Microsoft 365 guide
SPF, DKIM and DMARC for Microsoft 365: exact records
The exact SPF, DKIM and DMARC records for a custom domain on Microsoft 365, where to turn on DKIM, and the mistakes that make DMARC fail.
DMARC Done team · 5 October 2026 · 5 min read
This guide is for businesses that use Microsoft 365 (Exchange Online, Outlook) with their own domain, such as yourdomain.com. It gives you the three records Microsoft recommends, in the order to add them.
Microsoft 365 does not manage these records for your custom domain. You add them at your DNS host, the company where your domain’s DNS records live (often the company you bought the domain from). Microsoft says so directly: “There are no admin portals or PowerShell cmdlets in Microsoft 365 for you to manage SPF records in your domain.”
The records at a glance
| Record | Type | Host | Value |
|---|---|---|---|
| SPF | TXT | @ |
v=spf1 include:spf.protection.outlook.com -all |
| DKIM 1 | CNAME | selector1._domainkey |
copy from Microsoft (see below) |
| DKIM 2 | CNAME | selector2._domainkey |
copy from Microsoft (see below) |
| DMARC | TXT | _dmarc |
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com; fo=1 |
SPF: one TXT record at the root
SPF (Sender Policy Framework) lists the servers allowed to send mail for your domain. If Microsoft 365 is the only service that sends mail as you, Microsoft’s recommended record is:
Type: TXT
Host: @
Value: v=spf1 include:spf.protection.outlook.com -all
Microsoft recommends -all (hard fail) rather than ~all (soft fail) for Microsoft 365 domains. Its reason: DMARC treats both as failures, but “the DMARC policy is effectively ignored for SPF ~all failures if the messages don’t also contain DKIM signatures.”
If other services also send as your domain, for example a newsletter tool or an invoicing system, add their include: values before -all in the same record:
v=spf1 include:spf.protection.outlook.com include:spf.example-service.com -all
Only one SPF record is allowed per domain. If you already have one, edit it rather than adding a second.
DKIM: two CNAME records and a switch
DKIM (DomainKeys Identified Mail) signs each message so receivers can tell it really came from you. For DMARC to count it, the signature must use your own domain. Microsoft’s own alignment table shows that a signature for yourdomain.onmicrosoft.com does not align with yourdomain.com, so you need to turn on DKIM for your custom domain.
Step 1: Get your CNAME values
- Open the Microsoft Defender portal at
https://security.microsoft.com/authentication. The menu path is Email & collaboration > Policies & rules > Threat policies > Email authentication settings, then the DKIM tab. - Select your custom domain. The details flyout shows the two CNAME records to publish, with a Copy option.
The host names are the same for every Microsoft 365 organization: selector1._domainkey and selector2._domainkey. The values are unique to your tenant, so always copy them rather than typing them by hand. Depending on when the domain was added, they look like one of these:
selector1-yourdomain-com._domainkey.yourtenant.n-v1.dkim.mail.microsoft
selector1-yourdomain-com._domainkey.yourtenant.onmicrosoft.com
The first format is for custom domains added from May 2025 onwards. Existing domains keep the older onmicrosoft.com format.
Step 2: Publish both CNAMEs at your DNS host
Type: CNAME
Host: selector1._domainkey
Value: (selector1 value copied from Microsoft)
Type: CNAME
Host: selector2._domainkey
Value: (selector2 value copied from Microsoft)
Step 3: Turn on signing
Back on the DKIM tab, open the domain again and turn on Sign messages for this domain with DKIM signatures. If the CNAMEs are not visible in DNS yet, Microsoft reports them as missing. Wait a little and try again. When it works, the status shows that the domain is signing with DKIM.
DMARC: one TXT record at _dmarc
DMARC (Domain-based Message Authentication, Reporting and Conformance) tells receivers what to do with mail that fails SPF and DKIM, and where to send reports. Start in monitoring mode:
Type: TXT
Host: _dmarc
Value: v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com; fo=1
Microsoft notes that “The hostname value _dmarc is required.” Create the dmarc-reports@ address first. Microsoft recommends a dedicated mailbox or Microsoft 365 Group for reports rather than a person’s inbox.
Two Microsoft details worth knowing:
- Microsoft 365 does not send DMARC failure reports, even when a
ruf=address is published, sofo=1has no effect on mail to Microsoft. Other receivers may still send them if you addruf=later. - Microsoft also recommends a DMARC record for your
onmicrosoft.comdomain if you do not send mail from it. In the Microsoft 365 admin center, go to Settings > Domains, select theonmicrosoft.comdomain, open DNS records, select Add record, and add a TXT record named_dmarcwith the valuev=DMARC1; p=reject.
Plain-English takeaway: For Microsoft 365, publish one SPF record ending in
-all, two DKIM CNAMEs copied from the Defender portal (then flip the signing switch), and a DMARC record at_dmarcwithp=noneand a reporting address.
Where to add the records
All four records go in your DNS host’s control panel, not in Microsoft 365. The usual steps:
- Sign in at your DNS host and open the DNS settings for your domain.
- Add each record with the type, host and value above.
- Save, then wait. Changes are often visible within minutes but can take longer.
Panels differ in how they want the host name typed. Our DNS host guides cover the details for GoDaddy, Cloudflare, IONOS, Strato and Namecheap.
Common mistakes
- Two SPF records. Leftovers from an old email host are common. Two SPF records make SPF fail with a permanent error. Merge them into one.
- Small SPF typos. Microsoft lists the usual ones: a trailing dot after
outlook.com,include=instead ofinclude:, or a space after the colon. - Too many lookups. Each
include:costs DNS lookups and the limit is 10. See SPF too many DNS lookups. - CNAMEs published but signing left off. Publishing the records is not enough. The switch in the Defender portal must be on.
- Typed DKIM values. One wrong character breaks DKIM. Copy the values.
- Forgetting other senders. Your website, CRM or marketing tool also needs SPF or DKIM with your domain before you enforce DMARC.
Check your setup
Run the free checker at /check?d=yourdomain.com. It detects Microsoft 365, checks all three records and both DKIM selectors, and shows the exact records your domain is missing.
When to move to quarantine and reject
p=none only collects reports. It does not stop anyone from sending email as your domain. Microsoft’s guidance is to start at p=none, move to p=quarantine, then to p=reject, checking reports at each step. Our post on DMARC quarantine vs reject explains how long to wait and what to look for.
If you want us to read the reports, find every sender and take the domain to p=reject for you, see pricing. If the domain is not at p=reject within 60 days, you get a full refund.
Sources
- Microsoft Learn, Set up SPF to identify valid email sources for your Microsoft 365 domain: https://learn.microsoft.com/en-us/defender-office-365/email-authentication-spf-configure
- Microsoft Learn, How to use DKIM for email in your custom domain: https://learn.microsoft.com/en-us/defender-office-365/email-authentication-dkim-configure
- Microsoft Learn, Set up DMARC to validate email in Microsoft 365: https://learn.microsoft.com/en-us/defender-office-365/email-authentication-dmarc-configure
- Microsoft Learn, Add DNS records to connect your domain: https://learn.microsoft.com/en-us/microsoft-365/admin/get-help-with-domains/create-dns-records-at-any-dns-hosting-provider