There is a backstory few people remember anymore. In the eighties, the former Bundespost ran a service called Bildschirmtext — BTX. A closed system, proprietary pages, proprietary tariffs, proprietary censorship. Anyone who wanted to participate had to go through the Deutsche Bundespost. Anyone who didn’t want to go through the Deutsche Bundespost stayed out. The Internet buried that service later. With the Internet came open exchange, standardized, decentralized, without gatekeepers. Telekom — successor to the Bundespost — formally accepted that. In practice, however, it never quite forgot the BTX model.
You can check this today. Anyone who operates their own mail server and sends to an @t-online.de address occasionally experiences surprises. Sometimes the mail arrives. Sometimes it doesn’t. Sometimes you get a reply that looks like an SMTP dialog but reads like an invitation to a schoolroom exercise.
What happens when the mail doesn’t arrive
The error message is characteristic. Shortened, it goes roughly like this:
554 IP=198.51.100.42 - A problem occurred.
(Ask your postmaster for help or to contact tosa@rx.t-online.de to clarify.)
Whoever sees this for the first time suspects a configuration error on their side. Missing reverse DNS? Wrong SPF? Broken DKIM? You check. Everything correct. You write to tosa@rx.t-online.de. You receive a reply that usually consists of boilerplate text and refers to Section 4.1 of Telekom’s Postmaster FAQ. There it says, shortened:
From the hostname (FQDN) of the delivering system, the domain and thus the operator’s website with immediate contact possibility must be easily researchable and comprehensible for affected parties.
Concretely: The domain under which the mail server runs must have a website. That website must carry an impressum. With name, postal address, telephone, email address. Otherwise, no delivery.
That sounds like it targets spam. Mostly, though, it targets small operators.
The double language of the Postmaster FAQ
Let’s read the same Section 4.1 further. There’s talk of RFC 1912, of forward-confirmed reverse DNS, of EU Directive 2000/31/EC Article 5. Cleanly referenced, legally grounded. The problem: The directive applies to commercial, typically paid, digital services. A hobbyist running a mail server for themselves and their family is not a service provider under this directive. Neither is a club emailing members. Still less a private individual.
So Telekom cites a norm that simply doesn’t apply to most of those affected — and nonetheless demands fulfilment. At best, that’s generosity in interpretation. At worst, it’s presumption.
Add what Telekom writes in its own Postmaster FAQ under Section 3.5:
DKIM signatures are currently neither set nor evaluated. Telekom therefore does not enforce SPF either passively (when receiving emails) or actively (for sending) by setting corresponding DNS records.
That is remarkable. Telekom demands an impressum from others, going beyond RFC standards. Itself, it uses neither SPF nor DKIM — two of the most established procedures against spoofing and spam. It uses no greylisting. It offers no feedback loop, with which legitimate senders could learn whether their mails were classified as spam — “due to data protection regulations," they say. Privacy as an argument when it concerns explaining their own procedures. Privacy as ignorance when it concerns demanding someone else’s data.
This is not spam defence. This is unilateral coercion.
Who is affected
Those affected are not bulk senders. Those long ago moved to smart hosts at Microsoft, Google, Amazon SES, Mailgun, or Sendgrid. They have their own account managers at the big providers. They have deliverability teams. They phone the postmasters. For them, none of this is a problem.
Affected are:
- Private individuals running a small mail server for themselves and their families. People who don’t want to entrust their email to the major corporations. People acting GDPR-compliantly by handing over no data at all.
- Clubs and initiatives communicating via their own domain. Volunteers with no budget for external mail providers.
- Small craft businesses — butchers, bakers, carpentries — traditionally using
@t-online.deaddresses but increasingly moving to their own domains. If the business itself is hosted with Telekom, fine. If not, sometimes not. - Smaller IT service providers and hosts running mail servers for their clients and getting to repeat the entire circus on every IP change, every move, every new subnet.
- Freelancers and solo self-employed unwilling to publish their private address in an impressum — and under § 5 DDG not obliged to, if they don’t operate a commercial website.
Telekom does not inform its own customers that their mailboxes become effectively unreachable for parts of the world. The @t-online.de user hears nothing of it. They wait for the tradesperson’s mail, for the order confirmation, for the landlord’s reply. Nothing arrives. They call. The sender says: “I sent it." Both stand there. Telekom intervened, unnoticed.
That isn’t spam defence. That’s a wall drawn straight through a communication that ought to work.
The workarounds and what they cost
Anyone trying to circumvent the wall has several options. All are unsatisfactory.
Smart host via Google or Microsoft. Telekom recommends this itself — politely, in boilerplate. Whoever relays via Gmail gets their mail through. However: DKIM and DMARC no longer work properly, because the signature of your own domain disappears. You pay with authenticity for delivery. Professional smart host services that preserve DKIM cost money. For 3–4 mails a year to T-Online, a worthwhile investment? Hardly.
Set up a fake impressum. Happens regularly in practice. Some name, some address, anything as long as Telekom’s check passes. legality aside. Telekom doesn’t verify whether the data is correct. It only checks that something is there. The result: privacy undermined without Telekom caring. Spam not reduced. Legitimate operators nudged towards deception. Whoever can’t game the system drops out. Whoever games it gets through. That’s not how protection works.
Cancel the T-Online mailbox. The consequence more and more operators are considering. If you can’t reach @t-online.de because Telekom dictates conditions unilaterally, eventually you can no longer justify trying. The tradesperson, the customer, the landlord — they need to realise their address no longer works. Some notice only when important mail stops arriving.
Block yourself. Some operators go so far as to answer incoming mail from Telekom servers with an autoresponder explaining the situation. That’s legitimate but feels to the @t-online.de user like obstinance. Telekom won, because it holds the prerogative to define what “spam defence" means.
What Telekom really wants
The official justification reads: spam defence, customer protection, transparency. Reality looks different.
Telekom has operated a closed ecosystem for decades. MagentaEARTH, MagentaZuhause, MagentaCloud — all under one roof. Once a Telekom customer, always a Telekom customer. Email is a binding instrument therein. Using @t-online.de makes switching hard — address books, subscriptions, registrations, everything hangs off it.
The higher the hurdle for external mail servers, the more attractive the internal service. The more external mail providers fail, the more customers migrate to the big aggregators — Microsoft 365, Google Workspace — or indeed to Telekom itself. Small mail operators fall away silently. The market consolidates. What remains are oligopolies.
Plus the data angle. Whoever forces an impressum collects information about mail server operators. Whoever links the IP address to the domain operator knows who runs what. Whoever logs the frequency of inquiries knows activity levels. That’s not paranoia — it’s the logic of a corporation acting in a market where data is currency.
Spam defence would be technically feasible without these hurdles. SPF, DKIM, DMARC, ARC, DANE — established procedures exist. Telekom uses none of them consistently. Instead it uses manual approvals, forms, and “reputation." Reputation it defines itself. Reputation it makes no measurable. Reputation you acquire only by registering with them.
That’s not a technical standard. That’s a gating procedure.
The historical thread
BTX was a closed system. AOL was a closed system. CompuServe was a closed system. All three lost the Internet. Telekom never quite accepted that.
Today Telekom runs mail servers behaving like a closed system. It decides who may send in. It decides whom it informs. It decides which standards it accepts — and which it ignores itself. It uses market power to impose conditions no one internationally demands. Gmail, Outlook, Yahoo, Apple iCloud — all accept mail from small server operators when basic configuration is sound. Only Telekom doesn’t.
That’s not a German special achievement. That’s a German specialty.
International providers have their own problems. Microsoft likes to block whole IP segments, Google filters aggressively, Yahoo is barely serious anymore. But no one demands an impressum on the mail server domain. No one forces private persons to publish their residential address. No one refuses acceptance and then recommends detouring via Google. That’s Telekom-special.
Why this matters to libcom.de
libcom.de has worked with open-source infrastructure for a quarter century. One focus is sovereignty — the ability to run your own systems, control your own data, conduct your own communications. Running your own mail server is a classic tool for that. It isn’t easy. It requires maintenance, updates, monitoring. But it belongs to the operator. Not to Telekom. Not to Google. Not to Microsoft.
Running your own mail server runs a piece of Internet as it was meant to be: decentralized, federated, open. The SMTP protocol is old, but it works. It works as long as the big actors play along. Telekom doesn’t. It walls.
For small and mid-sized enterprises, freelancers, clubs, private individuals reluctant to disclose their data prematurely, this is a real obstacle. Either they bow to Telekom’s special wishes — disclosing data they wouldn’t need to disclose. Or they forgo communication with part of their customers, tenants, members, partners. Both unacceptable.
This isn’t about isolated cases. It’s about a pattern. Telekom uses a dominant market position to impose conditions exceeding international standards. It does so under the label spam defence. It does so without notifying its own customers. It does so without legal grounding. It does so because it can.
What to do
Telekom customers: Consider whether you still need @t-online.de. If you want to be reachable professionally, check whether your own senders reach you. Ask your tradespeople, landlords, customers. If they report mails aren’t arriving, that’s not their problem. That’s your provider. Switch. There are independent mail providers in Germany that adhere to standards. Manitu, Posteo, Mailbox.org, Sysprovide, Timme Hosting — all respect RFC 1912 without extras.
Mail server operators: Document incidents. Write to tosa@rx.t-online.de, but copy the Federal Network Agency in when Telekom stalls. In practice this sometimes has effect — not because the agency were responsible, but because Telekom notices someone is paying attention. Don’t play along with fake impressums. Stay correct. If Telekom blocks you, then block — and explain it to your customers, employees, partners.
Customers of Telekom customers: Pass it on. If your tradesperson uses @t-online.de and you can’t reach them, tell them. They won’t believe it. Show them the bounce message. Show them that Telekom refused your mail, not you. They need to know their provider cuts them off. They need to know they’re unreachable. They need to know this isn’t rare.
Politics and associations: This is market abuse. The Federal Network Agency should examine whether Telekom’s practice aligns with network neutrality — email is part of Internet communication. The digital association Bitkom should take a position. Data protection authorities should examine whether collecting impressum data via Telekom complies with the GDPR. Silence equals consent here.
Concrete recommendation
Anyone holding an @t-online.de address today should delete it promptly. Not cancel — delete. Not convert to dormant. Delete. Keeping it signals to Telekom: “I tolerate your practice." Deleting it signals: “I go where I’m reachable."
This isn’t a call for revenge. It’s a call for reason. Telekom won’t change course while customers stay. It will change course when customers leave. Markets work like that.
Professionally reachable parties switch to a provider working RFC-compliantly. Privately reachable ones likewise. Combined needs find bundle offerings. Costs are manageable. Benefits considerable: no unilateral blocks, no form processes, no Kafkaesque correspondence with boilerplate.
What libcom.de contributes
libcom.de plans, accompanies, and operates mail infrastructures — for small and mid-sized enterprises, freelancers, clubs, private individuals wanting to keep their communications in their hands. For over two decades. With open source, with standards, no vendor lock-in.
Anyone who has held his mail services in his own hands for over twenty years knows pitfalls that remain hidden from large providers. He knows the providers that define their own rules. Telekom is one case. Microsoft is one. Google is one. Each of these actors has its own mechanisms, its own filters, its own idiosyncrasies. Running mail servers means knowing them. Not knowing them means experiencing them — usually at three in the morning, logs filling up and customers calling.
Large anonymous providers with more than questionable practices are no reasonable choice for businesses relying on dependable communication. They lock in customers, dictate conditions, change terms at will, and respond to incidents with boilerplate. A small IT professional who operates what he sells knows his infrastructure inside out. He knows the problems because he lived through them himself. He knows the workarounds because he had to work them out himself. He knows his customers because he speaks with them — not via tickets but personally. Procuring mail services from such a partner buys expertise no call centre delivers. Someone reachable when it burns. Someone who knows Telekom — and who knows how to deal with Telekom without bending to it.
Anyone needing support — setup, troubleshooting, communication with providers like Telekom, migration away from @t-online.de — can reach out. Write to contact@libcom.de. We take an honest inventory. No sales pressure. With a view to what lasts long term.
Telekom builds walls. That isn’t new. New only is that more people notice. Rejecting the wall means leaving. Staying means consenting. Leaving means dissent. There is no third way.
Note: This article offers general orientation and does not constitute legal advice. Assessments of Telekom’s business practices draw on publicly accessible sources, forum contributions, and practical experience; all information provided without warranty.