External email to a mail forwarded user account (mail_user@med.umich.edu) will experience issues


Issue

The Michigan Medicine email forwarding service provided by HITS allows approved users to have their med.umich.edu mail forwarded to umich.edu.  Those approved for email forwarding no longer have a Michigan Medicine Outlook mailbox. 

As a result of this redirection, these email messages are no longer reviewed by the Michigan Medicine Microsoft environment and how they are reviewed during delivery is out of Michigan Medicine’s control.   

The forwarded messages get delivered to the campus email servers from the Microsoft 365 environment. This is a shared cloud environment, and the IPs are not unique to Michigan Medicine, so the system cannot remove the sending servers/IPs from scanning process as it would weaken email hygiene for any emails coming to them from any Microsoft 365 environment.  

Campus did make a change so that messages will now bypass the spam filter if they contain a valid DKIM signature from Michigan Medicine.  This should reduce the delivery time for forwarded messages. 

Users who have the email forwarding service enabled should inform their collaborators outside the university that future email should be sent to their umich.edu email address.  Messages sent directly to the @umich.edu domain will avoid the redirection process and should have fewer delivery delays. 

  

Example: User1@yahoo.com sends to mail_user@med.umich.edu 

In this example. the following may occur: 

1.  Mail Delivery delay (>8 hours) 

2.  Possible rejection (undeliverable) 

3. Delivered to junk/spam folder 

Technical background: This redirection breaks DKIM SPF and DMARC signatures in the messages that are forwarded.  The message is then considered as Spoofing. 

Environment

null

Cause

null

Resolution

null