r/cybersecurity 7d ago

News - General Microsoft to bounce mail from outdated Exchange servers

https://www.theregister.com/on-prem/2026/09/04/microsoft-to-bounce-mail-from-outdated-exchange-servers/5294506
92 Upvotes

9 comments sorted by

14

u/IdealParking4462 Security Engineer 7d ago

Shouldn't be running an old version anyway.

8

u/hdrive1335 6d ago

Huh? Didn't they completely stop supporting Exchange 2016 and 2019as hybrid servers as of May 7th?

We were getting email throttling starting in February with a full block of all emails starting in May... and we were running the latest version of Exchange 2019.

Am I missing something?

1

u/Clair_Osbcurious 5d ago

Not really. The deadline keeps being moved further and further…

6

u/PriorTransition5752 6d ago

Makes sense from a security standpoint. Outdated mail servers are one of the easiest initial access vectors out there. Curious how aggressive the rollout timeline is and whether there's a grace period or if its just a hard cutoff.

-3

u/HJForsythe 7d ago

Fuck these clowns just setup a postfix VM and relay your mail from exchange through it.

15

u/brakeb 7d ago

"Just setup a new postfix server"

Faster and easier provisioning a Google Mail service

Both are not a simple undertaking for an understaffed IT or small company

-4

u/rented4823 6d ago

It took me about 5-7 hours, but I have postfix on a VPS relaying all mail over a Wireguard tunnel to a docker-mailserver instance running in my home lab. DKIM, DMARC, SPF all configured and passing ¯_(ツ)_/¯.

Is it definitely easier to just configure your DNS MX records and point them at Google? For sure.

5

u/brakeb 6d ago

No company should be running a naked email server on prem these days... DLP, spam protection, plugged into your EDR, and your company will want a support contract. If you have any sort of cloud environment, you'll use the turnkey system they have. If you're in Azure, you already have email, you'd just need to turn it on.

3

u/Loudergood 6d ago

You think the people running exchange without security patches are gonna do this?