Immediate bounce back 550.5.7.705 Tenant has exceeded threshold.

thecomputerguy

Well-Known Member
Reaction score
1,366
Client is getting immediate bounce backs through two different domains, both hosted at Godaddy, both with O365 through Godaddy.

Logged into the accounts and immediately changed the password for both accounts. Hopped into the EAC expecting the mailboxes to be sitting in quarantine which they were not.

DNS is fine.

Called Godaddy and they said the same thing, they expected the boxes to be in quarantine but because they are not in quarantine it's possible that he was hacked at a "Deeper" level in which case it is something Microsoft will need to fix on their end at the tenant level which could take up to 72 hours.

Client is going to lose his **** if he has to wait 3 days for email. Client says he has not opened any emails that required login and/or compromising his account.

Issue persists through webmail as well.
 
There are nothing in connectors, and unfortunately since his email is at Godaddy I don't have full access to the admin center.
 
Godaddy forwarded to MS and they say it could take 5-7 days for a tenant release.

Got him setup with a temporary Gmail account for the time being ... lame
 
This is why you don't host mail with godaddy. If you had full admin access you could fix this yourself:

Yeah. That's why I really hate it when a customer has picked Godaddy for O365, very limited access to the admin side. Fortunately it's only one so the pain is minimized.

And to be sure @thecomputerguy they're not doing any mailing lists?
 
It would be 5-7 days even if they were on direct with Microsoft. I've seen this fault happen and take TWO WEEKS to clear up.

This happens when MULTIPLE mailboxes in an organization exceed 50,000 egress emails in a day.

The above link is a good one, pay attention to ALL the steps. You need to reset every mailbox password AND deploy MFA... NOW. The domain has been hit once, it will be a larger target going forward.

At least now it only prevents send... it used to prevent send AND receive.

P.S. 2FA his Godaddy account too while you're at it, because they're probably in there too.
 
It would be 5-7 days even if they were on direct with Microsoft. I've seen this fault happen and take TWO WEEKS to clear up.

This happens when MULTIPLE mailboxes in an organization exceed 50,000 egress emails in a day.

The above link is a good one, pay attention to ALL the steps. You need to reset every mailbox password AND deploy MFA... NOW. The domain has been hit once, it will be a larger target going forward.

At least now it only prevents send... it used to prevent send AND receive.

P.S. 2FA his Godaddy account too while you're at it, because they're probably in there too.
@Markverhyden

@nlinecomputers

Yeah O365 through Godaddy was not my choice, I learned a long time ago when I first started implementing MFA that Godaddy was horrible because there is no direct access to the admin side of the account and Godaddy slaps their skin on top of the MFA which I'm sure doesn't do anything except complicate things.

@Sky-Knight

I followed all the steps to clear it up and MFA is on everything he owns now, including his Godaddy account.
 
With "normal" O365 Exchange you can get into the security center and see login attempts on a per account basis. Just had to do this with a customer who fell for an O365 outage phishing attempt. Fortunately she entered the wrong password so I was able to show her the failed logins. But we changed it anyways.
 
Back
Top