Site AI Auditby Internet Solutions

Microsoft 365 Email Authentication: SPF, DKIM and DMARC Setup

15 tháng 8, 20268 phút đọcKhả năng gửi e-mail
Microsoft 365 Email Authentication: SPF, DKIM and DMARC Setup

Short answer: For Microsoft 365, publish an SPF record containing include:spf.protection.outlook.com, create the two DKIM CNAME records (selector1._domainkey and selector2._domainkey) with the exact values shown for your domain in the Microsoft Defender portal, then enable DKIM signing for the domain there. Finally add a DMARC TXT record at _dmarc, start with p=none and a report address, and move to enforcement once reports are clean.

What Microsoft 365 does for you, and what it does not

When you add a custom domain to Microsoft 365, the setup wizard asks for MX, autodiscover and SPF records so that mail can flow and Outlook clients can find their settings. That is enough for mail to work, and many organisations stop there. Two important pieces are left for you: DKIM for your own domain and DMARC.

Without custom DKIM, Microsoft 365 signs outgoing mail with your initial onmicrosoft.com domain. The signature is valid, but it does not match the domain in your From address, so it does not count for DMARC alignment. DMARC then depends on SPF alone, which breaks when mail is forwarded. Without DMARC, there is no policy against spoofing and no reports about who sends mail with your domain.

You need two things for the work: an account with the right admin role in Microsoft 365 (Global Administrator or Security Administrator), and access to your domain’s DNS. If Microsoft manages your DNS, some records can be created automatically; most businesses host DNS elsewhere and add the records by hand.

Step 1: confirm MX and autodiscover

Check that incoming mail is routed to Exchange Online. The Microsoft 365 admin center, under Settings and Domains, shows the expected records for each domain and whether they are detected. The MX record points to a host under Microsoft’s mail protection service, and a CNAME for autodiscover points to autodiscover.outlook.com. Remove MX records left over from a previous provider; mixed MX records split incoming mail between systems.

The domain status page is also useful later. After you add SPF, DKIM and DMARC, it helps confirm that Microsoft sees the records you published.

Step 2: publish the SPF record

For a domain that sends mail only through Microsoft 365, the record is:

v=spf1 include:spf.protection.outlook.com -all

Microsoft’s own guidance commonly uses -all; many administrators choose ~all while DMARC is still at p=none. Either is acceptable once you are sure the record lists every sender. If other services send mail using your domain in the envelope sender, such as a website mail service or a marketing platform, add their includes to the same record. Keep one SPF record per domain, and stay within ten DNS lookups.

A special case is on-premises devices and applications that send through Microsoft 365. If they connect using the domain’s MX endpoint (direct send or an SMTP relay connector), the IP address of your office or server may need to be in SPF, depending on the method. Microsoft documents each option; choose authenticated submission where possible, because it keeps the mail within the protected infrastructure.

Step 3: publish the DKIM CNAME records

Microsoft 365 uses two DKIM selectors so that it can rotate keys without interruption: while one key signs, the other is prepared. You publish two CNAME records, and Microsoft hosts the actual keys.

  1. Open the Microsoft Defender portal and go to Email & collaboration > Policies & rules > Threat policies > Email authentication settings, then the DKIM tab.
  2. Select your custom domain. The details pane shows the two CNAME records to create, with host names selector1._domainkey and selector2._domainkey and target values specific to your tenant and domain.
  3. Copy the values exactly. The format of the targets has changed over time for new domains, so never copy them from an old tutorial or from another tenant.
  4. Create both CNAME records in your DNS panel. As with any DNS record, enter only the host part if the panel adds the domain automatically.
  5. Wait for the records to be visible, then check with dig CNAME selector1._domainkey.yourdomain.com +short.

Step 4: enable DKIM signing

Publishing the CNAMEs is not enough. Back in the DKIM tab, select the domain and switch Sign messages for this domain with DKIM signatures to enabled. If the portal reports that the CNAME records cannot be found, wait for DNS to update and try again.

Once enabled, the status shows that DKIM is valid and signing. Outgoing mail now carries a signature with d=yourdomain.com. Microsoft rotates the keys between the two selectors, and you can also trigger a rotation from the same screen.

Repeat for every custom domain in the tenant, including domains used only for aliases or shared mailboxes. Each domain in a From address needs its own DKIM configuration to align.

Step 5: publish DMARC

Create a TXT record at _dmarc:

v=DMARC1; p=none; rua=mailto:[email protected]

Make sure the reporting mailbox exists and accepts external mail. If you use a shared mailbox or a Microsoft 365 group, check that external senders are allowed, or reports will bounce. After a few weeks of reports, fix any service that still fails alignment and move to p=quarantine and then p=reject.

Microsoft 365 also honours DMARC policies of other domains on incoming mail. You can configure how Exchange Online treats messages that fail a sender’s reject or quarantine policy in the anti-phishing policy, which is worth reviewing while you are in the Defender portal.

Step 6: verify real messages

  1. Send from an Outlook mailbox in your tenant to an external Gmail address and an Outlook.com address.
  2. In Gmail, open the message and use Show original. SPF, DKIM and DMARC should all show PASS, with DKIM for your domain.
  3. In Outlook on the web, you can view message details (headers) and look for Authentication-Results with spf=pass, dkim=pass and dmarc=pass action=none.
  4. If DKIM shows header.d= with an onmicrosoft.com domain, signing is not enabled for your custom domain yet.

Frequent problems in Microsoft 365 setups

ProblemCauseFix
DKIM passes with onmicrosoft.comCustom DKIM not enabledPublish both CNAMEs and enable signing in the Defender portal
Portal says CNAME records not foundDNS not updated yet, or host name entered with the domain twiceWait for TTL, check the exact name with dig
Scanner or app mail fails SPFDevice sends from an office IP not in SPFUse authenticated submission, or add the static IP to SPF
DMARC reports never arriveReport mailbox rejects external mailAllow external senders for the mailbox or group
Newsletter fails DMARCMarketing tool signs with its own domainConfigure custom domain DKIM in that tool
Secondary domain unprotectedOnly the primary domain was configuredRepeat SPF, DKIM and DMARC for each domain

Keeping the setup healthy

E-mail authentication tends to break quietly: someone moves DNS to a new provider and forgets the DKIM CNAMEs, or a new marketing tool is added without authentication. Keep a short document listing every record and every sending service, and review DMARC reports regularly.

A simple routine works well for most small and mid-sized tenants:

Site AI Audit checks a domain’s SPF (including the lookup limit), DKIM, DMARC and MX records from the outside and reports problems in plain words, together with the website’s SSL, security headers, speed and SEO. A free check confirms the published state; paid plans on the pricing page repeat the checks and alert you when a record disappears or changes.

Related reading

The bottom line

Microsoft 365 gets mail flowing with MX and SPF, but authentication is not complete until DKIM is enabled for your own domain and DMARC is published. Create both DKIM CNAMEs with the exact values from the Defender portal, switch signing on, add DMARC with reports, verify real messages, and repeat for every domain in the tenant.

FAQ

What is the SPF include for Microsoft 365?

The include is include:spf.protection.outlook.com. A domain that sends only through Microsoft 365 can use v=spf1 include:spf.protection.outlook.com -all or the softer ~all.

Why does Microsoft 365 use two DKIM records?

The two selectors allow key rotation without downtime. Microsoft signs with one key while the other is ready, and switches between them when keys are rotated.

Where do I enable DKIM in Microsoft 365?

In the Microsoft Defender portal under Email and collaboration, Policies and rules, Threat policies, Email authentication settings, on the DKIM tab. Select the domain and enable signing after the CNAME records are published.

Is DKIM enabled by default in Microsoft 365?

Microsoft signs outgoing mail with the initial onmicrosoft.com domain by default. That signature does not align with your custom domain, so you must enable DKIM for each custom domain yourself.

Can I copy DKIM CNAME values from another guide?

No. The target values are specific to your tenant and domain, and the format has changed over time. Always copy them from your own Defender portal.

Does Microsoft 365 create the DMARC record for me?

No, unless Microsoft hosts your DNS and you add it there yourself. You publish the DMARC TXT record at _dmarc in your DNS, starting with p=none and a report address.

#DKIM#DMARC#Email Authentication#Microsoft 365
Hãy kiểm tra website của chính bạn — miễn phí.Website của bạn cần sửa gì — và nên bắt đầu từ đâu.
Bắt đầu miễn phí
Internet Solutions

Sản phẩm khác từ đội ngũ chúng tôi

Do Internet Solutions phát triển. Hãy thử các sản phẩm khác của chúng tôi — mỗi sản phẩm giúp bạn tiết kiệm thời gian theo một cách riêng.

internet-solutions.net ↗
01Tự động đăng mạng xã hội
PostRSS

Bài mới từ nguồn cấp RSS của bạn được tự động đăng lên Facebook, X, LinkedIn, Telegram và hơn 60 mạng khác.

Gói miễn phí · từ 2014Truy cập →
02Chat trực tuyến AI cho website
Talkmio

Website của bạn trả lời khách truy cập 24/7 từ chính nội dung của bạn, bằng ngôn ngữ của họ.

Gói miễn phí · không cần thẻTruy cập →
03Trợ lý AI
Ask Mio

Trò chuyện, viết code, thiết kế, viết bài và nghiên cứu. Mio chọn mô hình tốt nhất cho từng việc.

Gói miễn phíTruy cập →
04Lái tự động AI cho blog và mạng xã hội
AI Blog Autopilot

AI viết bài SEO dài 2.000–3.000 từ và chia sẻ từng bài lên hơn 58 mạng xã hội.

3 bài đầu tiên miễn phíTruy cập →
05Thu thập SEO chuyên sâu
Site SEO AI Audit

Thu thập SEO toàn diện trên 7 lĩnh vực, gồm cả khả năng hiển thị trong tìm kiếm AI, với cách sửa xếp theo mức tác động.

Lần kiểm tra đầu tiên miễn phíTruy cập →
06Nguồn cấp RSS và sản phẩm
RSS Feed Creator

Tạo RSS từ bất kỳ trang web nào, cùng nguồn cấp sản phẩm cho Google và Meta tự động cập nhật.

Gói miễn phíTruy cập →
07Phát triển website và SEO
Internet Solutions

Website, cửa hàng trực tuyến và hệ thống theo yêu cầu, do đội ngũ của chúng tôi thiết kế, xây dựng và vận hành.

Từ 2011Truy cập →
Site AI Audit
Tổng quan quyền riêng tư

Website này dùng cookie để mang lại trải nghiệm người dùng tốt nhất có thể. Thông tin cookie được lưu trong trình duyệt của bạn và thực hiện các chức năng như nhận ra bạn khi bạn quay lại, giúp đội ngũ chúng tôi hiểu phần nào của website bạn thấy thú vị và hữu ích nhất.