IP Address: 40.107.243.124 โ IP Confounder
This page shows DMARC authentication failure data for this IP address. Learn more about this data.
Geolocation Information
- Country:
- US United States
- Region:
- Iowa
- City:
- Des Moines
- Coordinates:
- 41.6015, -93.6127
WHOIS Information
- Network Name:
- MSFT
- CIDR:
40.96.0.0/12, 40.74.0.0/15, 40.124.0.0/16, 40.125.0.0/17, 40.80.0.0/12, 40.120.0.0/14, 40.112.0.0/13, 40.76.0.0/14- Owner:
- Microsoft Corporation
- Org ID:
MSFT- Address:
- One Microsoft Way, Redmond, WA 98052
- Reverse DNS:
-
mail-dm6nam12on2124.outbound.protection.outlook.com
Last updated: 2/5/2026
Analysis
This IP is classified as a confounder: Microsoft 365 Exchange Online Protection (EOP). Failures observed from this source are expected artifacts of legitimate mail-handling behavior, typically email forwarding or mailing-list processing, and do not indicate spoofing attempts.
The host is operated by Microsoft Corporation and geolocates to Des Moines, United States. Its presence in DMARC aggregate reports is an artifact of how forwarded mail interacts with SPF and DKIM authentication, not a sign of abuse originating from this address.
Administrators observing this IP in their DMARC aggregate reports should not block or treat it as hostile. Microsoft Exchange Online Protection (EOP) and Office 365 relay addresses appear in DMARC reports for mail routed through Microsoft's filtering infrastructure. Ensure your SPF record includes Microsoft's published mail server ranges.
Microsoft Network (365 vs Azure)
Differentiating between Office 365, including email protection services, and Azure (public cloud) when diagnosing incidents is challenging because they utilize shared Microsoft-owned IP ranges. Most of this is probably O365/Outlook or Defender protection breaking DKIM and SPF authentication. Disambiguation is a work-in-progress.
IP Confounder: Microsoft 365 Exchange Online Protection (EOP)
Outbound; PTR: *.outbound.protection.outlook.com
Network Topology
External Reputation Lookups
Look up this IP in external threat intelligence and reputation databases (opens in new tab):
Nearby IPs
Other IPs in the 40.107.243.0/24 range observed failing DMARC:
40.107.243.92 (4 failures), 40.107.243.94 (4 failures), 40.107.243.112 (4 failures), 40.107.243.116 (4 failures), 40.107.243.134 (4 failures), 40.107.243.122 (4 failures), 40.107.243.100 (4 failures), 40.107.243.101 (3 failures)