Archive for April, 2014

AOL email policy changes to match Yahoo

April 25, 2014

Effective April 22, AOL has changed their email policy to tell other email servers if you see mail from a AOL user, but AOL didn’t send it, please do not deliver it.   This follows a similar change from Yahoo about a week ago.  Read more about the Yahoo change here.

 

What does this mean for you?

It means that you can NOT use a AOL email address as the contact email for your store.  If you do your email will not be accepted at over 90% of the worlds email servers.   If you are currently using an AOL email as your stores contact email this must be changed immediately.  If you are using one of the above as your contact email domain most of your email is being rejected as of a few days ago.

 

What do I need to do to fix this?

If you have a AOL.com address as your stores contact email change it immediately.  You can use an email address matching your domain name or another free email service if you choose.  This can be changed/viewed at General–>Contact Us.   Please note that although you can potentially use a Gmail or Hotmail or other free email provider it is NOT recommended.  The general consensus is that soon those and other free providers will be restricting email sent just like Yahoo and AOL are now doing.

 

Can I send email to AOL users?

Yes, this does not impact sending TO AOL addresses, only sending FROM AOL addresses.

 

What domain names does this encompass?

So far, AOL, Yahoo, Ymail and Rocketmail.  The predication is that Gmail and Hotmail etc will soon follow suite so switching to another free email service is probably not a good idea.

 

Is this a StoreSecured issue?

No, this is a fundamental change to the way AOL and Yahoo email works.  It is impacting the entire internet and not just us.  We are seeing this as a fundamental shift in the way larger providers are working to stop spam.

 

Further Information and links to help explain the issue

http://blog.aol.com/2014/04/22/aol-mail-takes-action-against-email-spoofing/

http://postmaster-blog.aol.com/2014/04/22/aol-mail-updates-dmarc-policy-to-reject/

Advertisements

Microsoft Email Block Removed

April 21, 2014

As of yesterday 4/20 at 5:32pm Pacific Microsoft is once again accepting our email.

 

So far we have received no communication from Microsoft stating that the block was removed however this does appear to be the case.  All messages are being delivered as normal.

 

After reading the previous blog posts about the block if you have any additional questions about the block and/or undeliverable messages please direct them to our help desk at storesecured.desk.com or support email, ie support@storesecured.com

 

 

 

 

 

Yahoo Email’s New Policy: For Yahoo Email Users

April 20, 2014

Yahoo has recently added a new email policy that tells other email servers if you see mail from a Yahoo user, but Yahoo didn’t send it, please do not deliver it.   This is a huge change to the way that email has always worked.  

 

What does this mean for you?

It means that you can NOT use a Yahoo, YMail, or Rocketmail email address as the contact email for your store.  If you do your email will not be accepted at over 90% of the worlds email servers.   If you are currently using one of the above domains as your stores contact email this must be changed immediately.  If you are using one of the above as your contact email domain most of your email is being rejected as of a few days ago.

 

What do I need to do to fix this?

If you have a yahoo.com address as your stores contact email change it.  You can use an email address matching your domain name or another free email service if you choose.  This can be changed/viewed at General–>Contact Us.

 

Can I send email to Yahoo users?

Yes, this does not impact sending TO yahoo addresses, only sending FROM yahoo addresses.

 

What domain names does this encompass?

So far, Yahoo, Ymail and Rocketmail.  The predication is that gmail and hotmail etc will soon follow suite.

 

Is this part of the reason for the Microsoft block?

Yes, part of the reason we have been blocked by Microsoft is due to the much higher than normal bounce rate caused by these new Yahoo restrictions.  For further information about our Microsoft email block please see https://blog.storesecured.com/2014/04/20/details-about-the-microsoft-block/

 

Is this a StoreSecured issue?

No, this is a fundamental change to the way Yahoo email works.  It is impacting the entire internet and not just us.

 

Further Information and links to help explain the issue

 http://blog.returnpath.com/blog/christine-borgia/all-about-yahoos-dmarc-reject-policy

http://yahoomail.tumblr.com/post/82426900353/yahoo-dmarc-policy-change-what-should-senders-do

http://www.spamresource.com/2014/04/up-in-arms-about-yahoos-dmarc-policy.html

Details about the Microsoft email blocking

April 20, 2014

What does the block mean?

We have received several questions about what it means to be blocked by Microsoft and what emails are not going out.  Any emails sent from our service to any of the email services owned by Microsoft are being rejected.  This means that emails to hotmail.com, live.com, msn.com, outlook.com and microsoft.com are all being rejected as well as other country variations such as .co.uk etc.   This includes all automatic notifications, newsletters and any email sent manually (if you use our email services).   If you use the StoreSecured email services you will receive a bounce back message stating that the email was rejected.  If you use an outside email service the bounce back cannot sent.

 

When did the block start?

The email blocking began on 4/18 at 15:25pm Pacific time.

 

When will the issue be resolved?

We had several good emails back and forth with Microsoft yesterday regarding the block and getting it removed.  Unfortunately we have to rely on Microsoft to communicate with us and then unblock us and they have only email support.   Getting a block removed takes lots of time, effort, research and patience.  We were hoping for resolution today but have received no response since last evening, which is probably be due to the Easter holiday, we are probably looking at Monday at the earliest now.   Please be patient with us as we work to remove the block as quickly as possible.

 

How can I send these emails in the meantime?

The only alternatives are to send emails by using an external email service, ie one not hosted by StoreSecured or by waiting until the block is removed and then resending.

 

 

Can I still receive emails from these domains?

Yes, all email is arriving as normal from the Microsoft domains.

 

 

Why were we blocked?

This is a complicated question to answer since there are many factors but basically the percentage of failed emails to successful emails exceeded some internal Microsoft threshold making them think that some of our users were doing some bad things (from our research nothing was malicious).  This was caused by a variety of factors occurring simultaneously including:

  • several of our users sent out emails to large lists that included a very high percentage of undeliverables
  • several of our users were setup to forward email to Microsoft domain names which no longer exist causing many undeliverables
  • a couple of our users were rate limited by Microsoft for exceeding normal thresholds (ie they sent high quantities of mail than normal) and the emails kept trying to be sent causing many undeliverables
  • a Yahoo policy change was put in place which no longer allows other email providers to send email using a yahoo.com domain name unless they are in fact Yahoo.  This has caused all of these emails to be undeliverable.  More on this shortly but note that due to a change at Yahoo, we can no longer send email using a from address from Yahoo.  This is internet wide and not restricted to StoreSecured, please see the following article for more information http://blog.returnpath.com/blog/christine-borgia/all-about-yahoos-dmarc-reject-policy

 

Why are you now not allowing automatic email forwarding to Microsoft domain names?

Please see above in the why were we blocked area and note that a large part of the reason that we were blocked by Microsoft is due to these email forwards to Microsoft domain names.  Additionally it is against Microsoft’s email policy best practices to forward email automatically from another service.

 

What can I do to help ensure this does not happen again?

  • Make sure that your email list is clean, promptly remove emails which are returned as undeliverable from marketing and newsletter lists
  • Send bulk emails using approved list methods such as the newsletter function and the built in Smartermail list management and sending
  • Use a strong password for email, ie at least 7 characters long including numbers, special characters and upper and lower case characters
  • Do not automatically forward email to an outside service, especially with spam emails included
  • Never buy email lists, only include people who have actually subscribed
  • Immediately remove people who request to be removed from marketing lists
  • Include a privacy policy on your website
  • If you receive a message that you are rate limited by a service do not continue to send out large volumes of emails until the rate limit is removed
  • Do not use a Yahoo.com email address as your store’s email.  All of your emails will be undeliverable.  For more information see: http://blog.returnpath.com/blog/christine-borgia/all-about-yahoos-dmarc-reject-policy

Emails Blocked by Microsoft

April 19, 2014

Currently all email from both StoreSecured email servers is being blocked by the Microsoft network.  This includes domain names such as hotmail, live.com, msn.com and microsoft.com.  We are working as quickly as possible to resolve the issue but resolution depends on a manual unblock by Microsoft staff.

 

Mail sent to any of these domain names will be returned with an error message similar to below:

550 SC-002 (COL0-MC3-F4) Unfortunately, messages from 74.205.16.101 weren’t sent. Please contact your Internet service provider since part of their network is on our block list. You can also refer your provider to http://mail.live.com/mail/troubleshooting.aspx#errors.

 

We are currently working to get the block removed, determine why we were blocked, as well as evaluate other alternatives and options to get these types of messages delivered.  Please note however that an alternative mail server has already been used and has been blocked as well.

 

While the block is in place from microsoft the only way to deliver messages to email addresses in these domain names would be by sending out the email through an alternate service.

Further updates will be posted here once available.

 

Update 4:00pm

We are in active conversations with Microsoft regarding this issue and expect a resolution within the next 24 hours.

Effective immediately email can NOT be setup to be forwarded to any Microsoft owned domain name.  This includes but is not limited to microsoft.com, hotmail.com, live.com, msn.com, outlook.com etc.  New email forwards cannot be setup to any of these domain names and existing forwards to these domain names will be disregarded.  These forwards are causing us many issues relating to the email blocking at Microsoft.  Note this does not mean that we will not send email to these domain names, it means that you cannot setup your email to automatically forward new messages to these locations.

Scheduled Maintenance 4/18 9:00pm

April 18, 2014

Scheduled maintenance period Friday 4/18 9:00pm-10:00pm PST for load balancer update/preventative maintenance.

 

During the maintenance window there will be expected downtime of between 15 minutes – 60 minutes which  all store websites will be temporarily unavailable.  The admin services, ftp and email will remain operational.

 

Update 9:55pm

The maintenance is complete.  It took longer than expected but all sites are now back up and running.  We are sorry for the delay a few issues were encountered during the update.

 

New Feature: Order Export Summary

April 17, 2014

All stores now include the ability to export order summary information.  This feature is in addition to the existing order detail export.  The order summary export will include 1 line per order with summary information for the order vs the order detail export which includes 1 line for each item in the order.

 

To export order summary information please visit Orders–>Search

Select the criteria for the orders you wish to export using the order search boxes.

Select the Export Summary button

The file will be created and then a link will be shown to download the file

 

We have attempted to keep the order summary export as close as possible to the specification for the order detail export for those who which to switch and/or use both.  All order summary type information from the order detail export has been kept in the same columns.

 

Columns in detail export and NOT in summary export

  • Item_id
  • Item_SKU
  • Item_Name
  • Additional Quantity

 

Columns ADDED to summary export

  • Shipping
  • Ship Weight
  • Taxes
  • Coupon
  • Gift Certificate
  • Sub total
  • IP Address
  • Referrer
  • Residential

Scheduled Maintenance 4/12 10:00pm

April 11, 2014

Scheduled maintenance period Saturday 4/12 10:00pm-11:00pm PST for firewall replacement.

 

During the maintenance window all services, ie mail, ftp, websites, admin interface etc will be temporarily unavailable as the old firewall is turned off and the new one is started.   The downtime  is expected to last between 5 and 15 minutes.

Re: OpenSSL security threat status

April 9, 2014

We have recently received several inquires asking if StoreSecured was affected by the OpenSSL security flaw that was recently discovered.  The answer is no, we are not affected.  StoreSecured uses Windows servers and as such we do not utilize OpenSSL and are NOT affected by this security issue.

 

If you have not heard about the OpenSSL issue and want to read more please visit:

http://techcrunch.com/2014/04/07/massive-security-bug-in-openssl-could-effect-a-huge-chunk-of-the-internet/

New Feature: Restrict Login by IP

April 4, 2014

All stores now include the ability to restrict admin login by IP or range of IPs.  This feature is useful for store admins who want to restrict employees from logging in outside of the office location.

 

To restrict the login for a particular login please visit

My Account–>Admin Logins–>View/Edit

Click on the Edit link for the login to restrict

In the area labelled Login Access choose the radio button to restrict the login by IP or IP range

Enter the IP or range of IPs

Select the Save this Login button

 

If an IP restriction is in place the user will not be able to login if they are not at a valid IP.

 

**Note that an IP restriction cannot be placed on the main admin for the store.