If your company email runs on Microsoft 365 (Outlook, Exchange Online), you need three DNS records to keep your mail out of spam and stop others from sending email as your domain: SPF, DKIM and DMARC. Gmail and Yahoo require them from bulk senders, and Microsoft announced similar rules for Outlook.com in 2025.
You'll need admin access to Microsoft 365 and to your domain's DNS. Start by checking your domain with our free DMARC checker so you know which records are missing.
Step 1: SPF
SPF is one TXT record on your domain (host @) listing the services allowed to send as you.
- If only Microsoft 365 sends your email:
v=spf1 include:spf.protection.outlook.com -all - If other services send too (newsletters, CRM, website forms), add their includes to the same record. A domain must have exactly one SPF record.
Microsoft 365 domains often already have this record, because the domain setup wizard asks you to add it. Check for an existing v=spf1 record before adding one.
Step 2: DKIM
Microsoft signs mail for your custom domain only after you publish two CNAME records and switch DKIM on.
- Open the Microsoft Defender portal and go to Email & collaboration → Policies & rules → Threat policies → Email authentication settings → DKIM.
- Select your domain. Microsoft shows two CNAME records, for the hosts
selector1._domainkeyandselector2._domainkey. - Copy both exactly as shown into your DNS provider as CNAME records. The targets are specific to your tenant, so don't copy them from another guide.
- Wait for DNS to update, return to the DKIM page and switch Sign messages for this domain with DKIM signatures to on.
If you get an error that the CNAME records don't exist, DNS hasn't caught up yet. Try again after an hour.
Step 3: DMARC
- Add a TXT record with the host
_dmarc:v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com; fo=1 - Make sure the reporting address exists. You'll receive a daily report from each large email provider.
- After two to four weeks of reports, when all legitimate mail passes, change
p=nonetop=quarantine, and later top=reject.
p=none only monitors. Spoofed mail still gets delivered until you move to quarantine or reject.
Step 4: Check it
- Run the DMARC checker again. DKIM is found under
selector1orselector2. - Send a message to a Gmail address and choose ⋮ → Show original. SPF, DKIM and DMARC should all say PASS.
Things that often go wrong
- Third-party senders. Your marketing tool or helpdesk sends as your domain but isn't in SPF and doesn't sign with your DKIM. It fails DMARC once you tighten the policy. Your DMARC reports will name these senders.
- A second SPF record added by a new service's setup guide. Merge it into the existing one.
- Records lost after a DNS move. When a domain moves to a new DNS host, TXT and CNAME records are easy to leave behind. Daily Website Report re-checks your email records every day and alerts you if one disappears.