IP Address: 209.85.220.69 โ IP Confounder
Dormant. IP address 209.85.220.69 is registered to Google LLC and geolocates to United States. It first appeared in sh4meful's dataset on March 12, 2024 and was most recently observed on June 23, 2026. Over the observation window, it has failed DMARC alignment 170 times across 10 distinct sender domains. Its reverse DNS resolves to mail-sor-f69.google.com. Network context: this address sits within GOOGLE (Google LLC), a network sh4meful has observed producing 822 failures across 185 distinct IPs during the same window. This volume is elevated relative to most IPs observed in sh4meful's dataset and warrants closer scrutiny.
Failure Activity Over Time
This page shows DMARC authentication failure data for this IP address. Learn more about this data.
Geolocation Information
- Country:
- US United States
- Coordinates:
- 37.751, -97.822
WHOIS Information
- Network Name:
- CIDR:
209.85.128.0/17- Owner:
- Google LLC
- Org ID:
GOGL- Address:
- 1600 Amphitheatre Parkway, Mountain View, CA 94043
- Reverse DNS:
-
mail-sor-f69.google.com
Last updated: 2/5/2026
Analysis
This IP is classified as a confounder: Google (mail-sor-f69.google.com). Failures observed from this source are expected artifacts of legitimate mail-handling behavior, typically email forwarding or mailing-list processing, and do not indicate spoofing attempts.
The host is operated by Google LLC and geolocates to United States. Its presence in DMARC aggregate reports is an artifact of how forwarded mail interacts with SPF and DKIM authentication, not a sign of abuse originating from this address.
Administrators observing this IP in their DMARC aggregate reports should not block or treat it as hostile. Google Workspace relay addresses appear in DMARC reports for mail routed through Google's filtering infrastructure. Ensure your SPF record includes Google's published mail server ranges if you use Google Workspace.
Google, and Google Cloud Platform (GCP)
This is (part of) the GCP public cloud. Some email protection services run in GCP, but it is also an attack/spam vector.
IP Confounder: Google (mail-sor-f69.google.com)
The server, mail-sor-f69.google.com (IP address 209.85.220.69), belongs to Google and is acting as an outbound mail server for Gmail/Google Workspace users. While part of Google's network, it has been reported for sending emails that may fail SPF or DMARC alignment, often because the sending domain's SPF record does not include this specific IP or the DKIM signature is missing. Key Details Regarding 209.85.220.69: - Validity: It is a legitimate Google IP, generally not considered a "bad bot," but it is frequently involved in reporting scenarios where emails fail authentication. Sources: Gemini (retrieved 29-Jan), Dmarcian (https://forum.dmarcian.com/t/google-server-69-failing-dkim/1758)
Network Topology
This address is part of GOOGLE (Google LLC), announced from United States. 185 IPs in this network have been observed in sh4meful's dataset.
Failures Detected from this IP
Showing 1-50 of 170 failures, affecting 1,265 messages| Date โผ | Messages |
|---|---|
| 6/23/2026 | 10 |
| 6/19/2026 | 2 |
| 6/18/2026 | 3 |
| 6/17/2026 | 2 |
| 6/16/2026 | 1 |
| 6/5/2026 | 4 |
| 6/4/2026 | 3 |
| 6/3/2026 | 2 |
| 6/2/2026 | 1 |
| 5/15/2026 | 4 |
| 5/14/2026 | 3 |
| 5/13/2026 | 2 |
| 5/12/2026 | 2 |
| 4/10/2026 | 1 |
| 4/9/2026 | 3 |
| 4/8/2026 | 2 |
| 4/7/2026 | 1 |
| 3/27/2026 | 2 |
| 3/26/2026 | 3 |
| 3/25/2026 | 2 |
| 3/24/2026 | 1 |
| 3/13/2026 | 2 |
| 3/12/2026 | 3 |
| 3/11/2026 | 4 |
| 3/10/2026 | 1 |
| 2/27/2026 | 2 |
| 2/26/2026 | 3 |
| 2/25/2026 | 4 |
| 2/24/2026 | 2 |
| 1/30/2026 | 1 |
| 1/29/2026 | 4 |
| 1/28/2026 | 1 |
| 1/26/2026 | 1 |
| 1/16/2026 | 2 |
| 1/15/2026 | 4 |
| 1/14/2026 | 1 |
| 1/12/2026 | 1 |
| 1/9/2026 | 2 |
| 1/8/2026 | 4 |
| 1/7/2026 | 1 |
| 1/5/2026 | 1 |
| 12/19/2025 | 2 |
| 12/18/2025 | 3 |
| 12/17/2025 | 4 |
| 12/16/2025 | 2 |
| 12/12/2025 | 2 |
| 12/11/2025 | 4 |
| 12/8/2025 | 1 |
| 12/5/2025 | 4 |
| 12/4/2025 | 7 |
External Reputation Lookups
Look up this IP in external threat intelligence and reputation databases (opens in new tab):
Nearby IPs
The following IP addresses share the same /24 subnet as 209.85.220.69 and have appeared in sh4meful's dataset. Related activity in nearby addresses often indicates infrastructure operated by a single actor or provider.
- 209.85.220.41 โ 369 failures, first seen 2 years ago, the same day as this address.
- 209.85.220.97 โ 43 failures, first seen 2 years ago, the same day as this address.
- 209.85.220.101 โ 26 failures, first seen 1 year ago, 231 days after this address.
- 209.85.220.65 โ 5 failures, first seen 2 years ago, 4 days before this address.
Recommended Action
If this IP appears in your own DMARC reports, treat it as an unauthorized sender unless you have specifically verified it as a legitimate service you use. Ensure your DMARC policy is at p=quarantine or p=reject to prevent delivery of messages this IP claims to send from your domain. If you're new to DMARC, our complete guide walks through the mechanics.