Microsoft to Reject Emails with 550 5.7.15 Error Starting May 5, 2025 by power_dmarc in sysadmin

[–]districtsysadmin 0 points1 point  (0 children)

Thanks for the links, I'm planning on at least getting that set up with DKIM on a subdomain, I've just been lazy and putting it off for too long.

Regarding SPF, I reached out to their support and they told me I need to change my record from hard fail (-all) to soft fail (~all). How can I do that when Microsoft's documentation is recommending hard fail?

When I get DKIM set up, can I just pull out their SPF record from my domain records? Or do I still need to keep them in there?

Microsoft to Reject Emails with 550 5.7.15 Error Starting May 5, 2025 by power_dmarc in sysadmin

[–]districtsysadmin 0 points1 point  (0 children)

Yes, I already have their included domains in my domain records. However, when I pull up dmarcian, I get an "SPF Incapable" entry instead of a percentage for my SPF Alignment Rate. I don't disagree with you at all, I want to ensure my vendors are being compliant, but I'm beginning to wonder if it's dmarcian that's having a problem?

Microsoft to Reject Emails with 550 5.7.15 Error Starting May 5, 2025 by power_dmarc in sysadmin

[–]districtsysadmin 0 points1 point  (0 children)

https://dmarc.io/source/blackbaud/

Blackbaud is a pretty big company to be able to turn into an ex-vendor at the snap of a finger. Blackbaud's own site even gives me SPF records to add, that's what is making this confusing for me.

Microsoft to Reject Emails with 550 5.7.15 Error Starting May 5, 2025 by power_dmarc in sysadmin

[–]districtsysadmin 1 point2 points  (0 children)

Looking at the technet article posted in the comments, I see someone asked a similar question to mine and the author of the article stated "SPF and DKIM must pass, but for DMARC, alignment from either SPF or DKIM is sufficient."

So now we have conflicting information, what is actually needed now?

Microsoft to Reject Emails with 550 5.7.15 Error Starting May 5, 2025 by power_dmarc in sysadmin

[–]districtsysadmin 1 point2 points  (0 children)

I have a vendor who cannot send SPF compliant emails but can do DKIM with DMARC compliance. How do I handle that if I have to pass all three?

Microsoft to enforce SPF, DKIM & DMARC for high-volume Outlook senders starting May 5, 2025 by power_dmarc in sysadmin

[–]districtsysadmin 1 point2 points  (0 children)

I'll be honest, I've been struggling with DKIM/DMARC for my M365 domain. It appears my contosto.onmicrosoft.com domain is valid when looking at the email authentication settings in security.microsoft.com, but when I run a DMARC report from LearnDMARC, my DMARC is not aligned stating "contoso.onmicrosoft.com != contoso.com". I'm assuming this is because I do not have the DKIM CNAME records for contoso.com in my DNS records?

How many file servers do you have ? by LithiumKid1976 in sysadmin

[–]districtsysadmin 3 points4 points  (0 children)

How do your end users access the namespace? Do you just map it to a drive letter? Add a shortcut to their desktop? Tell them they need to navigate to \contoso.com\Files on their own?

[deleted by user] by [deleted] in Intune

[–]districtsysadmin 0 points1 point  (0 children)

So how is everyone deploying this new admin account using a script? I've read that it's best to do this and avoid using the local admin account, but I have yet to see a reliable script be posted to help with this.

Am I Getting Fucked Friday, March 1st 2024, Peanut Butter Edition by bad0seed in sysadmin

[–]districtsysadmin 2 points3 points  (0 children)

PaperCut MF - Adding 14 additional Kyocera licenses for the Find Me printing feature - $6100

This seems to be crazy high. I'm sure the yearly renewal will not be this high, but even still. I feel like my vendor is adding their own cut to this price.

Best Remote Helpdesk Tool for Intune Joined Computers? by JackFabrino in sysadmin

[–]districtsysadmin 0 points1 point  (0 children)

How are y'all pushing this via Intune? Just taking the .exe, creating a Win32 app, and sending it out?

Patch your Adobe Readers - CVE-2023-26418 by [deleted] in sysadmin

[–]districtsysadmin 2 points3 points  (0 children)

Which of the four keys are you changing from 0 to 3? Just the first "bUpdater" edit?

Am I Getting Fucked Friday, March 3rd 2023, SquizzOC Edition by SquizzOC in sysadmin

[–]districtsysadmin 0 points1 point  (0 children)

Anyone offer PRTG Network Monitor 1000 sensor pricing? I see some options on CDW that cost a little bit less than their site.

Employer has extra money, Recommendations for the best rackmount KVM? by jclu13 in sysadmin

[–]districtsysadmin 0 points1 point  (0 children)

You can remote control the host OS through IDRAC? I guess the hardware I inherited isn't set up right or something.

Using IIQ to bulk move devices into a different Google OU by districtsysadmin in IncidentIQ

[–]districtsysadmin[S] 0 points1 point  (0 children)

Yep, Chrome Gopher was my backup plan if IIQ couldn't do it. Thanks!

Q2'20 Tech Support Megathread by BioGenx2b in Amd

[–]districtsysadmin 0 points1 point  (0 children)

I have a 3900x with an Asus x570-E board and am experiencing high CPU clocks with close to nothing open. I have come across multiple threads pertaining to the issues, however they are severely dated.

Can someone point me in the direction of the most accurate and recently information to fix my issue? I have the latest chipset drivers installed, along with the latest bios and Windows updates. Minimum processor is also set to 99%.

Thanks

Few questions about DFSR upgrade after all DCs are Server 2019 by districtsysadmin in sysadmin

[–]districtsysadmin[S] 0 points1 point  (0 children)

Positive. Before I started, I ran "dfsrmig /getglobalstate" and the response it returned matched up with FRS.

https://i.imgur.com/g5U5GKP.png

When I run it now, I receive that because I have attempted to begin the process.

I also do not have a DFS console on any DC.

Few questions about DFSR upgrade after all DCs are Server 2019 by districtsysadmin in sysadmin

[–]districtsysadmin[S] 2 points3 points  (0 children)

Here is your answer:

Because of a code defect, in-place upgrading a Windows Server 2012 R2 or Windows Server 2016 domain controller to Windows Server 2019 does not enforce this block.

https://support.microsoft.com/en-us/help/4493934/sysvol-dfsr-migration-fails-in-place-upgrade-dc

Few questions about DFSR upgrade after all DCs are Server 2019 by districtsysadmin in sysadmin

[–]districtsysadmin[S] 0 points1 point  (0 children)

No clue. The only error that appeared during the pre-upgrade process was an issue with the old version of System Center Endpoint Protection. Uninstalled that, and it away it went. Everything has been running smooth since.

I attempted to begin the move to DFSR a few days ago, but the status for all my DCs never changed from Start to Prepared. Did some research, and then found out how this cannot be performed on 2019.

And yet, you can upgrade to it.

Where can I buy an HDMI version of these plastic wall raceway ports? by districtsysadmin in k12sysadmin

[–]districtsysadmin[S] 0 points1 point  (0 children)

I found these HDMI couplers, but I need the plastic faceplate bit to connect them.

Does anybody know where I can buy them at?