Mail delivery issue - SpamHaus involved

David Touitou 0 Reputation points
2025-04-29T09:29:56.61+00:00

Hello.

We're hosting mails for customers (outside of M365).

Since last week, some of our outgoing relays are getting bounced by M365.
Some mails go through and some other are blocked (same outgoing relay, same sender, same recipient).

The bounce message states this is because the relays IP are listed in SpamHaus.

550 5.7.1 Service unavailable, Client host [aaa.bbb.ccc.ddd] blocked using Spamhaus. To request removal from this list see https://www.spamhaus.org/query/ip/aaa.bbb.ccc.ddd AS(1440) [PA3PEPF000089BB.FRAP264.PROD.OUTLOOK.COM 2025-04-29T09:12:41.378Z 08DD86E7F1133478] (in reply to RCPT TO command))

If we check the IPs directly in SpamHaus (or follow the link that is given by M365 in the bounce message), the IP are clean. Not even "previously listed", clean: "IP has no issues".

What is going on?

Microsoft 365 Publishing
Microsoft 365 Publishing
Microsoft 365: Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.Publishing: The process of preparing, producing, and releasing content for distribution or sale.
688 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Hien-L 3,215 Reputation points Microsoft External Staff Moderator
    2025-04-30T07:08:16.24+00:00

    Hi @David Touitou ,

    Welcome to our forum!

    Based on your description, I understand the frustration of email delivery issues. It seems that although the host has been removed from the Spamhaus blocklist, your business partner is still experiencing issues. There are a few steps you can take to resolve this issue:

    1. M365 caches Spamhaus blocklist results for 1–4 hours after removal. Even if Spamhaus delists your IP, Microsoft’s servers might still use outdated cached data during this window

    The email server may have cached the blocklist information. In this case, restarting the email server or clearing the DNS cache may help.

    1. Ensure SPF, DKIM, and DMARC are properly configured. M365 prioritizes authenticated emails, use tools like MXToolbox to verify your DNS records.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.