Sending provider

Microsoft 365 SPF, DKIM and DMARC setup

Microsoft 365 needs v=spf1 include:spf.protection.outlook.com -all as the SPF record of your domain, two DKIM CNAME records (selector1._domainkey and selector2._domainkey) that point to keys Microsoft hosts, and a DMARC TXT record at _dmarc. DKIM is off for custom domains until you turn it on in the Defender portal after the CNAMEs are published.

Microsoft 365

Records at a glance

SPF record
v=spf1 include:spf.protection.outlook.com -all
DKIM

Two CNAMEs: selector1._domainkey and selector2._domainkey

DMARC

TXT at _dmarc, start with p=none and move to quarantine, then reject

Check Microsoft 365 on your domain

Enter the domain you send from: the check looks for the Microsoft 365 SPF include, its DKIM key and your DMARC record, and says what to fix.

Looks for SPF include:spf.protection.outlook.com, DKIM at selector1 and selector2 and a DMARC record. Lookups go from your browser to Cloudflare's public DNS resolver.

DNS records

The Microsoft 365 records

Values in angle brackets are specific to your account; copy them from the provider. Hosts are relative to your domain, as most DNS panels expect them.

  • Name / host
    @
    Value
    v=spf1 include:spf.protection.outlook.com -all

    Worldwide and GCC tenants. GCC High and DoD use include:spf.protection.office365.us; 21Vianet uses include:spf.protection.partner.outlook.cn

  • Name / host
    selector1._domainkey
    Value
    selector1-<CustomDomainWithDashes>._domainkey.<InitialDomainPrefix>.<DynamicPartitionCharacter>-v1.dkim.mail.microsoft

    Domains added since May 2025. Copy the exact value from the Defender portal; Microsoft assigns the partition character

  • Name / host
    selector2._domainkey
    Value
    selector2-<CustomDomainWithDashes>._domainkey.<InitialDomainPrefix>.<DynamicPartitionCharacter>-v1.dkim.mail.microsoft

    Both selectors are needed: Microsoft signs with one and rotates to the other

  • Name / host
    _dmarc
    Value
    v=DMARC1; p=none; pct=100; rua=mailto:rua@<yourdomain>

    Microsoft's first step; move to p=quarantine and then p=reject as the reports show your senders passing

Good to know

Step by step

Turn on DKIM in Microsoft 365

  1. Open Email authentication settingssource (opens the vendor's page in a new tab)

    In the Microsoft Defender portal go to Email & collaboration > Policies & rules > Threat policies > Email authentication settings, then the DKIM tab

  2. Enable the domainsource (opens the vendor's page in a new tab)

    Select your custom domain (Status NoDKIMKeys) and slide the toggle to Enabled. A Client error dialog shows the CNAME values; select OK and the status becomes CnameMissing

  3. Copy the two CNAMEssource (opens the vendor's page in a new tab)

    Open the domain's details flyout and copy both values from the Publish CNAMEs section

  4. Publish them at your DNS hostsource (opens the vendor's page in a new tab)

    Create selector1._domainkey and selector2._domainkey as CNAME records with those values. Enter the host without your domain if the panel adds it

  5. Sign messagessource (opens the vendor's page in a new tab)

    Once Microsoft detects the records, turn on Sign messages for this domain with DKIM signatures. The status changes to Valid

DMARC

DMARC with Microsoft 365

DMARCA safe first record

TXT at _dmarc

v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com

Replace the address with a mailbox you read; move to p=quarantine when the reports show every sender passing.

Troubleshooting

Common Microsoft 365 errors and fixes

For cold email

Mailboxes that come with the DNS records done

If the domain is for cold outreach, keep Microsoft 365 on your main domain and send from separate domains. Outreach2day buys the domains, publishes SPF, DKIM and DMARC, creates the mailboxes and starts warm-up, then sends your campaigns from its own sequencer or exports the mailboxes to Instantly or Smartlead.

  • SPF, DKIM and DMARC set for youOn every domain, checked after setup and kept in place
  • $2.50 a mailbox a month12-mailbox minimum; warm-up and the sending engine included
  • 1,000+ mailboxesA volume price per mailbox, quoted on a call

Questions

What is the SPF record for Office 365?

v=spf1 include:spf.protection.outlook.com -all for worldwide and GCC tenants. If other services send as the domain, add their includes to the same record; a domain may have only one SPF record.

Why does Microsoft 365 DKIM show CnameMissing?

Microsoft cannot find the two CNAME records yet. The usual causes are a host name with the domain added twice, a TXT record in place of a CNAME, or one of the two selectors missing. New records can take a while to appear in DNS.

Is DKIM on by default in Microsoft 365?

Only for the *.onmicrosoft.com domain. A custom domain stays unsigned until you publish the two CNAMEs and turn signing on in the Defender portal or with Set-DkimSigningConfig.

Should I use Microsoft 365 mailboxes for cold email?

Keep the company domain for company mail. Cold outreach is usually sent from separate domains with their own mailboxes, so a complaint or a blocklist hit never touches the main domain.

Deliverability call

Talk to our deliverability team

Book a call with the people who run our mailbox infrastructure. We look at your current setup and tell you what to change. Running 1,000+ mailboxes? We also quote a volume price below every vendor list price in our comparisons, warm-up and sending included.

  • Review your domains, DNS records and current inbox placement
  • Size the setup: domains, mailboxes per domain and daily volume per mailbox
  • Plan warm-up and the move from your current provider or sequencer
  • 1,000+ mailboxes: a volume price per mailbox for your setup

Free call

See open times in your time zone and book on this page.

Or open the booking page