Set up DMARC with Microsoft 365
This guide shows what to configure for a domain whose mail is sent from Microsoft 365 (Exchange Online), and how to confirm it in DMARC+. For the exact screens and commands in Microsoft's admin portals, use Microsoft's own documentation, since those screens change. Search for "Microsoft 365 SPF", "Microsoft 365 DKIM for custom domains" and "Microsoft 365 DMARC".
What you need to configure
| Record | Requirement | Where the details come from |
|---|---|---|
| SPF | One SPF record for the domain that includes Microsoft's sending servers | Microsoft's SPF documentation gives the include value to use |
| DKIM | Microsoft signs with your own domain once you enable DKIM for the custom domain | Microsoft's DKIM documentation. It provides two selector records to publish in your DNS. |
| DMARC | A record at _dmarc.<domain> with your DMARC+ report address |
DMARC+ Managed DMARC or the DMARC Generator |
Note: until DKIM is enabled for your custom domain, Microsoft may sign with its own default domain. That signature is valid but does not align with your From domain, so DMARC then depends on SPF alone.
Steps
- Add the domain in DMARC+ (DMARC+ > Domains). Enter the DKIM selector that Microsoft gave you for the domain. If you have not enabled DKIM yet, do step 3 first, then return and set the selector.
- Set up SPF. Add Microsoft's include to your single SPF record. If you also use other senders, keep them in the same record. Check the result with Tools > SPF.
- Enable DKIM for the custom domain following Microsoft's documentation. Publish the records they give you, wait for DNS, then turn the feature on. Verify with Tools > DKIM, entering each selector.
- Publish DMARC at
**p=none**with your DMARC+ report address. See Set up DMARC for the first time. - Wait two weeks, then review Aggregate Reports.
- Fix other senders and follow From monitoring to enforcement.
Things to check for Microsoft 365
| Check | Why |
|---|---|
| Both DKIM selectors are published | Microsoft rotates between two selectors |
| DKIM signing is on for every sending domain | Each domain is enabled separately |
| The domain is not also authorized in a second SPF record | Two SPF records break SPF |
| Mail from shared mailboxes, scanners, and apps that relay through Microsoft is included | They may use different sending paths |
| Subdomains you send from | Each subdomain that sends needs its own alignment |
Reading the results
In the Aggregate Reports Explorer, mail from Microsoft appears with server names that identify the service. It should show DMARC pass. If it fails:
| Symptom | Likely cause | Fix |
|---|---|---|
| SPF passes, DMARC fails | SPF is not aligned, and DKIM is not enabled for your domain | Enable DKIM for the custom domain |
| DKIM fails | Selector records missing or wrong | Republish records from Microsoft's documentation |
| SPF fails | Microsoft's include is missing, or the lookup limit is exceeded | Fix the record. See Lookup tools. |
| Fails only for forwarded mail | Forwarding broke SPF | See Troubleshooting |
Before enforcing
- Every Microsoft path passes DMARC.
- Third-party services that send as your domain are set up. See Managing third-party senders.