Metainformationen zur Seite
  •  

Unterschiede

Hier werden die Unterschiede zwischen zwei Versionen der Seite angezeigt.

Link zu der Vergleichsansicht

Beide Seiten, vorherige ÜberarbeitungVorherige Überarbeitung
Nächste Überarbeitung
Vorherige Überarbeitung
mail:microsoft_ip-sperre_aufheben [2023/05/22 10:35] – gelöscht - Externe Bearbeitung (Unknown date) 127.0.0.1mail:microsoft_ip-sperre_aufheben [2026/10/06 13:00] (aktuell) – [Kontakt aufnehmen] 195.16.228.206
Zeile 1: Zeile 1:
 +====== IP-Sperre von Microsoft aufheben lassen ======
 +
 +Microsoft sperrt anhand von unklaren Richtlinien scheinbar wahllos IP-Adressen für die Maileinlieferung zu ihren Diensten (outlook.com, hotmail.com, live.de,...). Traurige Beispiele dafür findest du bei [[https://disroot.org/de/blog/microsoft_hostility|Disroot]] und [[https://blog.paranoidpenguin.net/2020/07/my-mail-server-got-blocked-by-outlook-com/|hier]]. Nachfolgend findest du ein paar Hinweise zum Vorgehen, um die eigene IP-Adresse entsperren zu lassen.
 +
 +===== Eine Sperre erkennen =====
 +
 +  * Auf der Ebene des Mailservers ist die Sperrung an gescheiterten TLS-Verbindungen zu MS-Diensten zu erkennen:<code>
 +relay=hotmail-com.olc.protection.outlook.com[104.47.0.0]:25, delay=2.9, delays=2/0/0.67/0.18, dsn=5.7.1, status=bounced (host hotmail-com.olc.protection.outlook.com[104.47.0.0] said:
 +550 5.7.1 Unfortunately, messages from [51.75.0.0] weren't sent. Please contact your Internet service provider since part of their net work is on our block list (S3140).
 +You can also refer your provider to http://mail.live.com/mail/troubleshooting.aspx#errors. [SG2APC01FT042.eop-APC01.prod.protection.outlook.com]
 +</code>
 +  * Der Umfang der Sperre lässt sich anhand des Fehler-Codes erkennen:
 +    * S3140: IP ist vollständig blockiert,
 +    * S3150: IP ist gedrosselt.
 +  * Über den [[https://sendersupport.olc.protection.outlook.com/snds/|Smart Network Data Service]] (SNDS) kannst du den Status deiner IP-Adressen einsehen. Eine vorherige Anmeldung ist dafür notwendig.
 +
 +===== IP Testen =====
 +
 +Die folgenden Tests geben Hinweise darauf, ob mit deinem Setup alles in Ordnung ist:
 +  * https://www.mail-tester.com/
 +  * https://www.internet.nl/
 +  * https://talosintelligence.com/reputation_center
 +  * https://www.suped.com/tools/email-tester
 +
 +Delisting request — IP 194.164.48.221 blocked by Outlook.com/Hotmail (S3150)
 +
 + Hello,
 +
 +  I would like to request review/delisting of IP address 194.164.48.221 from the Outlook.com/Hotmail block
 +  list.
 +
 +  Server details:
 +  - Sending IP: 194.164.48.221
 +  - Hostname (PTR and forward DNS match): web02.kohlweiss.domains
 +  - Mail software: Postfix on Linux (Plesk-managed)
 +
 +  Rejection observed:
 +  On 2026-10-06 at 08:46:19 UTC, a legitimate message was rejected during the MAIL FROM phase with:
 +
 +  550 5.7.1 Unfortunately, messages from [194.164.48.221] weren't sent. Please contact your Internet service
 +  provider since part of their network is on our block list (S3150). You can also refer your provider to
 +  http://mail.live.com/mail/troubleshooting.aspx#errors. [Name=Protocol Filter
 +  Agent][AGT=PFA][MxId=11BE461A669B11DA] [MI3PEPF0000855E.eurprd05.prod.outlook.com 2026-10-06T08:46:19.748Z
 +  08DF230D33EB04E7]
 +
 +Checks performed and findings:
 +  - Reviewed the Postfix mail queue: empty, no backlog.
 +  - Reviewed mail logs for the affected period: normal, low outbound volume. No evidence of a compromised
 +    mailbox, unauthorized relay use, unusual SASL authentications, or script/webform abuse.
 +  - Verified PTR record for 194.164.48.221 resolves to web02.kohlweiss.domains, matching the server's forward
 +    DNS (A record) and its SMTP EHLO name.
 +  - Implemented and verified SPF, DKIM (2048-bit RSA), and DMARC for the affected sender domain
 +    (virgolini.com).
 +  - Confirmed via independent third-party test (mail-tester.com, score 7.9/10) that SPF, DKIM, and DMARC all
 +    pass, and that this IP is not listed on any of 20 common public blocklists, including Spamhaus SBL, XBL,
 +    PBL, and CSS.
 +
 +  Given the very low and normal sending volume, the absence of any abuse indicators, fully compliant
 +  authentication, and a clean reputation across all checked blocklists, we believe this IP (or a shared range
 +  it belongs to) was listed as a result of activity from other senders on the same network, rather than from
 +  this server. We would appreciate confirmation of what is required for delisting, and whether this is an
 +  IP-specific listing or a range-level one.
 +
 +  The complete SMTP rejection / NDR is attached below for reference.
 +
 +  Thank you for your assistance.
 +
 +  Regards,
 +  Thomas Kohlweiss