Sending provider
Microsoft 365 SPF, DKIM and DMARC setup
Microsoft 365 needs v=spf1 include:spf.protection.outlook.com -all as the SPF record of your domain, two DKIM CNAME records (selector1._domainkey and selector2._domainkey) that point to keys Microsoft hosts, and a DMARC TXT record at _dmarc. DKIM is off for custom domains until you turn it on in the Defender portal after the CNAMEs are published.
Microsoft 365
Records at a glance
- SPF record
v=spf1 include:spf.protection.outlook.com -all- DKIM
Two CNAMEs: selector1._domainkey and selector2._domainkey
- DMARC
TXT at _dmarc, start with p=none and move to quarantine, then reject
Check Microsoft 365 on your domain
Enter the domain you send from: the check looks for the Microsoft 365 SPF include, its DKIM key and your DMARC record, and says what to fix.
Looks for SPF include:spf.protection.outlook.com, DKIM at selector1 and selector2 and a DMARC record. Lookups go from your browser to Cloudflare's public DNS resolver.
DNS records
The Microsoft 365 records
Values in angle brackets are specific to your account; copy them from the provider. Hosts are relative to your domain, as most DNS panels expect them.
- Name / host
@Valuev=spf1 include:spf.protection.outlook.com -allWorldwide and GCC tenants. GCC High and DoD use include:spf.protection.office365.us; 21Vianet uses include:spf.protection.partner.outlook.cn
- Name / host
selector1._domainkeyValueselector1-<CustomDomainWithDashes>._domainkey.<InitialDomainPrefix>.<DynamicPartitionCharacter>-v1.dkim.mail.microsoftDomains added since May 2025. Copy the exact value from the Defender portal; Microsoft assigns the partition character
- Name / host
selector2._domainkeyValueselector2-<CustomDomainWithDashes>._domainkey.<InitialDomainPrefix>.<DynamicPartitionCharacter>-v1.dkim.mail.microsoftBoth selectors are needed: Microsoft signs with one and rotates to the other
- Name / host
_dmarcValuev=DMARC1; p=none; pct=100; rua=mailto:rua@<yourdomain>Microsoft's first step; move to p=quarantine and then p=reject as the reports show your senders passing
Good to know
- Older domains keep the earlier DKIM format, selector1-contoso-com._domainkey.contoso.onmicrosoft.com; the two formats cannot be mixed for one selectorsource (opens the vendor's page in a new tab)
- Microsoft recommends -all at the end of the SPF record and a TTL of 3600 seconds or more; do not flatten the Microsoft include, its IP addresses changesource (opens the vendor's page in a new tab)
- Every subdomain that sends mail needs its own SPF record; the *.onmicrosoft.com domain needs no setupsource (opens the vendor's page in a new tab)
- Keys are 1024-bit by default; New-DkimSigningConfig and Rotate-DkimSigningConfig take -KeySize 2048, and a rotation takes four dayssource (opens the vendor's page in a new tab)
Step by step
Turn on DKIM in Microsoft 365
Open Email authentication settingssource (opens the vendor's page in a new tab)
In the Microsoft Defender portal go to Email & collaboration > Policies & rules > Threat policies > Email authentication settings, then the DKIM tab
Enable the domainsource (opens the vendor's page in a new tab)
Select your custom domain (Status NoDKIMKeys) and slide the toggle to Enabled. A Client error dialog shows the CNAME values; select OK and the status becomes CnameMissing
Copy the two CNAMEssource (opens the vendor's page in a new tab)
Open the domain's details flyout and copy both values from the Publish CNAMEs section
Publish them at your DNS hostsource (opens the vendor's page in a new tab)
Create selector1._domainkey and selector2._domainkey as CNAME records with those values. Enter the host without your domain if the panel adds it
Sign messagessource (opens the vendor's page in a new tab)
Once Microsoft detects the records, turn on Sign messages for this domain with DKIM signatures. The status changes to Valid
Where the records go
Field by field for the DNS panel your domain uses:
DMARC
DMARC with Microsoft 365
- Start with v=DMARC1; p=none; pct=100; rua=mailto:rua@<yourdomain> and read the aggregate reportssource (opens the vendor's page in a new tab)
- Then p=quarantine with pct stepped from 10 to 100, and p=reject as the goalsource (opens the vendor's page in a new tab)
- A domain that sends no mail at all gets v=DMARC1; p=reject;source (opens the vendor's page in a new tab)
- Outbound mail that fails DMARC on a domain with p=quarantine or p=reject goes out through Microsoft's high-risk delivery poolsource (opens the vendor's page in a new tab)
TXT at _dmarc
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.comReplace the address with a mailbox you read; move to p=quarantine when the reports show every sender passing.
Troubleshooting
Common Microsoft 365 errors and fixes
DKIM status CnameMissing: host doubled
Enter only selector1._domainkey as the host. Panels like GoDaddy add the domain, and a full name turns into selector1._domainkey.contoso.com.contoso.comsource (opens the vendor's page in a new tab)
DKIM status CnameMissing: TXT record instead of CNAME
Delete the TXT record and create a CNAME that points to the dkim.mail.microsoft valuesource (opens the vendor's page in a new tab)
Key rotation fails
Publish both selector1 and selector2; with one of them missing, Microsoft cannot rotate the keysource (opens the vendor's page in a new tab)
Wrong CNAME target
Use the exact Selector1CNAME and Selector2CNAME values from the portal or Get-DkimSigningConfig; dots, dashes and the partition character must matchsource (opens the vendor's page in a new tab)
SPF permerror
Keep one SPF record per domain and stay within 10 DNS lookups; move other senders to subdomainssource (opens the vendor's page in a new tab)
SPF syntax error
Check for a trailing period, include= in place of include: or a space after the colonsource (opens the vendor's page in a new tab)
For cold email
Mailboxes that come with the DNS records done
If the domain is for cold outreach, keep Microsoft 365 on your main domain and send from separate domains. Outreach2day buys the domains, publishes SPF, DKIM and DMARC, creates the mailboxes and starts warm-up, then sends your campaigns from its own sequencer or exports the mailboxes to Instantly or Smartlead.
- SPF, DKIM and DMARC set for youOn every domain, checked after setup and kept in place
- $2.50 a mailbox a month12-mailbox minimum; warm-up and the sending engine included
- 1,000+ mailboxesA volume price per mailbox, quoted on a call
Questions
What is the SPF record for Office 365?
v=spf1 include:spf.protection.outlook.com -all for worldwide and GCC tenants. If other services send as the domain, add their includes to the same record; a domain may have only one SPF record.
Why does Microsoft 365 DKIM show CnameMissing?
Microsoft cannot find the two CNAME records yet. The usual causes are a host name with the domain added twice, a TXT record in place of a CNAME, or one of the two selectors missing. New records can take a while to appear in DNS.
Is DKIM on by default in Microsoft 365?
Only for the *.onmicrosoft.com domain. A custom domain stays unsigned until you publish the two CNAMEs and turn signing on in the Defender portal or with Set-DkimSigningConfig.
Should I use Microsoft 365 mailboxes for cold email?
Keep the company domain for company mail. Cold outreach is usually sent from separate domains with their own mailboxes, so a complaint or a blocklist hit never touches the main domain.
Sources
Microsoft 365 documentation, checked . Menus and values change; if a step differs, Microsoft 365's own page is the reference.
Deliverability call
Talk to our deliverability team
Book a call with the people who run our mailbox infrastructure. We look at your current setup and tell you what to change. Running 1,000+ mailboxes? We also quote a volume price below every vendor list price in our comparisons, warm-up and sending included.
- Review your domains, DNS records and current inbox placement
- Size the setup: domains, mailboxes per domain and daily volume per mailbox
- Plan warm-up and the move from your current provider or sequencer
- 1,000+ mailboxes: a volume price per mailbox for your setup
Free call
See open times in your time zone and book on this page.
Or open the booking pageLoading available times…
Open the booking page instead