Skip to content
DMARC Done

Microsoft 365 guide

SPF, DKIM and DMARC for Microsoft 365: exact records

The exact SPF, DKIM and DMARC records for a custom domain on Microsoft 365, where to turn on DKIM, and the mistakes that make DMARC fail.

DMARC Done team · 5 October 2026 · 5 min read

This guide is for businesses that use Microsoft 365 (Exchange Online, Outlook) with their own domain, such as yourdomain.com. It gives you the three records Microsoft recommends, in the order to add them.

Microsoft 365 does not manage these records for your custom domain. You add them at your DNS host, the company where your domain’s DNS records live (often the company you bought the domain from). Microsoft says so directly: “There are no admin portals or PowerShell cmdlets in Microsoft 365 for you to manage SPF records in your domain.”

The records at a glance

Record Type Host Value
SPF TXT @ v=spf1 include:spf.protection.outlook.com -all
DKIM 1 CNAME selector1._domainkey copy from Microsoft (see below)
DKIM 2 CNAME selector2._domainkey copy from Microsoft (see below)
DMARC TXT _dmarc v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com; fo=1

SPF: one TXT record at the root

SPF (Sender Policy Framework) lists the servers allowed to send mail for your domain. If Microsoft 365 is the only service that sends mail as you, Microsoft’s recommended record is:

Type:  TXT
Host:  @
Value: v=spf1 include:spf.protection.outlook.com -all

Microsoft recommends -all (hard fail) rather than ~all (soft fail) for Microsoft 365 domains. Its reason: DMARC treats both as failures, but “the DMARC policy is effectively ignored for SPF ~all failures if the messages don’t also contain DKIM signatures.”

If other services also send as your domain, for example a newsletter tool or an invoicing system, add their include: values before -all in the same record:

v=spf1 include:spf.protection.outlook.com include:spf.example-service.com -all

Only one SPF record is allowed per domain. If you already have one, edit it rather than adding a second.

DKIM: two CNAME records and a switch

DKIM (DomainKeys Identified Mail) signs each message so receivers can tell it really came from you. For DMARC to count it, the signature must use your own domain. Microsoft’s own alignment table shows that a signature for yourdomain.onmicrosoft.com does not align with yourdomain.com, so you need to turn on DKIM for your custom domain.

Step 1: Get your CNAME values

  1. Open the Microsoft Defender portal at https://security.microsoft.com/authentication. The menu path is Email & collaboration > Policies & rules > Threat policies > Email authentication settings, then the DKIM tab.
  2. Select your custom domain. The details flyout shows the two CNAME records to publish, with a Copy option.

The host names are the same for every Microsoft 365 organization: selector1._domainkey and selector2._domainkey. The values are unique to your tenant, so always copy them rather than typing them by hand. Depending on when the domain was added, they look like one of these:

selector1-yourdomain-com._domainkey.yourtenant.n-v1.dkim.mail.microsoft
selector1-yourdomain-com._domainkey.yourtenant.onmicrosoft.com

The first format is for custom domains added from May 2025 onwards. Existing domains keep the older onmicrosoft.com format.

Step 2: Publish both CNAMEs at your DNS host

Type:  CNAME
Host:  selector1._domainkey
Value: (selector1 value copied from Microsoft)

Type:  CNAME
Host:  selector2._domainkey
Value: (selector2 value copied from Microsoft)

Step 3: Turn on signing

Back on the DKIM tab, open the domain again and turn on Sign messages for this domain with DKIM signatures. If the CNAMEs are not visible in DNS yet, Microsoft reports them as missing. Wait a little and try again. When it works, the status shows that the domain is signing with DKIM.

DMARC: one TXT record at _dmarc

DMARC (Domain-based Message Authentication, Reporting and Conformance) tells receivers what to do with mail that fails SPF and DKIM, and where to send reports. Start in monitoring mode:

Type:  TXT
Host:  _dmarc
Value: v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com; fo=1

Microsoft notes that “The hostname value _dmarc is required.” Create the dmarc-reports@ address first. Microsoft recommends a dedicated mailbox or Microsoft 365 Group for reports rather than a person’s inbox.

Two Microsoft details worth knowing:

  • Microsoft 365 does not send DMARC failure reports, even when a ruf= address is published, so fo=1 has no effect on mail to Microsoft. Other receivers may still send them if you add ruf= later.
  • Microsoft also recommends a DMARC record for your onmicrosoft.com domain if you do not send mail from it. In the Microsoft 365 admin center, go to Settings > Domains, select the onmicrosoft.com domain, open DNS records, select Add record, and add a TXT record named _dmarc with the value v=DMARC1; p=reject.

Plain-English takeaway: For Microsoft 365, publish one SPF record ending in -all, two DKIM CNAMEs copied from the Defender portal (then flip the signing switch), and a DMARC record at _dmarc with p=none and a reporting address.

Where to add the records

All four records go in your DNS host’s control panel, not in Microsoft 365. The usual steps:

  1. Sign in at your DNS host and open the DNS settings for your domain.
  2. Add each record with the type, host and value above.
  3. Save, then wait. Changes are often visible within minutes but can take longer.

Panels differ in how they want the host name typed. Our DNS host guides cover the details for GoDaddy, Cloudflare, IONOS, Strato and Namecheap.

Common mistakes

  • Two SPF records. Leftovers from an old email host are common. Two SPF records make SPF fail with a permanent error. Merge them into one.
  • Small SPF typos. Microsoft lists the usual ones: a trailing dot after outlook.com, include= instead of include:, or a space after the colon.
  • Too many lookups. Each include: costs DNS lookups and the limit is 10. See SPF too many DNS lookups.
  • CNAMEs published but signing left off. Publishing the records is not enough. The switch in the Defender portal must be on.
  • Typed DKIM values. One wrong character breaks DKIM. Copy the values.
  • Forgetting other senders. Your website, CRM or marketing tool also needs SPF or DKIM with your domain before you enforce DMARC.

Check your setup

Run the free checker at /check?d=yourdomain.com. It detects Microsoft 365, checks all three records and both DKIM selectors, and shows the exact records your domain is missing.

When to move to quarantine and reject

p=none only collects reports. It does not stop anyone from sending email as your domain. Microsoft’s guidance is to start at p=none, move to p=quarantine, then to p=reject, checking reports at each step. Our post on DMARC quarantine vs reject explains how long to wait and what to look for.

If you want us to read the reports, find every sender and take the domain to p=reject for you, see pricing. If the domain is not at p=reject within 60 days, you get a full refund.

Sources

See where your domain stands in 10 seconds

Free. No signup. We do not store the domains you check.