TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

iCloud Mail has DNS misconfigured?

180 pointsby wildekekabout 2 months ago

22 comments

Avamanderabout 2 months ago
They also started using new IPs without PTR records to send out mail. Though so has Microsoft just recently. Both heavily frown upon that when receiving mail themselves. Do as we say...
评论 #43512463 未加载
评论 #43514841 未加载
评论 #43512759 未加载
wildekekabout 2 months ago
So, Apple sends the wrong EHLO domain when trying to send emails out. This results in them dropping emails to their own users. Can't get past Apple's level 1 support. How can I get to someone that maintains their SMTP k8s cluster?
评论 #43512195 未加载
评论 #43511484 未加载
评论 #43513709 未加载
评论 #43514267 未加载
rreichel03about 2 months ago
A few years ago, when iCloud custom domains first launched, I found a bug where Apple would permanently cache the MX record. If an iCloud user had ever used a custom domain, future emails from iCloud to that domain would still get routed to their iCloud inbox—even if the domain’s MX record no longer pointed to Apple. They eventually fixed it, but didn’t think it deserved a bounty, which was a bit surprising.<p>I&#x27;m sure there&#x27;s a ton of interesting surface area here.
Polizeiposauneabout 2 months ago
This was mentioned earlier today on the mailop list:<p><a href="https:&#x2F;&#x2F;www.mail-archive.com&#x2F;mailop@mailop.org&#x2F;msg24300.html" rel="nofollow">https:&#x2F;&#x2F;www.mail-archive.com&#x2F;mailop@mailop.org&#x2F;msg24300.html</a><p>with a later response indicating that Apple was aware:<p><a href="https:&#x2F;&#x2F;www.mail-archive.com&#x2F;mailop@mailop.org&#x2F;msg24312.html" rel="nofollow">https:&#x2F;&#x2F;www.mail-archive.com&#x2F;mailop@mailop.org&#x2F;msg24312.html</a>
评论 #43514995 未加载
评论 #43513705 未加载
djhworldabout 2 months ago
I lost faith in iCloud custom domains a few months ago, I was receiving the usual marketing emails etc fine, but actual person to person emails? Sometimes replies would come through, other times nothing.<p>I thought at first people were just ignoring me, but when a company reached out to me over SMS to respond to a complaint I had, they said their email reply had bounced so was contacting me on SMS instead<p>Switched to fastmail at that point.
评论 #43514111 未加载
MisterBiggsabout 2 months ago
Is this new? I&#x27;ve been using icloud with a custom domain for about a year and just had my first failure today with an address that I&#x27;ve actively been talking to all week.
评论 #43512403 未加载
zeagleabout 2 months ago
I switched from migadu to iCloud to increase my bus factor for the family. It&#x27;s been interesting and a bit painful. For example I have a filter to forward emails from an &#x27;bothofus&#x27; alias to my spouse&#x27;s iCloud account at the same domain because there is no way to have a true alias --&gt; mailbox1, mailbox2. Sometimes iCloud bounces these emails from sent from itself.
评论 #43512137 未加载
jeffbeeabout 2 months ago
p00-icloudmta-asmtp-us-central-1k-100-percent-10.p00-icloudmta-asmtp-vip.icloud-mail-production.svc.kube.us-central-1k.k8s.cloud.apple.com is one hell of a name, though.<p>Did you try postmaster@apple.com, hostmaster@apple.com, or icloudadmin@apple.com (not traditional, but given in their docs)?
评论 #43511879 未加载
评论 #43511930 未加载
评论 #43512036 未加载
评论 #43512652 未加载
Galacoabout 2 months ago
iCloud Custom Domains &amp; Mail are filled with bugs. My favourite one is that if my custom email I want to register has EVER been associated with an Apple account, it can never be used as a custom domain, unless that domain is set to catch all; it is impossible to add that specific address; it just errors without any specific message. The original account was fully deleted; going to the arduous process they set up that takes weeks to actually delete the account.<p>Customer support is worthless for actual technical problems as usual for Apple. Fun extra regarding customer support; if you arrange a support call in a language not native to your region, they honor that, but that information is lost if they escalate the call; the callback is always in the national language, despite explicit requests over the phone during the callback schedule
评论 #43514590 未加载
ctippettabout 2 months ago
I had to give up trying to use iCloud for email. So many inbound emails would be silently dropped. I&#x27;ve also sent emails to @icloud.com addresses that the recipient never received.<p>The deliverability issues also apply to their Hide My Email feature. I frequently miss confirmation or verification emails after signing up with a @privaterelay.appleid.com address, so much so that I don&#x27;t even bother with it anymore.
评论 #43513100 未加载
jlund-molfeseabout 2 months ago
I&#x27;m seeing 10&#x2F;10 though, with a custom iCloud domain (&quot;Your hostname outbound.mr.icloud.com is assigned to a server.&quot;).<p>What&#x27;s different?
评论 #43515142 未加载
alfiedotwtfabout 2 months ago
This shows that email should die in a tyre fire and we all need to collectively move to something else… but we should have done this more than 10 years ago.<p>Email has SO many technical issues that if someone would have come out with email today, nobody would use it!<p>The ONLY thing going for it really is that it’s decentralised and has the network effect that almost everyone uses it. Bzzzt, I kid I kid!<p>Anyone under 25 will tell you they do NOT use emails and instead prefer instant message, and is email really decentralised? NO!! Try setting up your own relay and you’ll be dropped by any big service. Gmail+Outlook is basically a cartel with zero recourse!<p>Hmmm… could there even be a case of anti-trust given Gmail’s behaviour
评论 #43513891 未加载
diegoholiveiraabout 2 months ago
The only issue that I have with iCloud+ with my custom domain is about two gmail accounts which I don’t get mail from. It’s super weird.
评论 #43512634 未加载
indigodaddyabout 2 months ago
How do they not have an A record for it, kinda nuts<p><a href="https:&#x2F;&#x2F;dns-lookup.jvns.ca&#x2F;#p00-icloudmta-asmtp-us-central-1k-100-percent-10.p00-icloudmta-asmtp-vip.icloud-mail-production.svc.kube.us-central-1k.k8s.cloud.apple.com|A" rel="nofollow">https:&#x2F;&#x2F;dns-lookup.jvns.ca&#x2F;#p00-icloudmta-asmtp-us-central-1...</a>
FaridIOabout 2 months ago
I also use iCloud mail, mine looks slightly better (though not perfect): <a href="https:&#x2F;&#x2F;www.mail-tester.com&#x2F;test-n5b4ip8ey" rel="nofollow">https:&#x2F;&#x2F;www.mail-tester.com&#x2F;test-n5b4ip8ey</a>
评论 #43513390 未加载
aequitasabout 2 months ago
@wildekek, hi Willem. Nice seeing you here. Still in the mail business?
评论 #43515473 未加载
johnklosabout 2 months ago
The biggest problem with huge corporations is that sometimes it&#x27;s next to impossible to actually communicate with them. Does anyone have any good contacts at Apple?<p>I sent this more than two weeks ago:<p><pre><code> Date: Wed, 12 Mar 2025 22:56:55 +0000 (UTC) From: John Klos &lt;*******@klos.com&gt; To: apple.com-Admin@anonymised.email, apple.com-Tech@anonymised.email, Apple-NOC@apple.com, d*******@apple.com Subject: Issue with Apple&#x27;s SMTP delivery Hello, I&#x27;ve had several issues reported about email delivery from Apple. The error they have in common is this: Mar 12 21:38:17 daisy sm-mta[28249]: 52CLcCoi028249: ruleset=check_mail, arg1=&lt;*******@me.com&gt;, relay=p-west1-cluster6-host7-snip6-8.eps.apple.com [IPv6:2a01:b747:3003:204:0:0:0:47], reject=550 4.1.8 &lt;*******@me.com&gt;... Access denied. HELO does not resolve. (HELO p00-icloudmta-asmtp-us-west-1a-1.p00-icloudmta-asmtp-vip.icloud-mail-carry.svc.kube.us-west-1a.k8s.cloud.apple.com) Looking in to this, the resolution of &quot;p00-icloudmta-asmtp-us-west-1a-1.p00-icloudmta-asmtp-vip.icloud-mail-carry.svc.kube.us-west-1a.k8s.cloud.apple.com&quot; results in this list of MX: mx-in.g.apple.com mx-in-mdn.apple.com mx-in-hfd.apple.com mx-in-ma.apple.com mx-in-rn.apple.com mx-in-vib.apple.com mx-in-rno.apple.com mx-in-sg.apple.com All but two of these resolve to A records. Two of those, though, resolve to more MX: host mx-in-rno.apple.com mx-in-rno.apple.com mail is handled by 10 mx-in.g.apple.com. mx-in-rno.apple.com mail is handled by 20 mx-in-vib.apple.com. mx-in-rno.apple.com mail is handled by 20 mx-in-rno.apple.com. mx-in-rno.apple.com mail is handled by 20 mx-in-rn.apple.com. mx-in-rno.apple.com mail is handled by 20 mx-in-hfd.apple.com. mx-in-rno.apple.com mail is handled by 20 mx-in-sg.apple.com. mx-in-rno.apple.com mail is handled by 20 mx-in-mdn.apple.com. mx-in-rno.apple.com mail is handled by 20 mx-in-ma.apple.com. host mx-in-mdn.apple.com mx-in-mdn.apple.com mail is handled by 20 mx-in-mdn.apple.com. mx-in-mdn.apple.com mail is handled by 20 mx-in-sg.apple.com. mx-in-mdn.apple.com mail is handled by 10 mx-in.g.apple.com. mx-in-mdn.apple.com mail is handled by 20 mx-in-vib.apple.com. mx-in-mdn.apple.com mail is handled by 20 mx-in-rn.apple.com. mx-in-mdn.apple.com mail is handled by 20 mx-in-hfd.apple.com. mx-in-mdn.apple.com mail is handled by 20 mx-in-ma.apple.com. mx-in-mdn.apple.com mail is handled by 20 mx-in-rno.apple.com. This loop is a mistake and should be fixed. Additionally, RFC 5321 section 2.3.5 says that the name given in an EHLO &#x2F; HELO greeting should be an IP literal or a primary host name (&quot;a domain name that resolves to an address RR&quot;). The name given in the EHLO &#x2F; HELO exchange does not resolve to an address RR; it only resolves to an MX. While this is technically incorrect, the looping MX is the real issue. However, if you&#x27;re fixing the looping issue, you may want to consider fixing this issue at the same time. Please look in to this, and please let me know if you have any questions or need any additional information. Thank you, John Klos</code></pre>
eddythompson80about 2 months ago
So you created a proxy to an endpoint to an email from iCloud and something in the chain had a misconfigured DNS with the domain “p00-icloudmta-asmtp-us-central-1k-100-percent-10.p00-icloudmta-asmtp-vip.icloud-mail-production.svc.kube.us-central-1k”. It might as well be an issue with mail-testers.com or icloud.com<p>It’s impossible to tell from the shared page because both services are about DNS caching.
Adaptiveabout 2 months ago
iCloud custom domain, i&#x27;m scoring perfectly (other than mail message content which is irrelevant in this case). <a href="https:&#x2F;&#x2F;www.mail-tester.com&#x2F;test-cqf7rdktf" rel="nofollow">https:&#x2F;&#x2F;www.mail-tester.com&#x2F;test-cqf7rdktf</a>
评论 #43514164 未加载
wildekekabout 2 months ago
Update @12:16UTC: This seems fixed now! The 57.103.74.0&#x2F;24 block now had PTR records.
herghostabout 2 months ago
Mr Jenkinson will be here any minute now, chasing ambulances.
psauxabout 2 months ago
When you own a 17 net or 12 net, I think it comes as a given on extra txt records not needed. Totally not fair, but reality, and someone’s allowing it on the filtering side.