IP Address: 2a01:111:f403:c105::7
Differentiating between Office 365, including email protection services, and Azure (public cloud) when diagnosing incidents is challenging because they utilize shared Microsoft-owned IP ranges. Most of this is probably O365/Outlook or Defender protection breaking DKIM and SPF authentication. Disambiguation is a work-in-progress.
About this Data
▶The data here is from DMARC analysis for domains I administer, drawn from a larger dataset (comprising millions of authentication records and messages). These entries are from email attempts that failed both SPF and DKIM (and there are often alignment issues - hidden here). In many cases, these failures indicate unauthorized use of the domain name, and are commonly associated with spoofing, phishing, or other abusive mail activity.
Geolocation Information
- Country:
- US United States
- Region:
- Illinois
- City:
- Chicago
- Coordinates:
- 41.8835, -87.6305
WHOIS Information
- Network Name:
- UK-MICROSOFT-20060601
- Owner:
- ORG-MA42-RIPE
- Reverse DNS:
-
mail-northcentralusazlp170130007.outbound.protection.outlook.com
Last updated: 2/5/2026
Failures Detected from this IP
Showing 51-76 of 76 (failures, affecting 317 messages)| Date ▲ | Messages |
|---|---|
| 11/12/2025 | 6 |
| 11/13/2025 | 1 |
| 11/14/2025 | 4 |
| 11/19/2025 | 6 |
| 11/20/2025 | 7 |
| 11/21/2025 | 7 |
| 11/22/2025 | 2 |
| 12/2/2025 | 2 |
| 12/3/2025 | 9 |
| 12/4/2025 | 2 |
| 12/5/2025 | 11 |
| 12/9/2025 | 1 |
| 12/13/2025 | 1 |
| 12/16/2025 | 1 |
| 12/17/2025 | 4 |
| 12/18/2025 | 5 |
| 12/19/2025 | 7 |
| 12/20/2025 | 1 |
| 1/6/2026 | 1 |
| 1/7/2026 | 10 |
| 1/8/2026 | 4 |
| 1/14/2026 | 5 |
| 1/15/2026 | 1 |
| 1/28/2026 | 1 |
| 1/29/2026 | 2 |
| 1/30/2026 | 2 |