Set up SPF, DKIM and DMARC for Microsoft 365

The exact SPF, DKIM and DMARC records Microsoft 365 needs, where to add them and how to check they pass and align, so Microsoft 365 mail reaches the inbox.

Updated September 30, 2026

Microsoft 365 needs include:spf.protection.outlook.com in your SPF record, two DKIM CNAME records at selector1._domainkey and selector2._domainkey that point to targets the Defender portal gives you, and a DMARC record at _dmarc. DKIM signing for a custom domain is off until you publish the CNAMEs and turn it on, so mail from your domain can’t pass DMARC through DKIM until then.

Records at a glance

HostTypeValue
@TXT
v=spf1 include:spf.protection.outlook.com -all
Commercial and GCC tenants. GCC High and DoD use spf.protection.office365.us; 21Vianet uses spf.protection.partner.outlook.cn.
selector1._domainkeyCNAME
<Selector1CNAME from the Defender portal>
For example selector1-contoso-com._domainkey.contoso.n-v1.dkim.mail.microsoft (new domains) or selector1-contoso-com._domainkey.contoso.onmicrosoft.com (older domains).
selector2._domainkeyCNAME
<Selector2CNAME from the Defender portal>
Required too: Microsoft switches to it when keys rotate.
_dmarcTXT
v=DMARC1; p=none; rua=mailto:<your report address>

Set up SPF for Microsoft 365

Most tenants need include:spf.protection.outlook.com. Microsoft recommends ending the record with -all. As of September 2026 that include lists Microsoft’s IP ranges directly, so it costs one DNS lookup of your ten. Microsoft advises against flattening it into IP addresses, because its ranges change.

If you also send through other services, combine everything into one record:

Microsoft 365 plus an on-premises server and SendGrid
v=spf1 ip4:192.0.2.10 include:spf.protection.outlook.com include:sendgrid.net -all

Microsoft 365 has no SPF setting of its own; you edit the record at your DNS host. With DMARC Dojo’s hosted SPF you add senders in the dashboard instead, and it refuses changes that would break the 10-lookup limit. The onmicrosoft.com domain’s SPF is managed by Microsoft and can’t be changed.

Set up DKIM in the Microsoft Defender portal

Microsoft generates two key pairs per domain and hosts the public keys. Your CNAMEs point at them, which lets Microsoft rotate keys without further DNS changes. Only one selector signs at a time.

  1. In the Defender portal at security.microsoft.com, go to Email & collaboration > Policies & rules > Threat policies > Email authentication settings and select the DKIM tab.
  2. Find your custom domain (status NoDKIMKeys) and slide its toggle to Enabled. A “Client error” dialog appears because the CNAMEs don’t exist yet. Click OK; the status becomes CnameMissing.
  3. Click the domain’s row to open its details and copy the two values under Publish CNAMEs.
  4. At your DNS host, create CNAME records at selector1._domainkey and selector2._domainkey pointing to those values. Use CNAME, not TXT.
  5. After a few minutes (sometimes longer), return to the details flyout and turn on Sign messages for this domain with DKIM signatures. The status should read “Signing DKIM signatures for this domain.”

Key length: keys created in PowerShell with New-DkimSigningConfig default to 1024 bits unless you pass -KeySize 2048. To move an existing domain to 2048 bits, run Rotate-DkimSigningConfig -Identity contoso.com -KeySize 2048; a rotation takes about four days to take effect. To confirm signing, send a message to an outside mailbox and look for a DKIM-Signature header with d= your domain and s=selector1 or selector2, and dkim=pass in Authentication-Results.

Make it pass DMARC (alignment)

  • SPF usually aligns. Exchange Online sends with the user’s address as the envelope sender, so an SPF pass counts for your domain.
  • DKIM doesn’t align until you enable it for the custom domain. Microsoft signs mail from the initial *.onmicrosoft.com domain automatically, but a signature for contoso.onmicrosoft.com doesn’t match contoso.com in the From address. Only your own selectors fix that.

Enable DKIM on every custom domain and subdomain that sends mail; each needs its own CNAMEs. It’s what keeps mail passing DMARC when it’s forwarded or relayed and SPF breaks. Microsoft also recommends sending bulk mail from a subdomain such as marketing.contoso.com, with its own SPF record, to protect your main domain’s reputation. See DMARC alignment for the details.

Add a DMARC record

Starter DMARC record
v=DMARC1; p=none; rua=mailto:<your report address>

Microsoft’s own guidance is to add DMARC early, at a monitoring policy, and read the reports before enforcing. DMARC Dojo recognizes Microsoft 365 in DMARC reports, so Exchange Online traffic shows up as its own source and you can see whether it passes with alignment. When all legitimate mail passes, step up to quarantine and reject (here’s how).

Check your Microsoft 365 DKIM selectors

Enter your domain to confirm selector1 and selector2 resolve, and see your SPF and DMARC results with the fixes to make.

Troubleshooting

  • Status stays CnameMissing. The hostname probably includes your domain twice, as in selector1._domainkey.contoso.com.contoso.com. Enter only selector1._domainkey at hosts that append the domain.
  • You created a TXT record instead of a CNAME. Microsoft 365 doesn’t support publishing the key as TXT. Delete it and create the CNAME.
  • The target doesn’t match. Common mistakes: keeping dots instead of dashes in the domain part, including .onmicrosoft.com in a new-format target, or leaving out the partition letter. Copy the exact value from the portal or Get-DkimSigningConfig.
  • DKIM fails through Cloudflare. Set both CNAMEs to DNS only (gray cloud). A proxied record returns Cloudflare’s addresses instead of Microsoft’s key.
  • Key rotation fails later. Only selector1 was published. Microsoft needs both CNAMEs even though one is inactive.

Frequently asked questions

Why does Microsoft 365 need two DKIM selectors?

One signs while the other waits. When keys rotate, Microsoft switches to the other selector, so rotation works without you editing DNS again. Publish both CNAMEs from the start.

Do I need to do anything for my onmicrosoft.com domain?

No. Microsoft publishes SPF for onmicrosoft.com and signs its mail with DKIM automatically. You only need records for custom domains you send from.

Should I use -all or ~all with Microsoft 365?

Microsoft recommends -all when you also have DKIM and DMARC. DMARC counts both as an SPF failure, and your DMARC policy decides what happens to the message.

How do I rotate DKIM keys in Microsoft 365?

Open the domain on the DKIM tab of Email authentication settings and choose Rotate DKIM keys, or run Rotate-DkimSigningConfig in Exchange Online PowerShell. The new key starts signing after about four days.

Does Microsoft 365 need an SPF record on each subdomain?

Yes, for each subdomain that sends mail. SPF doesn’t inherit from the parent domain. DMARC does, so a subdomain without its own DMARC record uses the parent’s policy.