Ab heute nehmen unsere Mailserver keine E-Mails mehr an, die über die Infrastruktur von Mailgun (Sinch) verschickt werden. Das ist eine drastische Maßnahme. Sie ist uns nicht leichtgefallen. Und sie war nach drei Monaten die einzige, die noch übrig war.
Die Kurzfassung für Eilige
- Seit über drei Monaten wird ein Teil unserer Kundenpostfächer von einem Mailgun-Kunden mit Casino-Werbung zugemüllt.
- Wir haben diesen Missbrauch über Monate hinweg gemeldet – jedes Mal mit der vollständigen Original-Mail inklusive sämtlicher Header, unverändert.
- Die Antwort war jedes Mal derselbe Textbaustein mit der Bitte, doch bitte die vollständigen Header zu schicken.
- Der Absender versendet bis heute munter weiter.
- Seit heute lehnen wir Mails aus dem Mailgun-Netz an unseren Mailservern ab.
- Kunden, die einen legitimen Absender vermissen, bekommen von uns keine Ausnahme. Dazu unten mehr.
Wie man einen Abuse-Report korrekt beantwortet (eine Anleitung von Mailgun)
Es gibt in der Mailbranche einen ungeschriebenen Vertrag. Er lautet ungefähr so: Ihr dürft über unsere Netze Mails zustellen, und im Gegenzug kümmert ihr euch darum, wenn einer eurer Kunden Mist baut. Dieser Vertrag ist der Grund, warum E-Mail überhaupt noch funktioniert. Er wird von den allermeisten großen Versanddienstleistern auch ernst genommen – ein sauber dokumentierter Report, und der Spammer ist am nächsten Tag weg.
Mailgun hat sich für einen anderen Weg entschieden. Auf jede unserer Meldungen folgte zuverlässig innerhalb weniger Stunden dieselbe Nachricht: Man bedauert den Vorfall, so etwas werde selbstverständlich nicht toleriert, alle Kunden seien zum Double-Opt-in verpflichtet – und ob wir bitte <q>the full message headers</q> schicken könnten, damit das Abuse-Team tätig werden kann. Bitte in den Mailtext einfügen, nicht als Anhang, aus Sicherheitsgründen. Freundlicherweise war auch ein Google-Hilfeartikel verlinkt, in dem erklärt wird, wie man in Gmail an die Header kommt.
Das ist auf mehreren Ebenen bemerkenswert.
Erstens: Wir hatten die Header geschickt. Jedes Mal. Nicht als Screenshot, nicht als Zitat, nicht als Beschreibung – als vollständige, unveränderte Original-Nachricht im Anhang bzw. eingebettet, exakt so, wie ein Abuse-Desk sie braucht. Wir betreiben seit Jahren selbst Mailinfrastruktur für eine große Zahl an Postfächern. Wir wissen ziemlich genau, wie ein brauchbarer Abuse-Report aussieht.
Zweitens: Ein Anbieter, der Mails über die eigene Plattform verschickt, braucht unsere Header eigentlich gar nicht. Er hat die Nachricht selbst versendet. Die Message-ID steht in der Beschwerde. Der Absender-Domain-Teil steht in der Beschwerde. Alles, was nötig wäre, ist eine Datenbankabfrage im eigenen System.
Drittens – und das ist der eigentliche Punkt: Wenn auf einen inhaltlich vollständigen Report zwölfmal hintereinander dieselbe automatisierte Nachfrage folgt, dann liest dort niemand mit. Das ist keine Untersuchung. Das ist ein Warteschleifen-Bandansage in Textform.
Ein Abuse-Desk, der Beschwerden nicht liest, ist kein Abuse-Desk. Es ist ein Ticketsystem mit guten Manieren.
Warum uns das nicht egal sein kann
Man könnte sagen: Ist doch nur Spam, filtert ihn halt weg. Wir sehen das anders, aus drei Gründen.
Weil unsere Kunden dafür bezahlen, dass ihr Postfach sauber ist. Wenn ein Steuerberater, eine Arztpraxis oder ein Handwerksbetrieb morgens zwischen Mandantenanfragen und Rechnungen erst noch Casino-Werbung wegsortieren muss, dann haben wir unseren Job nicht gemacht. Filter fangen viel ab, aber professionell aufgesetzter Spam von einem reputablen Versanddienstleister ist genau deshalb so heimtückisch: Er kommt mit gültigem SPF, gültigem DKIM, sauberem DMARC und von IP-Adressen mit guter Historie. Er sieht für jeden Filter aus wie eine legitime Nachricht – weil er technisch eine ist.
Weil Reputation ein Gemeinschaftsgut ist. Genau diese saubere Reputation ist es, für die Mailgun-Kunden bezahlen. Sie ist der eigentliche Wert des Produkts. Wer sie zulässt für Casino-Spam, verkauft sie meistbietend an denjenigen, der am wenigsten Skrupel hat – und lässt die Rechnung von allen anderen bezahlen: den seriösen Mailgun-Kunden, deren Zustellraten sinken, und den Betreibern der Empfängerseite, also uns.
Weil unaufgeforderte Werbe-E-Mails hierzulande schlicht rechtswidrig sind. § 7 UWG kennt keinen Ermessensspielraum bei Werbung ohne vorherige ausdrückliche Einwilligung. Ein Dienstleister, der wiederholt und nachweislich über den Missbrauch seiner Plattform informiert wird und dennoch über Monate keine erkennbare Konsequenz zieht, kann sich schwer auf Nichtwissen berufen. Wir sind keine Anwaltskanzlei und wir schreiben hier kein Gutachten – aber wir dokumentieren.
Unsere letzte Nachricht an Mailgun
Weil Transparenz besser ist als Andeutungen, hier im Wortlaut, was wir heute an den Abuse-Desk geschickt haben (Ticket 7VW9NG-G31G9):
To whom it may concern (Ticket [7VW9NG-G31G9]),
We have been dealing with this exact same issue for three months now, and frankly we are done wasting time on it. Every single time we report abuse from this casino sender, we forward the complete, original spam email to your abuse address, including all full message headers, unaltered and unmodified. You already have everything you claim to need. Asking us again to „send the full message headers“ is not an investigation, it’s a stalling tactic, and it is not acceptable.
If your abuse team is not actually reading the reports it receives, that is a problem on your end, not ours. We are not going to keep repeating the same forwarding process every time this sender abuses your platform, only for your team to reply with a copy-paste request for information you already have.
Since Mailgun/Sinch has failed to stop this sender from abusing your infrastructure for three months despite repeated, fully-documented reports, we are now blocking all incoming mail from Mailgun across every one of our servers. This block will remain in place until this sender is no longer able to send mail through your service. We consider this the only effective way left to protect our systems and our users, given your abuse desk’s inaction.
We will also be publishing this on our blog for our clients and the wider public to see.
Wir gehen davon aus, dass darauf eine Nachricht folgt, in der man uns bedauert, auf die strenge Sendepolicy hinweist und um die vollständigen Header bittet. Wir haben Wetten laufen.
Was das konkret bedeutet
Ab sofort weisen unsere Mailserver Zustellversuche aus dem Mailgun-Netz bereits beim SMTP-Dialog ab. Bewusst mit einer permanenten Fehlermeldung und einem sprechenden Text – kein stilles Wegwerfen. Das ist uns wichtig:
- Der Absender bekommt eine Zustellfehlermeldung und weiß, dass seine Mail nicht angekommen ist.
- Niemand wartet vergeblich auf eine Antwort, die nie zugestellt wurde.
- Der Grund steht in der Bounce-Message, inklusive Verweis auf diesen Beitrag.
Stiller Mailverlust ist die schlechteste aller Varianten. Wir machen das nicht.
Für unsere Kunden
Mailgun wird auch von vielen völlig seriösen Diensten genutzt – für Bestellbestätigungen, Passwort-Resets, Zwei-Faktor-Codes oder Newsletter, die Sie tatsächlich abonniert haben. Diese Nachrichten sind von der Sperre ebenfalls betroffen. Das ist der unangenehme Teil dieser Entscheidung, und wir wollen ihn nicht kleinreden.
Wann heben wir die Sperre wieder auf?
Sobald der betreffende Absender nicht mehr über Mailgun versenden kann. Das ist die einzige Bedingung. Sie liegt vollständig in Mailguns Hand und ließe sich vermutlich in unter fünf Minuten erfüllen – vorausgesetzt, jemand liest die Tickets.
Ein Wort zum Schluss
Wir betreiben unsere Mailinfrastruktur selbst, in eigenen Racks, in europäischen Rechenzentren. Wir tun das unter anderem deshalb, weil wir bei Entscheidungen wie dieser nicht auf einen Konzern warten müssen, dem unsere Kunden egal sind. Heute war so ein Tag.
Wir hätten diesen Beitrag lieber nicht geschrieben. Wir hätten lieber eine Mail bekommen, in der steht: „Danke für den Report, Account gesperrt.“ Sieben Wörter. Mehr wäre nie nötig gewesen.
Sollte Mailgun das irgendwann nachholen, ergänzen wir diesen Beitrag gerne um ein Update. Wir würden uns aufrichtig freuen.
Stand: 3. August 2026. Fragen zur Sperre oder zu Ausnahmen für einzelne Absender beantwortet unser Support jederzeit.
Three months of casino spam, one canned reply, and one consequence: we are blocking Mailgun
As of today, our mail servers no longer accept email sent through Mailgun (Sinch) infrastructure. This is a drastic measure. It was not an easy decision. And after three months, it was the only one left.
The short version
- For over three months, some of our customers‘ mailboxes have been flooded with casino advertising sent by a Mailgun customer.
- We reported the abuse for months — every single time with the complete original message including all headers, unaltered.
- Every single time, the answer was the same canned reply asking us to please send the full message headers.
- The sender is still happily sending today.
- As of today, our mail servers reject mail originating from Mailgun’s network.
- The block applies in full. We are not maintaining an exception list. More on that below.
How to answer an abuse report properly (a tutorial by Mailgun)
There is an unwritten contract in the email industry. It goes roughly like this: you may deliver mail across our networks, and in return you deal with it when one of your customers misbehaves. That contract is the reason email still works at all. Most large sending providers take it seriously — one well-documented report, and the spammer is gone the next day.
Mailgun chose a different path. Every one of our reports was reliably answered within hours by the same message: they are sorry, this is definitely not something they tolerate, all of their users are obliged to obtain explicit consent — and could we please send <q>the full message headers</q> so their abuse team can take action. Pasted into the message body, not as an attachment, for security reasons. Helpfully, a Google support article explaining how to find message headers in Gmail was linked as well.
This is remarkable on several levels.
First: we had sent the headers. Every time. Not as a screenshot, not as a quote, not as a description — as the complete, unmodified original message, exactly the way an abuse desk needs it. We have been running mail infrastructure for a large number of mailboxes for years. We know fairly precisely what a usable abuse report looks like.
Second: a provider that sent the message through its own platform does not actually need our headers. It sent the message. The Message-ID is in the complaint. The sending domain is in the complaint. All it would take is a database query in their own system.
Third, and this is the real point: when twelve consecutive, complete reports are met with the same automated request, nobody is reading them. That is not an investigation. That is a hold-music recording in text form.
An abuse desk that does not read complaints is not an abuse desk. It is a ticket system with good manners.
Why we cannot simply ignore this
One could argue: it’s just spam, filter it out. We see it differently, for three reasons.
Because our customers pay us to keep their mailbox clean. When a tax advisor, a medical practice or a tradesperson has to sort casino ads out from client enquiries and invoices every morning, we have not done our job. Filters catch a great deal, but professionally sent spam from a reputable delivery provider is insidious for exactly that reason: it arrives with valid SPF, valid DKIM, clean DMARC and from IP addresses with a good history. To any filter it looks like a legitimate message — because technically it is one.
Because reputation is a shared resource. That clean reputation is precisely what Mailgun’s customers are paying for. It is the actual value of the product. Whoever rents it out to casino spam is selling it to whoever has the fewest scruples — and sends the bill to everyone else: to the legitimate Mailgun customers whose delivery rates decline, and to the operators on the receiving end, which is us.
Because unsolicited commercial email is simply unlawful here. German competition law (§ 7 UWG) leaves no room for discretion when it comes to advertising without prior explicit consent. A provider that is repeatedly and verifiably informed about the abuse of its platform, yet shows no discernible consequence over a period of months, will have a hard time claiming it did not know. We are not a law firm and this is not a legal opinion — but we do keep records.
Our final message to Mailgun
Because transparency beats insinuation, here is what we sent to their abuse desk today, verbatim (ticket 7VW9NG-G31G9):
To whom it may concern (Ticket [7VW9NG-G31G9]),
We have been dealing with this exact same issue for three months now, and frankly we are done wasting time on it. Every single time we report abuse from this casino sender, we forward the complete, original spam email to your abuse address, including all full message headers, unaltered and unmodified. You already have everything you claim to need. Asking us again to „send the full message headers“ is not an investigation, it’s a stalling tactic, and it is not acceptable.
If your abuse team is not actually reading the reports it receives, that is a problem on your end, not ours. We are not going to keep repeating the same forwarding process every time this sender abuses your platform, only for your team to reply with a copy-paste request for information you already have.
Since Mailgun/Sinch has failed to stop this sender from abusing your infrastructure for three months despite repeated, fully-documented reports, we are now blocking all incoming mail from Mailgun across every one of our servers. This block will remain in place until this sender is no longer able to send mail through your service. We consider this the only effective way left to protect our systems and our users, given your abuse desk’s inaction.
We will also be publishing this on our blog for our clients and the wider public to see.
We fully expect a reply expressing regret, referring to their strict sending policy, and asking for the full message headers. Bets are being taken internally.
What this means in practice
From now on, our mail servers reject delivery attempts from Mailgun’s network during the SMTP dialogue. Deliberately with a permanent error and a meaningful message — no silent discarding. That matters to us:
- The sender receives a bounce and knows the message was not delivered.
- Nobody waits in vain for a reply that never arrived.
- The reason is stated in the bounce message, including a link to this post.
Silently losing mail is the worst of all options. We don’t do that.
For our customers
Mailgun is also used by legitimate services — for order confirmations, password resets, two-factor codes or newsletters you actually subscribed to. Those messages are affected by the block as well. That is the uncomfortable part of this decision, and we are not going to talk it down.
The block applies in full, with no individual exceptions. That is a deliberate choice. A block with an allowlist is not a block, it is an administrative process that preserves the root cause and shifts the workload from Mailgun to us. As long as individual senders are waved through, nothing changes for the party causing the problem — and we would be maintaining exceptions week after week for something that a single click in someone else’s backend could end.
What you can do: if you are missing a sender that delivers via Mailgun, tell the sender. Not us. Delivery problems are the only currency that counts for a sending provider — and one customer asking why their invoices are not arriving tends to move more at Mailgun than twelve abuse reports. Switching to a provider with a functioning abuse desk is the more sustainable solution anyway, and there is no shortage of them.
When will the block be lifted?
As soon as the sender in question can no longer send through Mailgun. That is the only condition. It rests entirely in Mailgun’s hands and could probably be met in under five minutes — assuming somebody reads the tickets.
One final word
We run our mail infrastructure ourselves, in our own racks, in European data centres. One reason we do this is so that decisions like today’s do not depend on a corporation that is indifferent to our customers. Today was one of those days.
We would rather not have written this post. We would rather have received an email saying: „Thanks for the report, account suspended.“ Six words. That is all it would ever have taken.
Should Mailgun get around to it, we will gladly add an update to this post. We would be sincerely pleased to.
Last updated: 3 August 2026. Questions about the block are answered by our support team at any time.