outlook.com sending from MS-owned IPs that are outside their SPF?

Posted by abqcheeks@reddit | sysadmin | View on Reddit | 7 comments

I'm having trouble because we (my SMTP servers) are rejecting emails from outlook.com users (in particular, but maybe not exclusively, messages being forwarded by outlook.com users), that are sent from MS infrastructure, but from subnets outside of the SPF record for outlook.com.

Outlook.com SPF is "v=spf1 include:spf2.outlook.com -all" and spf2.outlook.com contains ip4:40.92.0.0/16

We're seeing messages from outlook.com addresses sent by IPs in 40.93.0.0/16

Also of interest, the SPF record that I believe ms365 customers are told to use, spf.protection.outlook.com contains ip4:40.92.0.0/15 ... note the /15, which means that block includes 40.93.0.0/16

Looking for discussions about this online is often confused by the above. I have seen several people and AI bots say that, e.g. 40.93.2.68 is covered by outlook.com's SPF, because they saw the /15 in spf.protection.outlook.com. But it's spf2.outlook.com that matters in this case.

Anybody got any ideas on where to report this? Most of the suggestions I've seen for reporting it to MS involve logging in to some sort of MS account to start, and I don't have one of those.

Or am I being dumb and SPF is so yesterday and I should let those mails through because of some other signal?

TIA