I'm starting to think blocking Failed RDNS is not such a good idea
"..from NAM02-BL2-obe.outbound.protection.outlook.com ([104.47.38.42] RDNS failed) by..."
RDNS is failing in from those server and a few more legit senders.
I was hoping to trap the spammers, but the net is too wide, need something smaller.