The first big SNDS update in years: What Changed and Why It Matters

Microsoft has made major changes to Smart Network Data Services (SNDS), its long-standing tool for monitoring IP reputation and complaint data for Outlook.com.

The update brings a new portal, a modern OAuth 2.0 API, changes to complaint reporting, and reduced spam-trap visibility. Some changes are welcome improvements; others require deliverability teams to update existing monitoring workflows.

If you need any help to ensure that you are ready to that new Microsoft JMRP ARF Compliant Format, you can contact the Postmastery Team

SNDS

New SNDS portal and URL

On June 8, 2026, Microsoft migrated SNDS to a new portal:
https://substrate.office.com/ip-domain-management-snds/SNDS
The historical URL (sendersupport.olc.protection.outlook.com/snds/) now redirects to the new platform, but Microsoft advised senders to update bookmarks, scripts, and integrations that relied on the old URLs.

Automated download links now expire

The old CSV access links were effectively permanent. The new automated access links now expire after 30 days and must be periodically renewed. If your monitoring stack still relies on those URLs, your imports may suddenly start returning 404 errors without any obvious indication that reputation data has stopped flowing.

API access replaces the old approach

Historically, most automation relied on CSV downloads generated through "Automated Data Access" links.
SNDS now provides an API secured with OAuth 2.0 authentication for retrieving:

  • IP Data reports
  • IP Status reports
  • Date-filtered reports
  • IPv4-specific queries

This is probably the biggest architectural change for anyone integrating SNDS data into dashboards or deliverability platforms. Note that the Oauth2 configuration in SNDS is targeted for desktop applications, not server based applications. The data returned by the API is the same CSV as the automated download links.

JMRP complaints now use standard ARF

Microsoft's Junk Mail Reporting Program (JMRP) now sends complaints in standard ARF (Abuse Reporting Format).
The most important consequence is that:

  • complaint reports no longer contain the full original message,
  • complaint sample downloads have been removed,

Many senders previously relied on parsing the original MIME message to identify the complaining recipient. Those workflows must now rely on headers such as:

  • Message-ID
  • custom identifiers (X-Campaign-ID, X-sendID, etc.)
  • VERP return paths
  • DKIM selectors or domains

This change aligns Microsoft more closely with Gmail and Yahoo's privacy approach.
For more details, please see our blog post on this subject.

Stronger controls for network ownership

Microsoft has added authentication requirements for approving or denying SNDS access requests. This reduces the risk of approvals being triggered accidentally by security scanners or link-preview tools.

Network ownership delegations now also expire and must be revalidated periodically. Organizations that manage IP ranges for customers, partners, or former clients should confirm that access remains current and renew delegations before they lapse.

Spam-trap reporting is being phased out

Microsoft recently announced that trap hit counts would be removed from the Data Report as of July 22, 2026.

During the transition period, reported values may already differ from historical values and should not be interpreted as exact counts. This is arguably the most significant loss of visibility for deliverability teams using SNDS for list hygiene monitoring.

A more modern interface

The SNDS interface received its first major refresh in years:

  • updated visual design,
  • profile management improvements,
  • integrated network management,
  • automated data access management within the portal.

The functionality remains largely the same, but the portal feels closer to modern Microsoft 365 administration tools than the original early-2000s interface.

What this means for deliverability teams

The portal redesign is useful, but the operational impact lies elsewhere.

The OAuth 2.0 API requires integration updates. Expiring automated links need active maintenance. The move to ARF removes detailed complaint-message data, and the removal of spam-trap counts reduces an important list-quality signal.

Teams running large sending programs or deliverability platforms should review these changes now (particularly API authentication, automated downloads, complaint attribution, and network-access ownership) before an existing workflow fails quietly.

More information

If you want more information about this topic, please send us a message via our contact form.
We are always happy to assist!