outlook error

Outlook.com 550 5.7.1 — Network on Block List (S3150)

Outlook.com refused the connection because the sending IP, or its network, is on Microsoft’s block list. The S3150 tag identifies this specific block.

What the bounce says

Exact wording as it appears in the rejection or NDR. Placeholders such as x.x.x.x and example.com stand for your own address and domain.

550 5.7.1 Unfortunately, messages from [x.x.x.x] weren't sent. Please contact your Internet service provider since part of their network is on our block list (S3150). You can also refer your provider to https://mail.live.com/mail/troubleshooting.aspx#errors.

S3150 is Outlook.com’s tag for a connection refused because the sending IP’s network is on Microsoft’s internal block list. The message suggests contacting your provider because the block often covers a range rather than a single address.

Reviewed 2026-09-08. Provider wording and requirements change; the provider reference below is authoritative.

Most common causes

  • The IP or its /24 has a history of spam
  • A shared hosting or cloud range inherited a bad reputation
  • A compromised host on the network sent abuse
  • New infrastructure with no reputation on a suspicious range

What to verify next

  1. Confirm the exact IP from the NDR
  2. Check public blocklists and PTR for the IP
  3. Fix any abuse source on your network first
  4. Submit a delisting request through Microsoft’s sender support form

Why a whole network is blocked

Microsoft blocks ranges when abuse originates from several addresses within them, which is common on cheap hosting and some cloud providers. A clean server inside a listed range is blocked along with its neighbours.

The block is Microsoft’s own, not a public blocklist, so public checks can show the IP as clean while Outlook.com still refuses it.

  • Range-level block, not necessarily your IP’s behaviour.
  • Public blocklists may show clean.
  • Delisting is through Microsoft, not a third party.

Getting delisted

Confirm your own IP is not sending abuse: check for compromise, open relay and misdirected bounces. Verify PTR and HELO. Then use Microsoft’s sender support form with the full rejection text; a response usually follows within a few days.

If the provider’s range is repeatedly blocked, moving to a dedicated IP or a reputable sending platform is often faster than repeated delisting.

Prevent recurrence

Authenticate fully so reputation accrues to your domain, keep complaint rates low, and monitor with SNDS so a new block is noticed before customers report it.

Best diagnostic path

Known limits

  • Microsoft decides delisting; timing is not guaranteed.
  • Shared ranges can be re-blocked by neighbours’ behaviour.

Common questions

My IP is clean everywhere else.

The block is on the range and Microsoft’s own list. Public lists do not show it.

Should I contact my ISP?

Yes, if the range is shared; they may have other customers affected and can request bulk delisting.

How long does delisting take?

Typically one to three business days after a complete request.

Why the exact message matters

The same status family can be triggered by different conditions, and providers frequently add diagnostic text that narrows the issue. Use the complete rejection text rather than treating the numeric code as a complete diagnosis.

Provider reference

For the provider-defined meaning and current requirements, review Microsoft Outlook.com sender troubleshooting.