Typical symptoms

  • NDRs and bounces550 errors, "hop count exceeded", relay rejections: the NDR rarely names the actual cause.
  • Delayed deliveryMessages arrive, but minutes or hours late; the delay almost always sits at one identifiable hop.
  • MisclassifiedInternal mail is treated as external, legitimate mail lands in junk or quarantine, spoofing gets through.
  • After changesSince the gateway swap, the certificate rollover or the migration, the mail flow behaves differently than expected.

Approach

  1. Pin down the symptomAffected routes, time window, message IDs; "mail is not arriving" becomes a verifiable finding.
  2. Secure the evidenceMessage trace, message tracking, full headers and NDRs, before anyone touches the configuration.
  3. Test the hypothesis in a controlled wayTargeted test messages over defined routes, one variable per test.
  4. Fix and proveThe correction, the proof over the same test route, and the documentation of why it happened.

Real-world examples