Dmarc Overview

Set up DMARC with Microsoft 365

This guide shows what to configure for a domain whose mail is sent from Microsoft 365 (Exchange Online), and how to confirm it in DMARC+. For the exact screens and commands in Microsoft's admin portals, use Microsoft's own documentation, since those screens change. Search for "Microsoft 365 SPF", "Microsoft 365 DKIM for custom domains" and "Microsoft 365 DMARC".

What you need to configure

Record Requirement Where the details come from
SPF One SPF record for the domain that includes Microsoft's sending servers Microsoft's SPF documentation gives the include value to use
DKIM Microsoft signs with your own domain once you enable DKIM for the custom domain Microsoft's DKIM documentation. It provides two selector records to publish in your DNS.
DMARC A record at _dmarc.<domain> with your DMARC+ report address DMARC+ Managed DMARC or the DMARC Generator

Note: until DKIM is enabled for your custom domain, Microsoft may sign with its own default domain. That signature is valid but does not align with your From domain, so DMARC then depends on SPF alone.

Steps

  1. Add the domain in DMARC+ (DMARC+ > Domains). Enter the DKIM selector that Microsoft gave you for the domain. If you have not enabled DKIM yet, do step 3 first, then return and set the selector.
  2. Set up SPF. Add Microsoft's include to your single SPF record. If you also use other senders, keep them in the same record. Check the result with Tools > SPF.
  3. Enable DKIM for the custom domain following Microsoft's documentation. Publish the records they give you, wait for DNS, then turn the feature on. Verify with Tools > DKIM, entering each selector.
  4. Publish DMARC at **p=none** with your DMARC+ report address. See Set up DMARC for the first time.
  5. Wait two weeks, then review Aggregate Reports.
  6. Fix other senders and follow From monitoring to enforcement.

Things to check for Microsoft 365

Check Why
Both DKIM selectors are published Microsoft rotates between two selectors
DKIM signing is on for every sending domain Each domain is enabled separately
The domain is not also authorized in a second SPF record Two SPF records break SPF
Mail from shared mailboxes, scanners, and apps that relay through Microsoft is included They may use different sending paths
Subdomains you send from Each subdomain that sends needs its own alignment

Reading the results

In the Aggregate Reports Explorer, mail from Microsoft appears with server names that identify the service. It should show DMARC pass. If it fails:

Symptom Likely cause Fix
SPF passes, DMARC fails SPF is not aligned, and DKIM is not enabled for your domain Enable DKIM for the custom domain
DKIM fails Selector records missing or wrong Republish records from Microsoft's documentation
SPF fails Microsoft's include is missing, or the lookup limit is exceeded Fix the record. See Lookup tools.
Fails only for forwarded mail Forwarding broke SPF See Troubleshooting

Before enforcing