What the bounce says
Exact wording as it appears in the rejection or NDR. Placeholders such as x.x.x.x and example.com stand for your own address and domain.
550 5.7.1 Unfortunately, messages from [x.x.x.x] weren't sent. Please contact your Internet service provider since part of their network is on our block list (S3150). You can also refer your provider to https://mail.live.com/mail/troubleshooting.aspx#errors.
S3150 is Outlook.com’s tag for a connection refused because the sending IP’s network is on Microsoft’s internal block list. The message suggests contacting your provider because the block often covers a range rather than a single address.
Most common causes
- The IP or its /24 has a history of spam
- A shared hosting or cloud range inherited a bad reputation
- A compromised host on the network sent abuse
- New infrastructure with no reputation on a suspicious range
What to verify next
- Confirm the exact IP from the NDR
- Check public blocklists and PTR for the IP
- Fix any abuse source on your network first
- Submit a delisting request through Microsoft’s sender support form
Why a whole network is blocked
Microsoft blocks ranges when abuse originates from several addresses within them, which is common on cheap hosting and some cloud providers. A clean server inside a listed range is blocked along with its neighbours.
The block is Microsoft’s own, not a public blocklist, so public checks can show the IP as clean while Outlook.com still refuses it.
- Range-level block, not necessarily your IP’s behaviour.
- Public blocklists may show clean.
- Delisting is through Microsoft, not a third party.
Getting delisted
Confirm your own IP is not sending abuse: check for compromise, open relay and misdirected bounces. Verify PTR and HELO. Then use Microsoft’s sender support form with the full rejection text; a response usually follows within a few days.
If the provider’s range is repeatedly blocked, moving to a dedicated IP or a reputable sending platform is often faster than repeated delisting.
Prevent recurrence
Authenticate fully so reputation accrues to your domain, keep complaint rates low, and monitor with SNDS so a new block is noticed before customers report it.
Best diagnostic path
Mail Failure Doctor
Classify the complete rejection and preserve provider-specific diagnostic context.
Open analysis → Live analysisReverse DNS & HELO Auditor
Check reverse identity, forward confirmation and SMTP greeting consistency.
Open analysis → Live analysisEmail Infrastructure Digital Twin
Map the domain’s public mail infrastructure and provider relationships before remediation.
Open analysis →Known limits
- Microsoft decides delisting; timing is not guaranteed.
- Shared ranges can be re-blocked by neighbours’ behaviour.
Common questions
My IP is clean everywhere else.
The block is on the range and Microsoft’s own list. Public lists do not show it.
Should I contact my ISP?
Yes, if the range is shared; they may have other customers affected and can request bulk delisting.
How long does delisting take?
Typically one to three business days after a complete request.
Why the exact message matters
The same status family can be triggered by different conditions, and providers frequently add diagnostic text that narrows the issue. Use the complete rejection text rather than treating the numeric code as a complete diagnosis.
Provider reference
For the provider-defined meaning and current requirements, review Microsoft Outlook.com sender troubleshooting.