# Microsoft Escalation Channels

> The remediation map for Microsoft blocks: Office 365 anti-spam IP delist portal (sender.office.com), delist@microsoft.com for 5.7.511, the Outlook.com sender support form, SNDS/JMRP prerequisites, what each channel needs, and realistic timelines.

Source: emailmarketing.net — https://emailmarketing.net/learn/providers/microsoft-escalation-channels

When Microsoft blocks your mail, the channel that can lift the block depends on which of Microsoft's systems applied it. Microsoft runs **two separate filtering systems, each with its own remediation paths**, and escalating to the wrong one wastes days. Start by classifying the block:

| Symptom | System | Channel |
|---|---|---|
| NDR `550 5.7.606–649 Access denied, banned sending IP` from a **business or tenant** recipient (a custom domain on Microsoft 365) | EOP (Office 365) | Delist portal `https://sender.office.com` |
| NDR `550 5.7.511 Access denied, banned sender` | EOP (Office 365), on the list that needs deeper investigation | Email `delist@microsoft.com` |
| `550 5.7.703 ... Tenant Allow Block List` | A block set by a single recipient tenant | Only that tenant's administrator can fix it; there is no Microsoft channel |
| `421 RP-001/002/003`, `550 SC-001..004`, `DY-001/002`, `OU-001/002`, or mail sent to Junk at **@outlook.com, @hotmail.com, @live.com or @msn.com** | Consumer Outlook.com | Sender support form (below), after the SNDS and JMRP prerequisites |

For what each code means, see [Microsoft Sender Requirements](https://emailmarketing.net/learn/providers/microsoft-sender-requirements). For diagnosing tenant mail from its headers, see [Microsoft Filtering Internals](https://emailmarketing.net/learn/providers/microsoft-filtering-internals).

## Channel 1: Office 365 Anti-Spam IP Delist Portal (sender.office.com)

Use this channel for IP addresses on the EOP **blocked senders list** (NDR range `5.7.606–649`, whose message itself points to the portal). It is self-service, and works one IP address at a time.

Process:

1. Go to `https://sender.office.com`.
2. Enter the **email address that received the NDR** and the **IP address from the error message** (one email address and one IP address per visit), and pass the CAPTCHA.
3. Microsoft sends a verification email to that address. Click the confirmation link to return to the portal.
4. Select **Delist IP**.

You need the exact NDR text (the IP address and the code) and a working mailbox at the address you enter. On timing, Microsoft states that results vary and that full removal **can take up to 24 hours or longer**.

Delisting removes only the block at the edge. Mail must still pass EOP and MDO filtering, including composite authentication, and if the traffic stays abusive the IP address is blocked again. As with any [blocklist removal](https://emailmarketing.net/learn/reference/blocklists-and-spamhaus), fix the root cause (a compromise, list quality, authentication) before you delist.

## Channel 2: delist@microsoft.com (error 5.7.511)

`550 5.7.511 Access denied, banned sender` means the IP address is on a list that requires **further investigation by Microsoft**, and the self-service portal explicitly cannot fix it. Forward the bounce to **`delist@microsoft.com`**, including the **full NDR text and the IP address**. Microsoft states that it will respond **within 48 hours** with next steps. Expect questions about the traffic, and have evidence of volume, consent and remediation ready.

## Channel 3: Outlook.com sender support form (consumer mailboxes)

This channel is only for deliverability problems at consumer Outlook.com, meaning "any address @msn.com, @Outlook.com, @hotmail.com, or @live.com". Use it for mail sent to Junk, for `SC-004` complaint blocks once you have remediated, for throttling (`RP-00x`) that does not recover, and for requests for mitigation during warm-up.

**Prerequisites Microsoft expects before you file** (requests without them tend to get standard denials):

1. Check that you comply with the Outlook.com policies page (authentication, PTR records, connection limits; see [Microsoft Sender Requirements](https://emailmarketing.net/learn/providers/microsoft-sender-requirements)).
2. Enroll the IP addresses in **SNDS and JMRP**, or refresh their enrollment. New IP addresses must be added to your JMRP account. See [Microsoft SNDS & JMRP](https://emailmarketing.net/learn/postmaster-tools/microsoft-snds-jmrp). SNDS data (filter color, complaint rate, share of RCPT failures) is also the evidence you will cite in the ticket.
3. Check the troubleshooting FAQ for your exact error code first.

**Where the form lives**: Microsoft's support article "Sender Support in Outlook.com" (`https://support.microsoft.com/en-us/outlook/sender-support-in-outlook-com`) and the postmaster troubleshooting page both link to the form. It was historically at `https://sendersupport.olc.protection.outlook.com/pm/Troubleshooting`, and can also be reached through the redirector `https://go.microsoft.com/fwlink/?LinkID=614866`.

The postmaster and SNDS pages have moved to `https://substrate.office.com/ip-domain-management-snds/`, and the old `sendersupport.olc.protection.outlook.com` domain is deprecated from **June 22, 2026**. Expect the redirector link to send you to the form's current location. For the live link, follow the postmaster Troubleshooting page (`https://substrate.office.com/ip-domain-management-snds/Postmaster/Troubleshooting`).

**What to include**: the affected sending IP addresses, the exact SMTP error string or code, the sending domains, a description of the mail stream (volume, opt-in method), and the remediation you have done (JMRP suppression, list cleaning, authentication fixes).

**Realistic flow and timeline** (widely reported by practitioners; this is not an official service level):

- The form produces an **automated response**, which often says "no problem detected" or offers a generic conditional mitigation.
- **Reply to that automated email** to escalate to a human agent. Responses come from `olcsupport.office.com` addresses, and a human response typically takes from one to several business days.
- When mitigation is granted, it is usually temporary or conditional. Reputation must be rebuilt through sending behavior, at low volume first.
- New IP addresses need **~2+ weeks** of reputation building at Outlook.com. SPF on a domain that already has a good reputation speeds up the ramp-up.

There is also a separate **Outlook.com consumer delisting form** at `https://support.microsoft.com/supportrequestform/8ad563e3-288e-2a61-8122-3ba03d6b8d75`, linked from Microsoft's EOP delisting article for blocks on the consumer side. Read the troubleshooting FAQ before you submit it.

## Channel 4: problems only the recipient tenant can fix (no Microsoft channel)

In some cases **no Microsoft channel for senders exists**: when the headers show `SFV:SKB` or `SFV:BLK` (the recipient's block lists), when a Tenant Allow/Block List entry blocks you (`5.7.703`), or when mail is quarantined as high confidence phishing because of a URL or domain the tenant has blocked. The recipient organization's administrator must remove the entry, or submit the message to Microsoft as a false positive through the Defender Submissions page (`https://security.microsoft.com/reportsubmission`). A submission is also the only way to get an allow for verdicts of malware or high confidence phishing. Give the recipient's administrator the full headers and the field guide in [Microsoft Filtering Internals](https://emailmarketing.net/learn/providers/microsoft-filtering-internals).

## Escalation checklist (consultant runbook)

1. **Classify** the block from the exact SMTP code or the verdict in the headers (see the table at the top).
2. **Fix the root cause first**: authentication alignment, compromised hosts, the causes of complaints, list hygiene. Microsoft blocks again senders whose remediation exists only on paper.
3. **Enroll in SNDS and JMRP** before any contact about consumer mailboxes, and pull the SNDS view of the days of the incident.
4. **Use the narrowest channel**: the portal for 606–649; `delist@microsoft.com` for 5.7.511; the sender support form for consumer Outlook.com issues; the recipient's administrator for blocks set by a tenant.
5. **Keep the paper trail**: ticket IDs and the automated responses. Replies to the automated email are what reach people.
6. **Verify after mitigation**: watch the SNDS filter results and run seed tests on consumer mailboxes. Increase volume gradually, as after a [warm-up](https://emailmarketing.net/learn/ip-management/ip-warm-up).

## Related articles

- [Microsoft Sender Requirements](https://emailmarketing.net/learn/providers/microsoft-sender-requirements), with the catalog of error codes and policies
- [Microsoft Filtering Internals](https://emailmarketing.net/learn/providers/microsoft-filtering-internals), on reading the verdict headers
- [Microsoft SNDS & JMRP](https://emailmarketing.net/learn/postmaster-tools/microsoft-snds-jmrp), the mandatory prerequisites
- [Blocklists & Spamhaus](https://emailmarketing.net/learn/reference/blocklists-and-spamhaus), since OU-001 blocks are driven by Spamhaus
