Three simultaneous auth failures silently blocked Gmail delivery for years
A transactional mail relay serving dozens of application hosts was silently failing to deliver emails, with thousands of messages bounced daily by Gmail. Three independent authentication issues were responsible: a missing v=spf1 SPF record, a broken reverse DNS setup where the PTR pointed to a different server, and OpenDKIM signing nothing due to a misconfigured table type that produced no error logs. Gmail's tightened bulk sender authentication requirements, enforced from February 2024 onward, turned a long-standing misconfiguration into an active outage, blocking critical emails including password resets. Each flaw masked the others, and because OpenDKIM logs no warning when it cannot match a signing key, the daemon appeared healthy while all outgoing mail left unsigned for an unknown period.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in