Prompt
How do I investigate intermittent email delivery?
Latest observation
Investigating intermittent email delivery is mostly about figuring out where the failure happens: sender, your mail server, the recipient’s server, or a spam/filtering layer in between. Here’s a practical way to work it.
1) Define the problem clearly
Start by gathering:
- Which messages are affected
- All mail, or only specific recipients/domains?
- Only attachments? Only certain subjects/content?
- What “intermittent” means
- Random delays?
- Some messages never arrive?
- Delivery varies by time of day?
- Who is affected
- One sender, many senders, one recipient, many recipients?
- Time window
- Exact timestamps for successful and failed attempts
2) Check whether the message actually left your system
Look for evidence that your mail system accepted and queued the message:
- SMTP logs on the sending server
- Mail transfer agent logs
- Message trace / tracking tools in your mail platform
- Outbound queue status
You want to answer:
- Was the message submitted?
- Was it accepted for delivery?
- Was it handed off to the destination server?
- Was there a bounce/NDR?
3) Inspect bounce messages and SMTP responses
If a message fails, the error often tells you why:
- 4xx = temporary failure, usually retryable
- 5xx = permanent failure
Common examples:
421/451/452→ temporary issues, greylisting, rate limiting, overloaded server550/554→ blocked, spam policy, invalid recipient, reputation issues
If mail is delayed intermittently, look for:
- Greylisting
- Deferred due to reputation/rate limits
- DNS lookup failures
- Connection timeouts
- TLS negotiation issues
4) Check mail flow path and filtering
Intermittent issues often happen in one of these layers:
- Spam filtering / security gateway
- Outbound relay
- Recipient-side filtering/quarantine
- Mailbox rules or client-side rules
- Transport rules / routing
Verify whether messages:
- Are being delivered to inbox
- Are landing in spam/quarantine
- Are being rejected at SMTP time
- Are accepted but later removed or redirected
5) Compare successful vs failed messages
Look for patterns in:
- Recipient domain
- Recipient mailbox
- Sender address/domain
- Message size
- Attachments
- Links or keywords in content
- Authentication results:
- SPF
- DKIM
- DMARC
If failures correlate with certain content or recipients, that points to filtering or reputation issues.
6) Verify DNS and authentication
Bad or inconsistent DNS/auth often causes sporadic delivery problems:
- SPF record valid and not too broad?
- DKIM signing consistent?
- DMARC policy aligned?
- MX records correct?
- Reverse DNS (PTR) set for outbound IP?
- A/AAAA records resolving properly?
- TLS certificate issues?
Intermittent DNS resolution problems can also cause time-based failures if resolvers or upstream DNS are unreliable.
7) Look for throttling or rate limits
Mail systems may temporarily defer mail if:
- Too many messages are sent in a burst
- Same recipient/domain is targeted repeatedly
- The sending IP has a poor reputation
- The recipient server enforces per-IP or per-domain limits
Signs:
- Messages eventually deliver after retries
- Logs show “deferred,” “temporarily rejected,” or “try again later”
8) Check queue health and server resources
On your mail server, intermittent delivery may come from resource issues:
- Disk full or near full
- High CPU
- Memory pressure
- Queue backlog
- Stuck SMTP sessions
- Antivirus or content filter timeouts
If mail delays happen during busy periods, resource constraints are a strong suspect.
9) Use message tracing and headers
If you have access to the recipient or can ask them, inspect:
- Full email headers
- Received chain
- Authentication-Results
- Spam/quarantine headers
Headers can show:
- Which servers handled the message
- Delays between hops
- Whether SPF/DKIM/DMARC passed
- Whether content filtering marked it as spam
10) Reproduce with controlled tests
Send test messages:
- From the same sender account
- To the same recipient/domain
- With and without attachments
- Plain text vs HTML
- Small vs large message
- Different subjects/content
This helps determine whether the issue is:
- Content-related
- Size-related
- Recipient-specific
- Time-dependent
11) Correlate with external factors
Check whether the problem aligns with:
- Network outages
- DNS incidents
- Firewall changes
- Mail server updates
- Spam policy changes
- IP reputation changes
- Blacklist listings
12) If you’re on a hosted platform
Use the vendor’s tools:
- Delivery reports
- Message trace
- Quarantine search
- Admin audit logs
- Service health dashboard
For Microsoft 365, Google Workspace, or similar, message trace is often the fastest way to see where mail went.
Practical troubleshooting checklist
- Get exact examples of affected messages.
- Check SMTP/message trace logs for those timestamps.
- Compare successful vs failed deliveries.
- Review bounce codes and defer responses.
- Verify SPF, DKIM, DMARC, MX, and PTR.
- Check queues, server health, and rate limits.
- Review spam/quarantine/filtering logs.
- Test with controlled messages.
- Escalate with logs and message IDs if using a provider.
If you want, I can also give you:
- a step-by-step checklist for Microsoft 365 / Exchange
- a Postfix/Exim investigation guide
- or a template for collecting evidence from users and logs