IP Address: 2a01:111:f403:c001::2
Differentiating between Office 365, including email protection services, and Azure (public cloud) when diagnosing incidents is challenging because they utilize shared Microsoft-owned IP ranges. Most of this is probably O365/Outlook or Defender protection breaking DKIM and SPF authentication. Disambiguation is a work-in-progress.
About this Data
▶The data here is from DMARC analysis for domains I administer, drawn from a larger dataset (comprising millions of authentication records and messages). These entries are from email attempts that failed both SPF and DKIM (and there are often alignment issues - hidden here). In many cases, these failures indicate unauthorized use of the domain name, and are commonly associated with spoofing, phishing, or other abusive mail activity.
Geolocation Information
- Country:
- US United States
- Region:
- California
- City:
- San Jose
- Coordinates:
- 37.3388, -121.8916
WHOIS Information
- Network Name:
- UK-MICROSOFT-20060601
- Owner:
- ORG-MA42-RIPE
- Reverse DNS:
-
mail-westusazlp170120002.outbound.protection.outlook.com
Last updated: 2/5/2026
Failures Detected from this IP
Showing 51-84 of 84 (failures, affecting 330 messages)| Date ▼ | Messages |
|---|---|
| 9/19/2025 | 9 |
| 9/18/2025 | 7 |
| 9/17/2025 | 6 |
| 9/16/2025 | 1 |
| 9/13/2025 | 3 |
| 9/12/2025 | 7 |
| 9/11/2025 | 6 |
| 9/10/2025 | 6 |
| 9/6/2025 | 1 |
| 8/22/2025 | 2 |
| 8/1/2025 | 2 |
| 7/31/2025 | 3 |
| 7/18/2025 | 1 |
| 7/11/2025 | 1 |
| 7/10/2025 | 1 |
| 7/9/2025 | 3 |
| 7/3/2025 | 3 |
| 7/2/2025 | 1 |
| 7/1/2025 | 5 |
| 6/27/2025 | 2 |
| 6/19/2025 | 2 |
| 6/4/2025 | 2 |
| 5/16/2025 | 1 |
| 5/9/2025 | 2 |
| 5/2/2025 | 4 |
| 5/1/2025 | 1 |
| 4/16/2025 | 1 |
| 3/19/2025 | 1 |
| 2/28/2025 | 1 |
| 2/26/2025 | 1 |
| 2/14/2025 | 5 |
| 12/18/2024 | 1 |
| 9/26/2024 | 1 |
| 9/12/2024 | 3 |