we see sporadic DNS resolver errors for A records of *.mail.protection.outlook.com
Only a few per day vs many successful lookups.
I haven't noticed this, but we found out last week that Microsoft apparently has enabled a new cluster of servers for europe in networks 40.92.7[345].*. All of these currently completely lack PTR data, and the corresponding SOA suggests a last modification date of February 5, 2018:
92.40.in-addr.arpa. 3600 IN SOA ns1.msft.net. msnhst.microsoft.com. 2018020502 7200 900 2419200 3600
they pop up in logs such as this:
[40.92.75.99] claimed to be EUR04-VI1-obe.outbound.protection.outlook.com
and rejected connections seem to carry only freemail services (hotmail, windowslivemail).
We informed SOA and whois contacts last Wednesday, but haven't heard back from them.
Cheers, Markus