to%20flow%20without%20being%20rejected%20by%20other%20recipient%20orgs%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1487533%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%20Online%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1491329%22%20slang%3D%22en-US%22%3ERe%3A%20NDR%20and%20failed%20forward%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1491329%22%20slang%3D%22en-US%22%3EHello%20Forest%2C%3CBR%20%2F%3E%3CBR%20%2F%3ECould%20you%20maybe%20post%20an%20example%20of%20a%20NDR%3F%3CBR%20%2F%3EThis%20should%20give%20you%20the%20reason%20and%20what%20I%20suspect%20is%20that%20the%20recipient's%20mail%20server%20checks%20the%20message%20based%20on%20the%20sender%20(%40sharepoint.com%2F%40microsoft.com)%20which%20fails%20of%20course.%3CBR%20%2F%3EAs%20there%20is%20no%20possibility%20to%20%22edit%22%20the%20message%20header%20or%20original%20sender%20I%20would%20advice%20you%20to%20change%20the%20behavior%20of%20the%20forwarding.%3CBR%20%2F%3EYou%20could%20add%20a%20Transport%20Rule%20which%20says%20%22If%20sender%20is..%22%20and%20then%20apply%20an%20action%20to%20it%20depending%20on%20your%20needs.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1491910%22%20slang%3D%22en-US%22%3ERe%3A%20NDR%20and%20failed%20forward%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1491910%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F399562%22%20target%3D%22_blank%22%3E%40PvB91%3C%2FA%3E%26nbsp%3B%3CFONT%20color%3D%22%23800080%22%3EThis%20one%20was%20rejected%20to%20to%20DMARC%20failure%20that%20may%20be%20because%20DMARC%20does%20not%20traverse%20on%20Forwards%20or%20Microsoft%20hasn't%20set%20DMARC%20on%20sharepointonline.com%20and%20the%20recipient%20domain%20%3CSTRONG%3EMIL%20is%20very%20strict%20about%20security.%3C%2FSTRONG%3E%3C%2FFONT%3E%3C%2FP%3E%3CDIV%20class%3D%22row%20marginBottom20%22%3E%3CDIV%20class%3D%22col-xs-11%22%3E%3CDIV%20class%3D%22font-size-18%20lia-indent-padding-left-30px%22%3E%3CSPAN%3E%3CBR%20%2F%3E%22Status%3C%2FSPAN%3E%3C%2FDIV%3E%3CP%20class%3D%22lia-indent-padding-left-30px%22%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3CDIV%20class%3D%22ng-binding%20lia-indent-padding-left-30px%22%3EOffice%20365%20received%20the%20message%20that%20you%20specified%2C%20but%20couldn't%20deliver%20it%20to%20the%20recipient%20(xxxxxxx%40mail.mil)%20due%20to%20the%20following%20error%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3CSTRONG%3EError%3A%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E550%205.7.1%20550%20%235.7.1%20DMARC%20unauthenticated%20mail%20is%20prohibited%3CBR%20%2F%3E%3CBR%20%2F%3EA%20non-delivery%20report%20(NDR)%20message%20was%20sent%20to%20no-reply%40sharepointonline.com.%20The%20NDR%20might%20provide%20more%20details%20about%20why%20the%20email%20message%20wasn't%20delivered%20and%20how%20to%20fix%20the%20issue.%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3CDIV%20class%3D%22row%20marginBottom20%20lia-indent-padding-left-30px%22%3E%3CDIV%20class%3D%22col-xs-1%20align-right%20icon%20wrench%20lia-indent-padding-left-30px%22%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%20class%3D%22col-xs-11%20lia-indent-padding-left-30px%22%3E%3CDIV%20class%3D%22font-size-18%20lia-indent-padding-left-30px%22%3E%3CSPAN%20class%3D%22ng-binding%22%3EHow%20to%20fix%20it%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%20class%3D%22ng-binding%20lia-indent-padding-left-30px%22%3E%3CDIV%20class%3D%22lia-indent-padding-left-30px%22%3EAsk%20the%20sender%20(no-reply%40sharepointonline.com)%20to%20follow%20the%20instructions%20in%20the%20NDR%20to%20fix%20this%20issue.%20The%20NDR%20might%20also%20include%20specific%20information%20for%20email%20admins.%20If%20the%20sender%20is%20unable%20to%20fix%20the%20issue%2C%20ask%20them%20to%20forward%20you%20the%20NDR%20and%20then%20follow%20the%20guidance%20for%20email%20admins.%22%3C%2FDIV%3E%3CDIV%20class%3D%22lia-indent-padding-left-30px%22%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%20class%3D%22lia-indent-padding-left-30px%22%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%3E%3CFONT%20color%3D%22%23800080%22%3EThis%20one%20was%20rejected%20by%20AOL.com%20(yahoo.com)%3C%2FFONT%3E%3C%2FDIV%3E%3CDIV%3E%3CDIV%20class%3D%22row%20marginBottom20%22%3E%3CDIV%20class%3D%22col-xs-11%22%3E%3CDIV%20class%3D%22font-size-18%20lia-indent-padding-left-30px%22%3E%3CSPAN%3EStatus%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%20class%3D%22ng-binding%20lia-indent-padding-left-30px%22%3EOffice%20365%20received%20the%20message%20that%20you%20specified%2C%20but%20couldn't%20deliver%20it%20to%20the%20recipient%20(xxxxxx%40aol.com)%20due%20to%20the%20following%20error%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3CSTRONG%3EError%3A%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E554%205.7.9%20Message%20not%20accepted%20for%20policy%20reasons.%20See%20%3CA%20href%3D%22https%3A%2F%2Fhelp.yahoo.com%2Fkb%2Fpostmaster%2FSLN7253.html%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fhelp.yahoo.com%2Fkb%2Fpostmaster%2FSLN7253.html%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EA%20non-delivery%20report%20(NDR)%20message%20was%20sent%20to%20no-reply%40sharepointonline.com.%20The%20NDR%20might%20provide%20more%20details%20about%20why%20the%20email%20message%20wasn't%20delivered%20and%20how%20to%20fix%20the%20issue.%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3CDIV%20class%3D%22row%20marginBottom20%20lia-indent-padding-left-30px%22%3E%3CDIV%20class%3D%22col-xs-1%20align-right%20icon%20wrench%20lia-indent-padding-left-30px%22%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%20class%3D%22col-xs-11%20lia-indent-padding-left-30px%22%3E%3CDIV%20class%3D%22font-size-18%20lia-indent-padding-left-30px%22%3E%3CSPAN%20class%3D%22ng-binding%22%3EHow%20to%20fix%20it%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%20class%3D%22ng-binding%20lia-indent-padding-left-30px%22%3E%3CDIV%20class%3D%22lia-indent-padding-left-30px%22%3EAsk%20the%20sender%20(no-reply%40sharepointonline.com)%20to%20follow%20the%20instructions%20in%20the%20NDR%20to%20fix%20this%20issue.%20The%20NDR%20might%20also%20include%20specific%20information%20for%20email%20admins.%20If%20the%20sender%20is%20unable%20to%20fix%20the%20issue%2C%20ask%20them%20to%20forward%20you%20the%20NDR%20and%20then%20follow%20the%20guidance%20for%20email%20admins.%3C%2FDIV%3E%3CDIV%20class%3D%22lia-indent-padding-left-30px%22%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%3E%3CFONT%20color%3D%22%23800080%22%3EAlthough%20the%20reference%20link%20does%20not%20specifically%20mention%20DMARC%2C%20it%20does%20give%20this%20explanation%2C%3C%2FFONT%3E%20%22%3CEM%3EYour%20message%20wasn't%20delivered%20because%20Yahoo%20was%20unable%20to%20verify%20that%20it%20came%20from%20a%20legitimate%20email%20sender.%3C%2FEM%3E%3CP%3E%3CEM%3EYour%20email%20failed%20one%20or%20more%20authentication%20checks%20that%20Yahoo%20uses%20to%20verify%20emails%20are%20truly%20sent%20from%20the%20domains%20they%20claim%20to%20originate%20from.%3C%2FEM%3E%22%3C%2FP%3E%3CP%3E%3CFONT%20color%3D%22%23800080%22%3EI%20know%20there%20is%20issues%20with%20DMARC%20and%20forwards%20but%20how%20is%20one%20supposed%20to%20tell%20recipients%20that%20the%20mail%20is%20legitimate%3F%3C%2FFONT%3E%3C%2FP%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1493725%22%20slang%3D%22en-US%22%3ERe%3A%20NDR%20and%20failed%20forward%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1493725%22%20slang%3D%22en-US%22%3EHello%20Forest%2C%3CBR%20%2F%3E%3CBR%20%2F%3EThe%20spam%20protection%20cannot%20be%20turned%20off%20because%20that%20would%20mean%20that%20a%20lot%20of%20spam%20would%20be%20passed%20through%20to%20the%20mailboxes.%3CBR%20%2F%3E%3CBR%20%2F%3EI'm%20afraid%20you%20will%20need%20to%20either%20disable%20the%20forwards%20on%20the%20mailboxes%20and%20tell%20users%20to%20look%20into%20their%20own%20mailboxes%20or%20set%20up%20mail%20flow%20rules%20which%20change%20the%20behaviour%20of%20the%20received%20message.%3C%2FLINGO-BODY%3E
Highlighted
Frequent Contributor

Getting lots of failed e-mail from the no-reply@sharepointonline.com .

We have SharePoint Lists that generate notifications when items are changed as part of Employee notifications.

Seems to be mostly from the mail forwards some of our staff have set up going to Yahoo and other organizations. I believe that it is related to improper DMARC or DKIM records.

According to the Microsoft Roadmap there are changes coming to change the sender ID BUT it will not be enabled for Legacy SharePoint which is what we have.

Does anyone have any ideas on how to get the notifications from SharePoint to flow without being rejected by other recipient orgs?

3 Replies
Highlighted
Hello Forest,

Could you maybe post an example of a NDR?
This should give you the reason and what I suspect is that the recipient's mail server checks the message based on the sender (@sharepoint.com/@microsoft.com) which fails of course.
As there is no possibility to "edit" the message header or original sender I would advice you to change the behavior of the forwarding.
You could add a Transport Rule which says "If sender is.." and then apply an action to it depending on your needs.
Highlighted

@PvB91 This one was rejected to to DMARC failure that may be because DMARC does not traverse on Forwards or Microsoft hasn't set DMARC on sharepointonline.com and the recipient domain MIL is very strict about security.


"Status

 

Office 365 received the message that you specified, but couldn't deliver it to the recipient (xxxxxxx@mail.mil) due to the following error:

Error: 550 5.7.1 550 #5.7.1 DMARC unauthenticated mail is prohibited

A non-delivery report (NDR) message was sent to no-reply@sharepointonline.com. The NDR might provide more details about why the email message wasn't delivered and how to fix the issue.
 
How to fix it
Ask the sender (no-reply@sharepointonline.com) to follow the instructions in the NDR to fix this issue. The NDR might also include specific information for email admins. If the sender is unable to fix the issue, ask them to forward you the NDR and then follow the guidance for email admins."
 
 
This one was rejected by AOL.com (yahoo.com)
Status
Office 365 received the message that you specified, but couldn't deliver it to the recipient (xxxxxx@aol.com) due to the following error:

Error: 554 5.7.9 Message not accepted for policy reasons. See https://help.yahoo.com/kb/postmaster/SLN7253.html

A non-delivery report (NDR) message was sent to no-reply@sharepointonline.com. The NDR might provide more details about why the email message wasn't delivered and how to fix the issue.
 
How to fix it
Ask the sender (no-reply@sharepointonline.com) to follow the instructions in the NDR to fix this issue. The NDR might also include specific information for email admins. If the sender is unable to fix the issue, ask them to forward you the NDR and then follow the guidance for email admins.
 
Although the reference link does not specifically mention DMARC, it does give this explanation, "Your message wasn't delivered because Yahoo was unable to verify that it came from a legitimate email sender.

Your email failed one or more authentication checks that Yahoo uses to verify emails are truly sent from the domains they claim to originate from."

I know there is issues with DMARC and forwards but how is one supposed to tell recipients that the mail is legitimate?

Highlighted
Hello Forest,

The spam protection cannot be turned off because that would mean that a lot of spam would be passed through to the mailboxes.

I'm afraid you will need to either disable the forwards on the mailboxes and tell users to look into their own mailboxes or set up mail flow rules which change the behaviour of the received message.