A robust email, calendaring, and collaboration platform developed by Microsoft, designed for enterprise-level communication and data management.Miscellaneous topics that do not fit into specific categories.
S3150 block on our own /27 — delist portal says "not qualified", no response on SR since 04 Aug
Since 2026-07-29 10:39 CEST, every message from our mail server to Outlook.com
consumer domains (hotmail.de, hotmail.com, outlook.de, outlook.com, live.de) is
rejected at the MAIL FROM stage with S3150. Delivery to all other providers is
unaffected. Before that date, mail to Outlook.com had been delivered normally
from the same IP for years, and nothing changed on our side.
Verbatim NDR (recipient redacted):
<redacted>@hotmail.com: host hotmail-com.olc.protection.outlook.com[52.101.8.53]
said: 550 5.7.1 Unfortunately, messages from [89.238.74.203] weren't sent.
Please contact your Internet service provider since part of their network is on
our block list (S3150). You can also refer your provider to
http://mail.live.com/mail/troubleshooting.aspx#errors. [Name=Protocol Filter
Agent][AGT=PFA][MxId=11BDDB66C69D2C4D]
[DS3PEPF0000C37B.namprd04.prod.outlook.com 2026-08-04T10:12:27.115Z
08DEEDB36831B5DD] (in reply to MAIL FROM command)
SENDING SOURCE
IP: 89.238.74.203 (single dedicated mail server, Postfix)
PTR: mail.syssofttec.de, forward-confirmed
RIPE inetnum: 89.238.74.192 - 89.238.74.223, netname SYSSOFTTEC-2,
ASSIGNED PA, registered to our own company
Upstream: manitu GmbH, AS34240 (Germany)
The flagged range is our own /27. There are no third-party tenants in it. Only
.203 is configured to send mail and it is the only address in the block with a
dedicated PTR record.
AUTHENTICATION
SPF v=spf1 mx a -all (MX = 89.238.74.203, pass)
DKIM selector "dkim", RSA-2048, all outbound mail signed
DMARC v=DMARC1; p=reject; rua=mailto:<redacted>
TLS on all outbound connections.
REPUTATION
I checked all 32 addresses of the /27 against Spamhaus ZEN, Barracuda,
SpamCop, PSBL and NiX Spam. Not a single listing.
TRAFFIC PROFILE
Purely transactional and recipient-initiated: confirmation messages for
daycare-place applications, sent on behalf of German municipalities. Each
message is triggered by a parent submitting a web form and is addressed to
that person only. A few messages per day. No marketing, no newsletters, no
purchased lists, no bulk mail.
WHAT I HAVE ALREADY DONE
- Submitted a delisting request. The automated reply came back "Not qualified for mitigation" for the entire range 89.238.74.192 - 89.238.74.223.
- Replied to that thread on 2026-08-04 with the full NDR, the authentication details and the traffic profile, as the mail instructed, to have an agent review the case. No response so far. Service request number: 01KZ8ZKTNJ7CNP1DMBKWWK70XY
- Registered and authorised the IP in SNDS; JMRP enrolment in progress.
THE PROBLEM WITH WAITING
Because the rejection happens at MAIL FROM, no message is ever accepted, so no
new positive sending signal can accumulate and SNDS shows no data. The block
cannot resolve itself over time — it needs either a manual review or a change
of sending path.
QUESTIONS
- Could someone from the Outlook.com Deliverability team pick up service request 01KZ8ZKTNJ7CNP1DMBKWWK70XY? Two days without a reply may be normal, but I have no way to tell whether the reply entered the queue at all.
- With no public blocklist entry, correct SPF/DKIM/DMARC/FCrDNS and a purely transactional volume of a few messages per day, which signal typically drives an S3150 decision? I would rather fix the cause than keep asking for mitigation.
- Does SNDS retain data from before a block was applied? The interesting period is the week before 2026-07-29, which would show the complaint rate that triggered this.
- Is mitigation possible for the individual IP 89.238.74.203 instead of the whole /27, given that we control every address in that range?
Thanks in advance.