Skip to content

What to do when your cheap IP gets blacklisted by Microsoft

General Discussion by kat_fold 23 replies 1.2K views
#11
harbourops said:
Their support team provides RFC-compliant guidance at no charge

Hetzner's support is solid but let's be real, their Falkenstein ranges aren't magically clean either. I got a /29 there last year that was already warm. The difference is they'll actually engage with SNDS and help you document sender reputation, whereas Contabo's support ticket will sit for a week then tell you to use their webmail.

The warm-up schedule you listed is mail industry standard, not Hetzner-specific. Works anywhere you have a clean IP and a provider that doesn't rate-limit you into the ground.

seedbox, NAS, tape, and three offsite
#12
hankels said:
Falkenstein ranges aren't magically clean

Fair. I've had two dirty allocations from them in three years, both resolved by support escalation within 48 hours. The /29 pricing starts at 8.40 EUR/month for the IP block itself, so it's not comparable to a 4 EUR VPS obviously.

My point was more about process than provider worship. Document everything, use official channels, warm up properly. Cycling IPs without fixing the underlying reputation problem is how you end up with providers that just ban mail ports entirely. I've seen that happen at two budget hosts now.

#13
hankels said:
If blacklisted, destroy and repeat

This is how you train providers to require identity verification for every new instance. Already seeing it with some hosts in Poland.

I test from Kraków on a local ISP static IP first, then migrate to VPS only after the reputation is established. Backwards from how most people do it, but my delivery rates are better than most hosted solutions.

9 #14

Seattle-based here. I just went through this with Vultr's Seattle DC. IP was clean at spinup, got blacklisted by Microsoft after three weeks of legitimate transactional mail (receipts, password resets, maybe 200/day).

Turns out Vultr had reassigned that IP from a previous customer who was running cold email campaigns. The Microsoft block followed the IP, not the domain or the sending history.

Delisting took 8 days. Now I keep IPs for a minimum 90 days before trusting them for anything critical. Also using Amazon SES as a fallback, which feels dirty but works.

#15
jackdrag said:
Amazon SES as a fallback

This. For anyone actually running client sites, a proper transactional mail service is the answer, not wrestling with VPS IP reputation. Postmark, Mailgun, SendGrid, pick one. The API takes an hour to integrate and you stop being collateral damage in some Romanian bulletproof hoster's war with Microsoft.

The "I want to self-host everything" crowd always shows up in these threads. Great, you run your own Postfix. You're also one compromised WordPress plugin away from being a spam source that gets your whole range listed.

swimming upstream since 2019 🐟
#16
ana_mad said:
One compromised WordPress plugin away from being a spam source

Ran an ISP for eleven years, saw this exact pattern kill more small operators than anything else. The economics of IPv4 reputation are brutal now.

Back in 2012 you could get clean space and maintain it with basic hygiene. Today the major mail receivers have tightened thresholds so much that a single compromised customer in a /24 can poison the whole neighborhood for weeks. Microsoft and Google both use network-level reputation signals now, not just per-IP.

For students and hobbyists: the free tiers at Mailgun or SendGrid are genuinely your best path. For anyone claiming they "need" self-hosted mail for privacy, run your own submission server and relay through a reputable outbound provider. You keep your data at rest, they handle delivery.

2 #17

Following this thread closely. I'm on OVHcloud's Warsaw DC and my IP is clean so far but I haven't tried mailing to Outlook addresses yet. Is there a quick test I can do without setting up full mail infrastructure?

#18
Key56 said:
Is there a quick test I can do without setting up full mail infrastructure?

Swaks. One-liner:

swaks --to [email protected] --from [email protected] --server your.server.ip

If you get a 250 queued, you're probably fine. 4xx or 5xx with references to protection.outlook.com or SC-001, you're listed. You don't need SPF/DKIM for the initial connectivity test, though you'll want them before real sending.

Install with apt on Debian/Ubuntu, or it's a single Perl script you can curl if you don't want packages.

airgapped, encrypted, faraday'd, still worried
#19

Worked perfectly, got 250 queued. Thanks olespete!

4 #20
olespete said:
Swaks

Swaks is great but be careful running this from work machines. A lot of corporate firewalls flag outbound port 25 as suspicious and you might end up explaining to IT why you're "sending spam."

For a safer test, use mail-tester.com instead. Sends through their infrastructure so no local port 25 needed, and you get a full SPF/DKIM/DMARC/RDNS report back. Score above 8 and you're in decent shape for most receivers.

Honey badger don't care... about downtime

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft