MXroute - Postmortem: Heracles IMAP – Incident details

All systems operational

Postmortem: Heracles IMAP

Resolved
Operational
Started 22 days agoLasted less than a minute

Affected

IMAP

Operational from 9:12 PM to 9:12 PM

Updates
  • Resolved
    Resolved

    This morning the Heracles server (heracles.mxrouting.net, only for users on that server) experienced IMAP connection failures due to reaching configured limits in Dovecot. A total of 3,899 connections failed from 10:08:51 to 14:55:39 UTC. This is verified to have impacted customers across 1,465 domains on the server (total 7552 domains on Heracles). This was caused by two colliding factors:

    1. A DDOS attack against the IMAP server.

    2. Customers who violated our policy against warmup services flooding thousands of IMAP connections per minute using either instantly[.]io or a comparable service.

    Resolutions:

    1. Increased service limits.

    2. Created monitoring system that catches this specific issue.

    3. Created secondary monitoring system that ensures the previous monitoring system remains healthy.

    4. Suspended customers using warmup services.