Culture
The Great Reply-All Storms, and Why They Keep Happening
From Microsoft's Bedlam DL3 to the NHS's 500 million emails in 75 minutes: the great reply-all storms, why they snowball, and what finally stopped them.

In 2004, Larry Osterman, a long-serving Microsoft developer, described an experiment he’d tried at lunch. Sitting in the cafeteria with a group of colleagues, he said, out of nowhere, “Bedlam DL3”. About three of the old-timers at the table answered in chorus: “Me too!”
That is the reply-all storm in miniature: an in-joke that only makes sense if you were in the blast radius. Almost every large organisation has one, and they follow the same script so faithfully you could stage it. A message goes to far too many people. Someone asks to be removed. Someone else asks everyone to stop replying to all, by replying to all. Somewhere in a server room, a queue starts to grow.
Here are the best-documented storms, why they snowball the way they do, and what finally put a brake on them.
Bedlam DL3, the storm that named the genre
According to Osterman’s post, a developer in Microsoft’s internal IT group had built a tool for managing company-wide communications, and it created a set of distribution lists called “Bedlam DL” plus a number, each holding about a quarter of the company’s mailboxes. To most of the people on them, they were a mystery.
On 14 October 1997, according to Rodney Bliss, who was writing Exchange training courses at Microsoft at the time, somebody noticed they were on Bedlam DL3 and did the obvious thing. They emailed it: “Why am I on this mailing list? Please remove me from it.”
Thousands of colleagues had the same question, and a great many of them hit reply-all to say “Me too!” A second wave replied to everyone asking them to stop using reply-all, because it “bogs down the email system”. They were right, and they were helping.
Osterman’s back-of-envelope maths assumed about 13,000 people on the list (his post also mentions 25,000, and retellings vary) and 1,000 replies, which comes to 13 million deliveries. Some of those repliers had read and delivery receipts switched on, so every recipient of their message fired a receipt back: another 2.6 million. Call it 15.5 million messages in about an hour. Exchange’s hidden routing headers bloated every copy, and he put the traffic at 195 GB.
Then the software joined in. Exchange’s message transfer agent had a bug that crashed it on any message with more than 8,000 recipients, but only after delivering to the first 8,000. On restart it retried the queue, sent the same messages to the same 8,000 people, and crashed again. It took about two days of constant work to recover.
The team that fought it had T-shirts made, with “I survived Bedlam DL3” on the front and, on the back, “Me Too!” followed by the addresses of everyone who had replied. Microsoft’s permanent fix was a site-wide limit on the number of recipients a single message could have.
When the storm becomes the entertainment
Bedlam was an accident of plumbing. Later storms showed what people do once they realise they’ve been handed a megaphone.
NYU, 2012: the Replyallcalypse
Just after noon on a Monday in November 2012, NYU’s Bursar’s Office emailed nearly 40,000 students about electronic tax forms. Sophomore Max Wiseltier meant to forward it to his mother. Instead the entire student body received his reply: “Do you want me to do this?” He followed up with an apology, also to everyone.
The message had gone out on a list that, contrary to the university’s usual setup, allowed replies to all 39,979 recipients. Students worked out what that meant and started using it: questions, jokes, pictures of Nicolas Cage. By Thursday Wiseltier was on Jimmy Kimmel Live over Skype, reporting messages that ranged from threats telling him to leave school to people wanting him to run for president.
Cisco, 2013: twice in five weeks
In September 2013 a Cisco employee, nagging managers to get their staff through an online training module, accidentally copied in a mailing list called “sep_training1”. According to an insider who spoke to The Register, it reached about 23,500 people and ran to four million emails, 375 GB of traffic and an estimated $600,000 of lost productivity. Between the unsubscribe requests and the facepalm images, someone proposed that removal requests be submitted as haiku. The storm died down, then picked up again when the US offices woke up and opened their mail.
Five weeks later it happened again, reportedly on a list of 34,562.
Thomson Reuters, 2015: a man named Vince
On 26 August 2015 a message from someone named Vince reached about 33,000 Thomson Reuters inboxes, the Wall Street Journal reported. Hundreds of replies followed, many asking everyone to stop replying. A news agency’s staff being what they are, it was live-tweeted under #ReutersReplyAllGate. “Oh no,” wrote Peter Thal Larsen, “the patient zero of #reutersreplyallgate just sent another company-wide email trying to recall his message.” The company said email had slowed but all systems stayed up.
The NHS: 500 million emails in 75 minutes
The biggest documented storm we could find belongs to the NHS in England. On the morning of Monday 14 November 2016, an IT worker in Croydon sent a blank test message to what she thought was a small local list, CroydonPractices, with fewer than 20 people on it. Then she went home for the afternoon.
NHSmail had moved to a new platform run by Accenture that year, and a configuration error meant the list actually contained every NHSmail account in England: about 840,000 of them. Recipients began replying to ask to be taken off it, and each of those replies went to 840,000 people as well.
By lunchtime one NHS statistician had estimated 186 million emails. The real number was worse. An NHS Digital incident report, obtained by Digital Health, counted 500 million emails in one hour and 15 minutes. A normal day on NHSmail was three to five million, so that was roughly three months of traffic in the length of a film. The service never actually crashed, but queues had built up by 09:45, some staff couldn’t get into their accounts at all, and messages stamped 09:50 were still arriving at 15:45. NHS Digital’s statement to the Guardian had to be dictated over the phone, because of the problems with the email system.
The report was clear about blame: “the individual who created the distribution list was not at fault, and nor were the users who unwittingly used ‘reply to all’.” It also noted that Accenture’s contract had required a limit on how much email one user could send in one go, and that the limit had never been built. The fix on the day was the bluntest one available. NHS Digital switched off reply-all across the entire service.
Bedlam, again
Twenty-two years after the original, it happened at Microsoft again. On 24 January 2019 a message went out to everyone attached to Microsoft’s organisation on GitHub, as many as 11,543 people by one employee’s count. Business Insider heard that the message was, of all things, advice on how to get fewer GitHub notifications. People replied to ask to be removed, others told jokes to their captive audience, and a quirk reportedly re-subscribed anyone who managed to unsubscribe. Several employees reportedly added their own “Me too!”, and the thread was promptly christened “Bedlam V2”, or “Gitlam”.
Why reply-all storms snowball
Every one of these follows the same physics, and very little of it is anyone’s individual fault.
Every reply goes to everyone
In a normal conversation, each reply adds one message. On a big list, each reply is multiplied by the size of the list. Ten replies to a 10,000-person list is 100,000 deliveries; a hundred replies is a million. Divide the NHS’s 500 million by 840,000 recipients and it works out at only about 600 replies’ worth of traffic.
The only visible exit is the list
Internal distribution lists don’t have unsubscribe links. When you find yourself on one you never joined, the only address you can see is the list itself, so “please remove me” goes there, to everyone. The person who could actually remove you is usually not reading.
Complaining about reply-all is reply-all
The “please stop replying to all” message is the storm’s most reliable fuel, and it turns up in nearly every account above. It has survived into the 2020s intact: in September 2023 the US Senate had its own storm after an emergency drill asked staff to reply with their location, and one reply went to everyone.
The machines join in
Read and delivery receipts multiplied Bedlam. Recalls are worse, because recalling a message sends more messages. In 2006 Osterman described another Microsoft incident in which a message sent from a 2,500-member list’s own address was recalled, and every recipient’s Outlook sent a “recall success” or “recall failure” notice back to the list: an estimated 6.25 million emails. It was a security alias, so the members then emailed each other speculating about who was pen-testing the servers. When the US State Department had a storm in 2009, some diplomats tried to recall their replies, which generated another round.
Out-of-office replies could do the same, which is why RFC 3834, the 2004 standard for automatic replies, says vacation notices shouldn’t go out unless your address was explicitly in the To or Cc line, and why Exchange by default doesn’t send group members’ out-of-office replies back to whoever mailed the group. Lists that echo replies out to every subscriber turn all of this into a loop. In 2007 a reader replied to a Department of Homeland Security intelligence bulletin, the list re-sent it to everyone, and more than 2.2 million messages followed.
Servers choke on the queue
Mail servers are sized for normal days. The State Department’s post-storm cable called the result “effectively a denial of service as e-mail queues, especially between posts, back up”. Ordinary mail waits behind the junk, which is how a blank test message held up email across a health service that uses it to share patient information.
What actually fixed them
Mostly, dull settings.
Lock down who can post
A list of thousands should only accept mail from the handful of people meant to send to it. Exchange lets admins restrict who can send to a distribution group and require moderation, and Google Groups has a “Who can post” setting for the same job. Almost every storm above involved a big list that anyone could reply to. After its storm, NHSmail stopped users creating their own dynamic distribution lists. On the sending side, Outlook’s MailTips warn you about a “large audience” when you add a group with more than 25 members.
Stop the storm automatically
Microsoft announced Reply All Storm Protection at Ignite 2019 and had rolled it out to all Office 365 tenants by May 2020. It originally triggered on ten reply-alls to more than 5,000 recipients within 60 minutes, then blocked further reply-alls to that thread for four hours, sending anyone who tried a bounce message instead. Its announcement noted it was already working inside Microsoft, adding that “humans still behave like humans no matter which company they work for”.
In May 2021 Microsoft made it configurable per organisation and lowered the defaults to catch smaller storms:
| Setting | Default | Admins can set |
|---|---|---|
| Minimum recipients | 2,500 (was 5,000) | 1,000 to 5,000 |
| Minimum reply-alls | 10 | 2 to 20 |
| Detection window | 60 minutes | Fixed |
| Block duration | 6 hours (was 4) | 1 to 24 hours |
There’s now a reply-all storm report in the new Exchange admin center, so IT can see storms it has already stopped. The feature is Exchange Online only; if your organisation runs its own Exchange servers or another platform, list permissions are still your main line of defence.
What to do when you’re caught in one
The etiquette is short, and it’s mostly about doing nothing.
Don’t reply. Not to ask to be removed, not to ask others to stop, not “+1”, and not to recall anything. Every one of those is another copy for everyone.
Get it out of your sight instead. Gmail’s Mute and Outlook’s Ignore both take a thread out of your inbox along with its future replies, and a rule on the list’s address works in any client. We’ve covered Outlook rules and Gmail filters if you need a refresher.
If the list is clearly broken, tell IT. One message, to the helpdesk alone. They can kill the list in minutes; ten thousand colleagues can’t.
If you started it, the same applies. Resist the urge to apologise to everyone, as Max Wiseltier did. Tell IT and let them clean it up.
Organisations have tried discipline too. After its 2009 storm, the State Department sent every employee a cable ordering them to stop hitting reply-all on large lists and warning that “anyone who disregards these instructions will be subject to disciplinary actions”. The cable began: “Please ensure widest distribution of this message.”
The bottom line
Reply-all storms look like a story about careless people, but nearly every one was a configuration problem that people then made worse in completely predictable ways. The NHS report said as much: nobody who replied was at fault. Give 840,000 people a way to reply to 840,000 people and some of them will. The fixes that work take the choice away: a locked list, a recipient cap, an automatic brake. Better manners have never scaled to a whole health service.
We make an email client, and we’d love to say it fixes this. It doesn’t, and neither does any other: the storm lives on the server and so does the brake. What a client can do is keep the noise out of the way of the mail that matters, which is most of the argument for running your inbox as a board in the first place.
Frequently asked questions
What is a reply-all storm?
A reply-all storm is a chain reaction on a large email distribution list. One message reaches thousands of people, a few of them reply to everyone, and every reply is copied to the whole list again, which prompts more replies asking to be removed or asking everyone to stop. On a 10,000-person list, a hundred replies means a million deliveries. Big enough storms slow or stall the mail servers themselves.
What was the biggest reply-all storm ever?
The largest well-documented one hit the NHS in England on 14 November 2016. A distribution list bug sent a message to about 840,000 NHSmail accounts, and NHS Digital's own incident report counted 500 million emails in 75 minutes, roughly three months of normal traffic. The most famous is Microsoft's Bedlam DL3 in 1997, which produced an estimated 15.5 million messages and took about two days to clean up.
How do you stop a reply-all storm?
As a recipient, you can't, beyond not adding to it. The fix is administrative: whoever runs the mail system deletes or locks the list, or blocks replies to the thread. Exchange Online does the last part automatically with Reply-all Storm Protection, which by default blocks further reply-alls for six hours once it sees ten within an hour to 2,500 or more recipients. Better still, large lists should only accept mail from approved senders.
Should I reply to ask to be removed from the list?
No. On a distribution list, "please remove me" goes to everyone on it, which is exactly how storms grow, and it rarely gets you removed because the person who owns the list usually isn't reading. Mute or ignore the thread instead (Gmail's Mute and Outlook's Ignore both work), and if the list is clearly misconfigured, send one message to your IT helpdesk, addressed to them alone.
What was Bedlam DL3?
Bedlam DL3 was an internal Microsoft distribution list covering roughly a quarter of the company's mailboxes. In October 1997 someone who found themselves on it emailed the list asking to be removed, and thousands of colleagues replied "Me too!" to everyone. Microsoft developer Larry Osterman estimated about 15.5 million messages in an hour, and a server bug stretched the recovery to two days. Most histories of the reply-all storm start here.


