> Am 12.05.2026 um 19:47 schrieb John R Levine via mailop <[email protected]>:
> 
>> As others have mentioned, this is a long-standing issue with Outlook.com
>> that seems to be related to internal DNS timeouts.
> 
> After some experiementation I can say it's more than that.  I tweaked my MTA 
> setting so if it gets that 5.7.515 response, it requeues the message up to 
> three times.

We did also some experiments, in our case

* eur.olc.protection.outlook.com always responded with 5.7.515 DKIM=fail.
* outlook-com.olc.protection.outlook.com, 
hotmail-com.olc.protection.outlook.com often accepted the affected mails after 
2-4 retries.


With some trial and error we identified the problem with our samples of mails: 
The affected mails had more than one Precedence header and theses headers were 
included in the DKIM signature. 

Excluding the Precedence header(s) from the DKIM signature or having only one 
Precedence header resulted in 100% acceptance rate.

Our conclusion is, that most of the Microsoft servers remove the additional 
Precedence header(s) before checking the DKIM signature and therefore break the 
signature.


Regards,
Bernhard

Attachment: smime.p7s
Description: S/MIME cryptographic signature

_______________________________________________
mailop mailing list
[email protected]
https://list.mailop.org/listinfo/mailop

Reply via email to