emailmarketing.net

Comcast / Xfinity — Postmaster: Error Codes, Rate Limits, Unblocking

Comcast (comcast.net / Xfinity) sender policy: full BL/RL/ES/DM error-code table, SenderScore-based rate limits, connection and recipient limits, blocklist removal, and FBL.

Reference6 min read

Who it is for Senders, ESP operators

Applies to senders on any platform

If your mail to comcast.net or Xfinity addresses is deferred or rejected, the code in the bounce tells you why and what to do next. Comcast's postmaster documentation is unusually explicit. It names the blocklists Comcast consults, publishes a table of rate limits based on SenderScore, and runs a self-service unblock form 24/7.

The documentation used to live at postmaster.comcast.net and is now served through the Xfinity Service Policy Assurance (SPA) portal at spa.xfinity.com/help/postmaster. Comcast states that all its policies and thresholds are subject to change.

Where these details come from: the SPA portal is a JavaScript application, so the codes and thresholds below were captured from the archived postmaster.comcast.net pages (snapshots from 2021–2022) that the portal replaced. Treat the numeric thresholds as indicative, and check the current values on the live portal before a critical decision.

Core acceptance requirements ("avoiding blocks")

Rule Detail
RFC compliance All email must comply with the relevant RFCs
Reverse DNS Comcast checks the reverse DNS (rDNS) of the sending IP address. It refuses connections without a valid PTR record plus an MX or A record
Static IP addresses only Mail from dynamic or residential IP space is not accepted. An IP address is classified as dynamic if its rDNS "does not comply with standard static naming conventions"
DNSBLs Comcast consults external blocklists (historically Spamhaus Zen, Cloudmark CSI, Return Path (SenderScore), and Vade (earlier documented as TrendMicro MAPS)). A listing on any of them blocks you
List hygiene High volumes of undeliverable mail get the IP address blocked. Every 550 "Not our customer" must be treated as an unsubscribe by bulk mailers
Abuse management Enforce acceptable use policies (AUPs) and deal with compromised accounts. Dictionary and directory harvest attacks quickly lead to IP blocks
DMARC Comcast validates DMARC on inbound mail and enforces the sending domain's policy (see DM000001 below). It sends daily aggregate reports from dmarc-support@alerts.comcast.net

Hard limits

Limit Value
Simultaneous connections for each sending IP address 25
Emails in each SMTP session 1,000
Recipients for each message 100
Maximum message size 15 MB
Delisting requests At most 5 for each IP address per day, and at most 20 different IP addresses per day (block removal form)

Rate limiting (RL codes)

Traffic that is rate limited receives a 4xx temporary failure. The correct response is to retry later, and Comcast's own advice when rate limits apply is to shorten your retry interval. New IP addresses must warm up: limits rise each day as a history of clean volume builds (see IP Warm-Up).

Code Basis
RL000001 Sender reputation from SenderScore, plus authentication of the sending server, however many domains send from it
RL000002 Sender reputation and volume metrics from Cloudmark
RL000003 The history of volume and of the quality of that volume; independent of the number of domains; applies to IPv4 and IPv6

Hourly throughput by SenderScore (RL000001), as published. Two versions of the table existed, and both are shown:

SenderScore Recipients per hour (later table) Recipients per hour (earlier table)
N/A (no score) 120 300
0–15 1,200 1,200
16–25 3,600 3,600
26–30 6,000 7,200
31–50 12,000 14,400
51–70 24,000 50,400
71–85 42,000 72,000
86–100 60,000 86,400

These rates are subject to successful authentication.

Blocklist error codes (BL series)

The BL code is a bitmask of the external lists the IP address is on. Each bit position stands for one list. Reading BLxxxxxx from right to left, the lists are Spamhaus Zen, Cloudmark CSI, the Return Path SenderScore blocklist, and the Vade Threat List (documented earlier as TrendMicro MAPS).

The remedy is always the same: fix the outbound spam problem, then request removal from the listing service itself. Comcast copies the listing; it does not own it.

Code Listed on
BL000000 Comcast's own filters: sending patterns "characteristic of spam". Use Comcast's removal form
BL000001 Spamhaus Zen
BL000010 Cloudmark Sender Intelligence (CSI)
BL000011 CSI + Spamhaus Zen
BL000100 Return Path Reputation Network Blocklist (SenderScore)
BL000101 Return Path + Spamhaus Zen
BL000110 Return Path + CSI
BL000111 Return Path + CSI + Spamhaus Zen
BL001000 Vade Threat List (VTL)
BL001001 VTL + Spamhaus Zen
BL001010 VTL + CSI
BL001011 VTL + CSI + Spamhaus Zen
BL001100 VTL + Return Path
BL001101 VTL + Return Path + Spamhaus Zen
BL001110 VTL + Return Path + CSI
BL001111 VTL + Return Path + CSI + Spamhaus Zen

Policy error codes (ES, DM)

Code Meaning Remediation
ES000001 Sending from a dynamic or residential IP address inside Comcast's network. Subscribers may send only through smtp.comcast.net This block cannot be lifted. Use Comcast webmail or its submission service, or contact Commercial Services (support_biz@cable.comcast.com) to run a server
ES000010 Sending from IP space that Comcast classifies as dynamic or residential (usually because the rDNS does not look static) Change the rDNS to a static naming convention. If your provider cannot, escalate to Customer Security Assurance
DM000001 The message was rejected because the sending domain publishes DMARC p=reject and the message failed both DKIM and SPF for that domain Fix authentication and alignment (see DMARC)

Generic SMTP errors

Code or text Meaning
421 Too many sessions opened More than 25 simultaneous connections from the IP address
421 Reverse DNS failure : Try again later The rDNS lookup returned SERVFAIL (the authoritative DNS is misconfigured or down). Temporary failure; retry
421 Try again later Generic temporary failure; retry
452 Too many emails sent on this session More than 1,000 messages in the session
452 Too many recipients for message More than 100 recipients for the message
550 Not our customer The recipient does not exist. Bulk mailers must treat this as an unsubscribe
550 …too many invalid recipients The whole message is refused for all recipients. Clean the list and send again
550 Invalid sender domain The sending domain has no valid A or MX record
550 Account not available The recipient's account is currently unavailable
552 Message size exceeded Larger than 15 MB
554 PTR lookup failure The PTR lookup returned NXDOMAIN: the connecting IP address has no reverse DNS

Blocklist removal process

  1. Find the code in the bounce. Every non-delivery notice (NDN) links to the FAQ that explains the block.
  2. For codes from external lists (BL000001 and higher), fix the problem, then request delisting from the list operator (Spamhaus, CSI, SenderScore or Vade). Comcast honors the removal.
  3. For Comcast's internal blocks (BL000000), submit the Blocked Provider Request Form on the postmaster portal. The required fields are your name, email address, daytime and evening phone numbers, the domain of the blocked IP address, your role (email administrator, executive, subscriber or Comcast subscriber), the blocked IP addresses, and a description of the issue. You can also state what you have done to fix it (spam filtering in place, rDNS made static and consistent). The limits are 5 submissions per day and, according to third-party documentation, up to 20 IP addresses per day. The form is monitored 24/7, and simple blocks usually clear in well under an hour.
  4. Escalation: Customer Security Assurance, 888-565-4329, referred to on the pages for ES, RL and DM codes when self-service cannot resolve the problem.

Feedback loop (FBL)

  • Sign up at feedback.comcast.net. Registration can be based on IP addresses or on DKIM (the DKIM option launched as a beta).
  • Reports use the Abuse Reporting Format (ARF) and are generated when a user clicks "This is Spam". They include the full message headers, but the complainant's address is removed and is never restored.
  • You must be the party responsible for the sending server. On shared servers, the owner of the server should sign up.
  • The historical acceptance criteria were: a SenderScore of ≥ 60 accepted; 30–60 accepted only if the IP address is on no DNSBL; < 30 rejected. A refusal comes with an explanation and the steps to fix the problem, and you can apply again at any time.
  • Comcast reserves the right to stop sending feedback to any party at any time.

Comcast's outbound infrastructure (for receivers)

Consumer mail leaves from the hosts resqmta-*.sys.comcast.net and resdmta-*.sys.comcast.net (published ranges 96.103.146.x, 96.102.19.x and 96.102.200.x) and from the IPv6 ranges 2001:558:fd00::/…. Bulk messaging goes through a separate platform (MDP) at 96.114.127.0/27 and 68.87.28.32/27, plus two IPv6 /120s. Check the live portal for the current list.