Emails are rejected due to IP 40.95.89.66

Spf Record 11 Reputation points
2021-02-02T21:15:30.367+00:00

Microsoft 365 emails are rejected with spf validation error. Log shows that email originated from M365 IP 40.95.89.66 which is not included in SPF subnet of 40.95.0.0/15.

Please advise if there is roadmap to include this in M365 SPF subnet. If yes, please include this in M365 documentations for everyone's visibility.

Microsoft Exchange Online Management
Microsoft Exchange Online Management
Microsoft Exchange Online: A Microsoft email and calendaring hosted service.Management: The act or process of organizing, handling, directing or controlling something.
4,285 questions
{count} votes

5 answers

Sort by: Most helpful
  1. scottlan 11 Reputation points Microsoft Employee
    2021-02-05T14:14:59.267+00:00

    I haven't been able to check to see if that range should be included or not - but first, could you check to make sure that your messages are routing via the normal delivery pool, vs. being seen as high risk? Some delivery pools are intentionally excluded from SPF. Thanks!

    https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/high-risk-delivery-pool-for-outbound-messages?view=o365-worldwide

    1 person found this answer helpful.
    0 comments No comments

  2. Håkan Näslund 1 Reputation point
    2021-02-02T22:52:57.99+00:00

    To clarify...

    The spf for M365 (spf.protection.outlook.com) returns the following ip4 networks:
    40.92.0.0/15
    40.107.0.0/16
    52.100.0.0/14
    104.47.0.0/17
    51.4.72.0/24
    51.5.72.0/24
    51.5.80.0/27
    51.4.80.0/27

    None of these covers source address 40.95.89.66

    The first one would, if the mask had been 14 and not 15.

    0 comments No comments

  3. Tomass Pētersons 336 Reputation points
    2021-02-03T12:51:08.583+00:00

    You are not alone - https://learn.microsoft.com/en-us/answers/questions/250845/e-mail-message-rejected-by-icloud-because-of-dmarc.html

    Looks like someone at Microsoft got lazy and forgot to add all IP's to SPF records.

    0 comments No comments

  4. Robert Rowan 1 Reputation point
    2021-02-10T08:46:44.673+00:00

    I've been seeing the same thing since mid January on a handful of outbound email. I'm seeing outbound IPs in the 40.95.78.x-40.95.80.x range. We're getting back NDRs saying:

    Reason: LED=550 40.95.78.189 is not allowed to send mail from mydomain.com. Please see the SPF record, with scope mfrom, identity first.last@mydomain.com, and ip 40.95.78.189

    Checking MXtoolbox SPF shows these IPs are not the spf.protection.outlook.com record. I have a ticket open with the 365 support team but the only solution they came up with is to add random IP addresses to our own SPF record :(


  5. Mark Alley 0 Reputation points
    2023-02-14T18:43:45.76+00:00

    The reason these are not in the spf.protection.outlook.com SPF record is because the subnet 40.95.0.0/16 is used for the "High Risk Delivery Pool". Also, there are IPs used by the "Relay" IP pool, which is not publicly published, and also does not appear in the SPF record. Both of these are by design.

    https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/outbound-spam-high-risk-delivery-pool-about?view=o365-worldwide

    0 comments No comments