This IP address has been reported a total of
32
times from
10 distinct
sources.
52.103.20.4 was first reported on
, and the most recent report was
.
In the last 60 days, the top reporter locations were:
Guam
with 2
reports;
Canada
with 1
report;
Netherlands
with 1
report.
The most common categories in these recent reports were:
Email Spam
3
times;
Brute-Force
1
time;
Port Scan
1
time.
Recent Reports
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Spam email received in Outlook.com Junk Email folder.
Likely originating IP: 52.103.20.4
Origin sour ...
show moreSpam email received in Outlook.com Junk Email folder.
Likely originating IP: 52.103.20.4
Origin source header: Authentication-Results
Origin evidence: sender IP is 52.103.20.4
ReceivedDateTime: 10/01/2026 04:58:56
InternetMessageId: <PH7PR16MB479399F2802E7322370A647DE38A2@PH7PR16MB4793.namprd16.prod.outlook.com>
Selection reason: Selected explicit public sender IP from Authentication-Results
Known-good relay/IP/CIDR filtering was enabled.
Reporting mode: one report per qualifying Junk Email message
Subject: Iβd enjoy having you connect with me on the website.
show less
Email Spam
Anonymous
5 Login Attempts
Port Scan
Brute-Force
Anonymous
E-mail spam at 2026-09-12 11:47 from [email protected] with score 23
Spam email received in Outlook.com Junk Email folder.
Likely originating IP: 52.103.20.4
Origin sour ...
show moreSpam email received in Outlook.com Junk Email folder.
Likely originating IP: 52.103.20.4
Origin source header: Authentication-Results
Origin evidence: sender IP is 52.103.20.4
ReceivedDateTime: 09/10/2026 17:01:29
InternetMessageId: <DS2PR17MB78048BC5668B202D1C64575F94BF2@DS2PR17MB7804.namprd17.prod.outlook.com>
Selection reason: Selected explicit public sender IP from Authentication-Results
Known-good relay/IP/CIDR filtering was enabled.
Reporting mode: one report per qualifying Junk Email message
show less
Evidence at https://www.nk.ca/blog/index.php?/archives/19447-WEbSEoApp-spam-from-Microsoft-Outlook.h ...
show moreEvidence at https://www.nk.ca/blog/index.php?/archives/19447-WEbSEoApp-spam-from-Microsoft-Outlook.html
show less
SPAM COP From: Shiatsu Neck Massager -------- <[email protected]>
from CH1PR05CU001.outb ...
show moreSPAM COP From: Shiatsu Neck Massager -------- <[email protected]>
from CH1PR05CU001.outbound.protection.outlook.com ([52.103.20.4]) by cmsmtp with ESMTP id ko1qv7xLyFup4ko1qvBgDD
mail-northcentralusazolkn19010004.outbound.protection.outlook.com
from SJ2PR22MB4488.namprd22.prod.outlook.com (2603:10b6:a03:55a::17) by CH4PR22MB5917.namprd22.prod.outlook.com (2603:10b6:610:221::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9542.15
show less
Phishing
Email Spam
Port Scan
Hacking
Spoofing
Brute-Force
SPAM COP From: Norton Virus Protection -------- <[email protected]>
from CH1PR05CU001.ou ...
show moreSPAM COP From: Norton Virus Protection -------- <[email protected]>
from CH1PR05CU001.outbound.protection.outlook.com ([52.103.20.4]) by cmsmtp with ESMTP id TgVJv8xRDIVAeTgVKvkEUQ
from IA1PR05MB10079.namprd05.prod.outlook.com (2603:10b6:208:3d9::19) by BLAPR05MB7201.namprd05.prod.outlook.com (2603:10b6:208:292::14) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9412.9
show less
Phishing
Email Spam
Port Scan
Hacking
Spoofing
Brute-Force
Mail Rejected due to Proprietary Method on port 25, PTR: mail-northcentralusazolkn19010004.outbound. ...
show moreMail Rejected due to Proprietary Method on port 25, PTR: mail-northcentralusazolkn19010004.outbound.protection.outlook.com
show less
SPAM COP From: Knee Relief by Wellnee -------- <[email protected]>
from CH1PR05CU001. ...
show moreSPAM COP From: Knee Relief by Wellnee -------- <[email protected]>
from CH1PR05CU001.outbound.protection.outlook.com ([52.103.20.4]) by cmsmtp with ESMTP id NsYIv7hjuI3pdNsYJvd9eI
from BL0PR02MB3876.namprd02.prod.outlook.com (2603:10b6:207:4c::11) by DS7PR02MB10964.namprd02.prod.outlook.com (2603:10b6:8:258::23) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9343.17
show less
Phishing
Email Spam
Port Scan
Hacking
Spoofing
Brute-Force