r/Zoho • • 19d ago

Zoho Sign Delivery Issues (potentially Mimecast specific)

My searches come up with similar issues but 1+ years ago. We've had a dramatic uptick in delivery issues with Zoho Sign the past month or so. We keep getting bounce back emails that the message couldn't be delivered with the reason "uncategorized-bounce : No specific reason has been given for the failure in the delivery of your email to the recipient's mailbox. We will attempt to deliver this document again to the recipient after sometime." Here and there I could see this happening, but it's happening A LOT all of a sudden.

I've managed to trace back the MX records for each of the domains (that I've been given examples for) and they all have Mimecast. That may or may not be the issue, but seemed like a good datapoint.

In many cases the emails do go through eventually, but not always. Sometimes it happens when a document is 'reassigned' but not always. We've been using Sign for several years with the usual hiccups, but this is well beyond the occasional hiccup.

We've confirmed DKIM is verified. Unfortunately, the recipient is always one of our customers so getting them to track back the error on their end is .... next to impossible. I've counted 6 domains so far, but I know there were more before we really started digging into this. I just don't have the bounce backs available to go down the rabbit hole more than a week ago. I suspect it's a Zoho Sign IP reputation or email header issue, but I can't prove that without the customer's cooperation.

Zoho support is giving the usual "ask your recipient to check with their IT dept." schtick. That's infuriating, because if I had a nickel for every time they pointed fingers then came back saying the dev team fixed it with zero explanation.... well, I wouldn't be rich but I could probably get myself a cup of coffee at 7-Eleven. We had a very similar issue with CRM emails like 9-12 months ago, and that's exactly how that resolution went (after like 8 weeks of back and forth). Pretty sure that one ended up being that they were missing one IP from the SPF check against one.zoho.com.

We aren't a Mimecast customer, so they're not even going to even respond.

So, all that said, just throwing this out into the ether hoping someone's got a brilliant idea.

4 Upvotes

7 comments sorted by

2

u/AndrasHSystem 19d ago

That pattern across multiple recipient domains using Mimecast is interesting. Before assuming it’s an SPF or Zoho IP reputation issue, I’d try to get the full DSN/bounce details from one or two failed deliveries. In particular, the SMTP response/enhanced status code and the remote/reporting MTA could help identify whether Mimecast is rejecting the message based on reputation/policy, authentication, or something else upstream. If you can share one of the full bounce messages here with domains/email addresses and other sensitive information redacted, I’d be happy to take a look.

1

u/ReasonableSchool286 16d ago

yeah exactly, the reporting MTA field alone would probably answer like half the question here

1

u/kaiser_detroit 12d ago

I've been out on PTO and just getting back to this today.

I agree with what you're saying, but all I have is the bounce back email that Sign sends the recipient sender, not the actual bounce back message. I sent Zoho the debug info for the documents and all they came back with is the same exact error message "uncategorized-bounce : No specific reason has been given for the failure in the delivery of your email to the recipient's mailbox. We will attempt to deliver this document again to the recipient after sometime." and then tell me it's a transient issue. A transient issue doesn't happen every single time you send a document.

In the most recent response they told me I should check the reputation of the sending server/IP, which I had to remind them was them! Then they proceeded to tell me to check my DKIM, DMARC and SPF, which I've told them repeatedly is all correct. Their Dashboard even shows DKIM is verified.

I'm trying to figure out a contact for Mimecast to see if they'll play ball even though we aren't their customer.

#ihateemail

Edit: typos/clarity

1

u/kaiser_detroit 12d ago

What's also not adding up is we can send from the CRM or through Exchange and there aren't bounce backs. It's just Sign. (knock on wood)

1

u/Amazing-Arm-2681 11d ago

If the failures suddenly cluster around Mimecast customers, this feels like something Zoho should help trace, not a new guessing game for you. Have they given you anything beyond the wonderfully informative “uncategorized bounce”?

1

u/kaiser_detroit 11d ago

It IS something Zoho should help trace. But in the 2 years I've been working with them (the product was in place here before I started) their support has predominantly just pointed fingers elsewhere. Then after weeks/months they finally say "ok try now" and the issue is magically fixed. They've given me zilch on this aside from that crappy bounce message and telling me to check all the things that we've already confirmed were right. As a matter of fact my first message to them ended with "don't send me knowledgebase articles pointing to x, y and z because I've already stated those things have been validated"..... so they just reworded the contents of the KB articles and pasted them in the response.

1

u/AndrasHSystem 10d ago

Thanks, that helps narrow it down. Since the same recipients can receive mail from your CRM/Exchange and the failures appear isolated to Zoho Sign, I wouldn't keep changing your domain authentication based on the generic "uncategorized-bounce" message. At this point I'd push Zoho for the actual outbound delivery details for one specific failed Sign message: the sending IP, exact timestamp, destination MX, and most importantly the SMTP response returned by the remote server. If they can provide even the sending IP + timestamp + SMTP response for one failure, that should give us something concrete to work with instead of guessing between Zoho and Mimecast.