Mailgun forwarding can result in your domain being treated as spam
blog.rajivm.com
blog.rajivm.com
Mailgunner here, a couple of notes:
* The case outlined in this blog post is related to incoming email forwarding feature, not Mailgun outbound sending.
* General email forwarding case does not break Mailgun's DKIM signature.
* Forwarding is tricky as long as it modifies content and we have lots of edge cases with our customers, and we are always working on improving on edge cases like this one.
* This is an edge case where the email has been forwarded from Mailchimp -> Mailgun -> Gmail and we have some conflicting content with Mailchimp's original email causing the DKIM signature failure.
* Mailgun sending pipeline team is looking at the issue to get more detail about that.
Thanks everyone!
I've also been affected by this. Any course of action that I could take? I've been using the forwarding feature for a while, my setup is simply Cloudflare DNS -> Mailgun -> Gmail. Would be happy to provide my domain name if you need it!
I didn't have any problems with DKIM, though, or SPF. My problem was having to use a shared IP (part of the free plan) and sometimes getting an IP that was in one of the spam blacklists.
I'd add that https://www.mail-tester.com/ was INCREDIBLY useful when I was trying to diagnose problems.
Our company's email was 1.7/10 made some quick changes and now I'm 8.9
I couldn't have been happier with Mailgun a year or so ago. Currently, I have a bug filed and reported to them that impacts our business (as well as many others I'm sure), that has been outstanding since July. They still haven't acknowledged it - and all I get is stock responses linking to their broken documentation
Can anyone reccomend any alternatives? When we set up OpenRent in 2012, Mailgun was the best. Now I'm much less convinced - any feasible alternatives would be much appreciated.
Can you send me the ticket# so I can take a look?
Ticket: #69317 & #154021
In July we identified an issue where Mailgun -> ELB webhook communications are broken under ticket #65535. This has been pending action by Mailgun's team for 4 months now.
The recipient's server should always check if your email is authenticated (SPF, DKIM). If so, they should check if their user has emailed you in the past, and if so they should let your email through, to prevent it being marked as a false positive. They should try and do this even if your domain happens to land on a single DNS blacklist (or they should use a quorum of DNS blacklists).
We do it because (1) Mailgun is great, and (2) it supports catch-alls, so for example, /(.*)@foo.com/ goes to $1@bar.com. This allows our company to have one Google Apps account, but multiple email domains. Our DNS provider, Gandi, has email forwarding but not support catch-alls.
My understanding is that this is not precisely Mailgun's intended purpose, but that it's fine.
You can do this already with Google Apps by adding more domains to your account. If you are using a forwarding service into your primary domain, you run the risk of not being able to properly detect and filter spam from that forwarder (more configuration is required on gapp's side, which isn't always easy to get right).