Network: MSFT
Differentiating between Office 365, including email protection services, and Azure (public cloud) when diagnosing incidents is challenging because they utilize shared Microsoft-owned IP ranges. Most of this is probably O365/Outlook or Defender protection breaking DKIM and SPF authentication. Disambiguation is a work-in-progress.
This page shows DMARC authentication failures originating from the MSFT network. Learn more about this data.
Analysis
This network has contributed 6 unique IP addresses across 7 failed authentication events, accounting for 9 messages. Activity spans from March 12, 2024 to September 20, 2026, with peak volume in February 2025 (2 events). The top countries by failure volume are United States (56%), The Netherlands (22%), Ireland (11%). The most active source IPs from this network include 40.74.181.208 (2 failures), 4.240.39.194 (1 failure), 20.241.204.101 (1 failure). The distribution across MSFT (Microsoft) suggests mixed or general-purpose infrastructure.
Failures Detected from this Network
Showing 1-7 of 7 failures, affecting 9 messages| Date โผ | Source IP | Country | Messages |
|---|---|---|---|
| 9/20/2026 | IE | 1 | |
| 5/5/2026 | NL | 1 | |
| 5/1/2026 | NL | 1 | |
| 3/5/2026 | IN | 1 | |
| 2/27/2026 | US | 1 | |
| 2/26/2025 | US | 2 | |
| 2/14/2025 | US | 2 |