30 Runbooks

Troubleshooting Playbooks

Evidence-first triage, decision paths, recovery and prevention for common mail-infrastructure failures.

SMTP AUTH failures

Authentication errors, credential scope, TLS requirements and application configuration.

Unauthorized MAIL FROM use

Authenticated users submitting unapproved envelope sender domains.

SMTP listener connection refused

Service, bind address, firewall and port-conflict diagnosis.

Relay denied

Source authorization, authentication and recipient relay policy.

Rapid queue growth

Separate intake pressure, provider slowdown, DNS faults and local resource constraints.

Oldest message age rising

Identify whether delivery capacity or retry policy is preventing queue recovery.

Queue disk pressure

Contain intake, preserve critical mail and restore storage headroom.

DNS timeouts

Resolver health, reachability, cache behavior and source-IP routing.

PTR and HELO mismatch

Correct forward and reverse identity without introducing DNS inconsistency.

DKIM verification failure

Selector publication, key mismatch, canonicalization and body modification.

SPF failure

Envelope sender domain, source IP authorization and lookup-chain problems.

DMARC failure

Identifier alignment, SPF/DKIM pass results and From-domain policy.

TLS handshake failure

Certificate chain, hostname, protocol compatibility and time validity.

Microsoft S775 throttling

Evidence collection, rate stabilization and reputation recovery controls.

Microsoft 421 deferrals

Differentiate reputation throttling, resource pressure and transient provider conditions.

Gmail 421 temporary failures

Review reputation, recipient quality, authentication and traffic changes.

Gmail spam placement

Separate delivery acceptance from inbox placement and inspect engagement/list quality.

Yahoo/AOL 421 deferrals

Review provider responses, complaints, reputation and connection policy.

GMX/WEB.DE deferrals

Conservative rate adjustments and identity verification.

Apple iCloud deferrals

Inspect temporary responses, complaint signals and sender identity.

High hard-bounce rate

Pause affected sources, verify acquisition and suppress invalid recipients.

Complaint spike

Contain the campaign, map complaints to tenant/source and suppress immediately.

Bounce processing gap

Verify Return-Path, inbound DNS, parser and tenant mapping.

Accounting log gap

Check file paths, permissions, rotation, disk and ingestion checkpoints.

Wrong source IP used

Inspect VMTA assignment, pools, pattern lists and default routing.

Wrong HELO used

Trace VMTA selection and smtp-source-host identity.

MailWizz submission failure

Credentials, port, TLS mode, listener and application logs.

Postfix relay failure

relayhost syntax, transport maps, SASL and local network reachability.

PowerMTA startup error

Locate line-specific configuration faults and unsupported syntax.

Unexpected queue removal

Audit bounce policy, manual commands, scripts and filesystem events.

Search Trushilla Documentation