The Pragmatic Addict

Microsoft SMTP block lists

Background

Completely out of the blue I received a similar message when trying to send mail to outlook.com live.com hotmail.com & msn.com

host msn-com.olc.protection.outlook.com[52.101.41.123]
    said: 550 5.7.1 Unfortunately, messages from [97.107.133.211] weren't sent.
    Please contact your Internet service provider since part of their network
    is on our block list (S3150). You can also refer your provider to
    http://mail.live.com/mail/troubleshooting.aspx#errors. [Name=Protocol
    Filter Agent][AGT=PFA][MxId=11BE4A91A461D87F]
    [BY1PEPF000264AF.namprd02.prod.outlook.com 2026-10-09T23:50:55.394Z
    08DF2548D36B9F2E] (in reply to MAIL FROM command)
Our servers have been sending mail to these domains for years without any issues and this pops up out of the blue. In full disclosure, yes we do all the SPF,DKIM,DMARC stuff and we are not on any public block lists.

Searching around it took a while to find an appropriate course of action. The link they send is close to worthless in trying to resolve the issue. It would be nice if they gave more of an explanation.

Open a support ticket with Microsoft

To my genuine surprise after opening a ticket on olcsupport.office.com, I got a quick automated response. My first IP address was resolved immediately by their automated system, the second took an escalation. I should also note that immediately means they made their decicision, it takes up to 48 hours to propogate the waiver through their system (Yup, dog slow).

The escalation wasn’t horrible, I had to plead my case that my IP was doing all the correct stuff and wasn’t on any public block lists. They insisted that they got complaints from hotmail users that we were sending abusive emails. I went through 2 months of logs and detailed all of our messages sent thru, since we are a small site there were only a handful and of those we personally knew.

They escalated and 24 hours later they unblocked the IP address.

Behind the scenes

This is more conjecture but I’ve had this happen once before with Microsoft about 10 years ago. We were the vicitim of subnet collateral damage. Basically if Microsoft sees any kind of hinky stuff going on in your /24 subnet they just blacklist the whole thing. It’s really annoying with a VPS since you never know who your neighboors are. Because this is olc.protection.outlook.com the block happens for all of Microsoft’s free mailboxes.

How to protect your servers

I found a great resource in the Microsoft Q&A (I know this is very rare). The MS blocklist (S3140) query post had a good Anonymous response which pointed me how to to open a ticket and also to register for SNDS.

They highly recommend registering for SNDS (Smart Network Data Services). This is only a way to register your IP addresses so you will get notificiations if Microsoft has any complaints. It also keeps a good log of which IP address was reported on and by what service.

Going forward this is something you can point to if Microsoft claims you have complaints. You can point them to their own data to prove your case.

I would also highly recommend having 2 outbound servers with two different VPS providers (or at least on different subnets). At least if one gets dinged you have a backup.


Created: 2026-10-11 Modified: 2026-10-11