Comcast / Xfinity — Postmaster: Error Codes, Rate Limits, Unblocking
Comcast (comcast.net / Xfinity) sender policy: full BL/RL/ES/DM error-code table, SenderScore-based rate limits, connection and recipient limits, blocklist removal, and FBL.
Reference6 min read
Who it is for Senders, ESP operators
Applies to senders on any platform
ContentsOn this page — 9 sections
If your mail to comcast.net or Xfinity addresses is deferred or rejected, the code in the bounce tells you why and what to do next. Comcast's postmaster documentation is unusually explicit. It names the blocklists Comcast consults, publishes a table of rate limits based on SenderScore, and runs a self-service unblock form 24/7.
The documentation used to live at postmaster.comcast.net and is now served through the Xfinity Service Policy Assurance (SPA) portal at spa.xfinity.com/help/postmaster. Comcast states that all its policies and thresholds are subject to change.
Where these details come from: the SPA portal is a JavaScript application, so the codes and thresholds below were captured from the archived
postmaster.comcast.netpages (snapshots from 2021–2022) that the portal replaced. Treat the numeric thresholds as indicative, and check the current values on the live portal before a critical decision.
Core acceptance requirements ("avoiding blocks")
| Rule | Detail |
|---|---|
| RFC compliance | All email must comply with the relevant RFCs |
| Reverse DNS | Comcast checks the reverse DNS (rDNS) of the sending IP address. It refuses connections without a valid PTR record plus an MX or A record |
| Static IP addresses only | Mail from dynamic or residential IP space is not accepted. An IP address is classified as dynamic if its rDNS "does not comply with standard static naming conventions" |
| DNSBLs | Comcast consults external blocklists (historically Spamhaus Zen, Cloudmark CSI, Return Path (SenderScore), and Vade (earlier documented as TrendMicro MAPS)). A listing on any of them blocks you |
| List hygiene | High volumes of undeliverable mail get the IP address blocked. Every 550 "Not our customer" must be treated as an unsubscribe by bulk mailers |
| Abuse management | Enforce acceptable use policies (AUPs) and deal with compromised accounts. Dictionary and directory harvest attacks quickly lead to IP blocks |
| DMARC | Comcast validates DMARC on inbound mail and enforces the sending domain's policy (see DM000001 below). It sends daily aggregate reports from dmarc-support@alerts.comcast.net |
Hard limits
| Limit | Value |
|---|---|
| Simultaneous connections for each sending IP address | 25 |
| Emails in each SMTP session | 1,000 |
| Recipients for each message | 100 |
| Maximum message size | 15 MB |
| Delisting requests | At most 5 for each IP address per day, and at most 20 different IP addresses per day (block removal form) |
Rate limiting (RL codes)
Traffic that is rate limited receives a 4xx temporary failure. The correct response is to retry later, and Comcast's own advice when rate limits apply is to shorten your retry interval. New IP addresses must warm up: limits rise each day as a history of clean volume builds (see IP Warm-Up).
| Code | Basis |
|---|---|
| RL000001 | Sender reputation from SenderScore, plus authentication of the sending server, however many domains send from it |
| RL000002 | Sender reputation and volume metrics from Cloudmark |
| RL000003 | The history of volume and of the quality of that volume; independent of the number of domains; applies to IPv4 and IPv6 |
Hourly throughput by SenderScore (RL000001), as published. Two versions of the table existed, and both are shown:
| SenderScore | Recipients per hour (later table) | Recipients per hour (earlier table) |
|---|---|---|
| N/A (no score) | 120 | 300 |
| 0–15 | 1,200 | 1,200 |
| 16–25 | 3,600 | 3,600 |
| 26–30 | 6,000 | 7,200 |
| 31–50 | 12,000 | 14,400 |
| 51–70 | 24,000 | 50,400 |
| 71–85 | 42,000 | 72,000 |
| 86–100 | 60,000 | 86,400 |
These rates are subject to successful authentication.
Blocklist error codes (BL series)
The BL code is a bitmask of the external lists the IP address is on. Each bit position stands for one list. Reading BLxxxxxx from right to left, the lists are Spamhaus Zen, Cloudmark CSI, the Return Path SenderScore blocklist, and the Vade Threat List (documented earlier as TrendMicro MAPS).
The remedy is always the same: fix the outbound spam problem, then request removal from the listing service itself. Comcast copies the listing; it does not own it.
| Code | Listed on |
|---|---|
| BL000000 | Comcast's own filters: sending patterns "characteristic of spam". Use Comcast's removal form |
| BL000001 | Spamhaus Zen |
| BL000010 | Cloudmark Sender Intelligence (CSI) |
| BL000011 | CSI + Spamhaus Zen |
| BL000100 | Return Path Reputation Network Blocklist (SenderScore) |
| BL000101 | Return Path + Spamhaus Zen |
| BL000110 | Return Path + CSI |
| BL000111 | Return Path + CSI + Spamhaus Zen |
| BL001000 | Vade Threat List (VTL) |
| BL001001 | VTL + Spamhaus Zen |
| BL001010 | VTL + CSI |
| BL001011 | VTL + CSI + Spamhaus Zen |
| BL001100 | VTL + Return Path |
| BL001101 | VTL + Return Path + Spamhaus Zen |
| BL001110 | VTL + Return Path + CSI |
| BL001111 | VTL + Return Path + CSI + Spamhaus Zen |
Policy error codes (ES, DM)
| Code | Meaning | Remediation |
|---|---|---|
| ES000001 | Sending from a dynamic or residential IP address inside Comcast's network. Subscribers may send only through smtp.comcast.net | This block cannot be lifted. Use Comcast webmail or its submission service, or contact Commercial Services (support_biz@cable.comcast.com) to run a server |
| ES000010 | Sending from IP space that Comcast classifies as dynamic or residential (usually because the rDNS does not look static) | Change the rDNS to a static naming convention. If your provider cannot, escalate to Customer Security Assurance |
| DM000001 | The message was rejected because the sending domain publishes DMARC p=reject and the message failed both DKIM and SPF for that domain |
Fix authentication and alignment (see DMARC) |
Generic SMTP errors
| Code or text | Meaning |
|---|---|
| 421 Too many sessions opened | More than 25 simultaneous connections from the IP address |
| 421 Reverse DNS failure : Try again later | The rDNS lookup returned SERVFAIL (the authoritative DNS is misconfigured or down). Temporary failure; retry |
| 421 Try again later | Generic temporary failure; retry |
| 452 Too many emails sent on this session | More than 1,000 messages in the session |
| 452 Too many recipients for message | More than 100 recipients for the message |
| 550 Not our customer | The recipient does not exist. Bulk mailers must treat this as an unsubscribe |
| 550 …too many invalid recipients | The whole message is refused for all recipients. Clean the list and send again |
| 550 Invalid sender domain | The sending domain has no valid A or MX record |
| 550 Account not available | The recipient's account is currently unavailable |
| 552 Message size exceeded | Larger than 15 MB |
| 554 PTR lookup failure | The PTR lookup returned NXDOMAIN: the connecting IP address has no reverse DNS |
Blocklist removal process
- Find the code in the bounce. Every non-delivery notice (NDN) links to the FAQ that explains the block.
- For codes from external lists (BL000001 and higher), fix the problem, then request delisting from the list operator (Spamhaus, CSI, SenderScore or Vade). Comcast honors the removal.
- For Comcast's internal blocks (BL000000), submit the Blocked Provider Request Form on the postmaster portal. The required fields are your name, email address, daytime and evening phone numbers, the domain of the blocked IP address, your role (email administrator, executive, subscriber or Comcast subscriber), the blocked IP addresses, and a description of the issue. You can also state what you have done to fix it (spam filtering in place, rDNS made static and consistent). The limits are 5 submissions per day and, according to third-party documentation, up to 20 IP addresses per day. The form is monitored 24/7, and simple blocks usually clear in well under an hour.
- Escalation: Customer Security Assurance, 888-565-4329, referred to on the pages for ES, RL and DM codes when self-service cannot resolve the problem.
Feedback loop (FBL)
- Sign up at feedback.comcast.net. Registration can be based on IP addresses or on DKIM (the DKIM option launched as a beta).
- Reports use the Abuse Reporting Format (ARF) and are generated when a user clicks "This is Spam". They include the full message headers, but the complainant's address is removed and is never restored.
- You must be the party responsible for the sending server. On shared servers, the owner of the server should sign up.
- The historical acceptance criteria were: a SenderScore of ≥ 60 accepted; 30–60 accepted only if the IP address is on no DNSBL; < 30 rejected. A refusal comes with an explanation and the steps to fix the problem, and you can apply again at any time.
- Comcast reserves the right to stop sending feedback to any party at any time.
Comcast's outbound infrastructure (for receivers)
Consumer mail leaves from the hosts resqmta-*.sys.comcast.net and resdmta-*.sys.comcast.net (published ranges 96.103.146.x, 96.102.19.x and 96.102.200.x) and from the IPv6 ranges 2001:558:fd00::/…. Bulk messaging goes through a separate platform (MDP) at 96.114.127.0/27 and 68.87.28.32/27, plus two IPv6 /120s. Check the live portal for the current list.
Check your own record
The free check reads what your domain publishes in DNS.
In this topic
- Gmail Email Sender Guidelines
- Gmail SMTP Errors and Troubleshooting
- Yahoo Sender Requirements & Best Practices
- Yahoo Complaint Feedback Loop (CFL)