Skip to content

What to do when your cheap IP gets blacklisted by Microsoft

General Discussion by kat_fold 23 replies 1.2K views
6 #1

Hey folks

I see a lot of confusion when cheap IPv4s land on Microsoft's blocklists, so here's a quick reference.

First, check your IP reputation at sender.office.com — that's Microsoft's own tool. If you're listed, you'll need to fill out their delisting form (the JMRP one). Be honest about your mail volume and opt-in practices. They usually respond in 24-72 hours, sometimes longer for repeat listings.

For Gmail equivalents, use postmaster.google.com and their Bulk Sender Guidelines form. Yahoo uses their Complaint Feedback Loop via their postmaster site.

Keep your PTR records clean, maintain valid SPF/DKIM/DMARC, and never try to game the system with fake domains. The big providers share data.

Pinning this for a week. Questions welcome, but read the sticky first 🙂

~be kind or be gone~
3 #2
kat_fold said:
For Gmail equivalents, use postmaster.google.com and their Bulk Sender Guidelines form.

I feel you on the frustration — a lot of budget hosts hand out IPs that were burned by the previous tenant and the new user has no idea. The delisting forms work but you have to show you're not the same sender. I always tell people to request IP history if possible, though most cheap hosts won't have it. The real fix is dedicated sending infrastructure but I get that's not in the $3/year budget lol

#3

How do I know if im blacklisted in the first place? My emails to my professor keep bouncing and I dont know why. Im on a student plan from contabo.com

Is there like a free tool I can use! Thanks everyone

#4

I run 52 boxes across 8 providers and here's my take:

  • Delisting forms: works 60% of the time, takes 3 days avg
  • New IP from same range: usually still dirty
  • New IP from different range: 40% clean in my experience

Contabo.com and ovhcloud.com both gave me ranges that were toast on arrival. Vultr.com was cleanest so far but their $/GB is trash 😂

My actual workflow now:

  • Spin up box
  • Test mail to my own gmail + outlook
  • If blacklisted, destroy and repeat
  • Once clean, keep that IP forever

Yes this is stupid. Yes it works.

seedbox, NAS, tape, and three offsite
#5
hankels said:
If blacklisted, destroy and repeat

I used to work support at a different host, and IP cycling was never the answer there either.

What I do with Hetzner now:

  • Submit delisting requests through official provider channels
  • Maintain dedicated /29 or larger allocations for mail operations
  • Implement proper warm-up schedules (50 messages day 1, doubling weekly)
  • Monitor reputation via their included SNDS and Google Postmaster dashboards

For persistent issues, their support team provides RFC-compliant guidance at no charge. Their docs are here: https://docs.hetzner.com

I am a customer, not staff.

#6

What does SNDS show for your IP specifically

airgapped, encrypted, faraday'd, still worried
#7

50 messages day 1 on a student plan, sure

swimming upstream since 2019 🐟
#8
Rick20 said:
My emails to my professor keep bouncing

Check the bounce message in your mail client. If it says something like "550 SC-001" or references "protection.outlook.com" that's Microsoft blacklisting. Contabo's student plans are in the Nuremberg or Munich DCs usually, and those ranges get heavy use from spammers.

Free tool: mxtoolbox.com does a quick blacklist check against 100+ lists. Also just try telnet to outlook-com.olc.protection.outlook.com port 25 and see if you get a 4xx or 5xx before you even say HELO.

#9

Thanks AdamGsm! I tried mxtoolbox and it says I'm on UCEPROTECT Level 2. Is that the same thing as Microsoft? My bounce says "550 5.7.1 Unfortunately, messages from [my ip] weren't sent." That sounds like Microsoft right?

#10
Rick20 said:
UCEPROTECT Level 2

Different thing entirely. UCEPROTECT is a private blacklist, Microsoft uses their own internal SmartScreen and Exchange Online Protection data. Your 5.7.1 with that wording is absolutely Microsoft's filter.

UCEPROTECT Level 2 means your whole /24 is listed because multiple IPs in the range sent spam. Contabo's Nuremberg ranges are notorious for this. The bad news: only your provider can get the range delisted from UCEPROTECT, and they usually don't bother for budget plans. The good news: Microsoft's delisting form doesn't care about UCEPROTECT.

Fill out the JMRP form kat_fold mentioned. Meanwhile ask Contabo support if they can move you to a cleaner subnet, though at 4 EUR/month don't hold your breath.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft