If your mail keeps landing in junk, or someone is spoofing your CEO's address, the fix is almost always the same three DNS records. Microsoft, Google, and Yahoo now expect SPF, DKIM, and DMARC from anyone sending real volume, and a missing or broken record is one of the most common findings in any tenant I review.
What each record does
| Record | Answers the question | Lives at |
|---|---|---|
| SPF | Which servers are allowed to send mail for this domain? | TXT record on the domain root |
| DKIM | Was this message really signed by the domain, and was it changed in transit? | Two CNAME records pointing to Microsoft |
| DMARC | What should receivers do when SPF and DKIM fail, and who gets the reports? | TXT record at _dmarc |
SPF and DKIM prove a message is legitimate. DMARC ties them to the address the recipient actually sees, and tells the world what to do with fakes.
SPF
For a domain that sends only through Microsoft 365:
yourcompany.com. TXT "v=spf1 include:spf.protection.outlook.com -all"Rules that trip people up:
- One SPF record per domain. Two
v=spf1records means SPF fails everywhere. Merge them. - Ten DNS lookup limit. Every
include:counts. Stacking marketing tools, CRMs, and help desks can push you past ten, and then SPF fails. - Add every legitimate sender: newsletter platforms, invoicing systems, and your website's contact form. Check before you tighten anything.
-allvs~all:-all(fail) is the goal once DMARC is doing its job.~all(softfail) is fine while you're discovering senders.
DKIM
Exchange Online can sign outbound mail with your own domain, but only after you publish two CNAME records and turn signing on.
- In the Microsoft Defender portal, go to Email & collaboration -> Policies & rules -> Threat policies -> Email authentication settings -> DKIM.
- Select your domain. It shows the two CNAME records (
selector1._domainkeyandselector2._domainkey) with the exact values for your tenant. - Publish both CNAMEs at your DNS host, wait for them to resolve, then enable signing.
You can check the configuration from Exchange Online PowerShell:
Connect-ExchangeOnline
Get-DkimSigningConfig | Format-Table Domain, Enabled, Status, Selector1CNAME, Selector2CNAMEDMARC
Start in monitoring mode, read the reports, then tighten:
_dmarc.yourcompany.com. TXT "v=DMARC1; p=none; rua=mailto:dmarc@yourcompany.com"The rollout I use:
p=nonewith reporting on. Collect a few weeks of aggregate reports and find every legitimate sender that fails.- Fix those senders. Add them to SPF, or better, set up DKIM signing on the platform itself.
p=quarantine, optionally starting withpct=below 100 to phase it in.p=rejectonce reports show only spoofing is failing.
Checking your work
- Send a message to an outside mailbox, open the full headers, and paste them into Microsoft's Message Header Analyzer. Look for
spf=pass,dkim=pass, anddmarc=pass. - Use MxToolbox to check each record for syntax errors and SPF lookup count.
- In the Defender portal, check that DKIM shows as enabled and valid.
Don't forget parked domains
Domains you own but don't send mail from are easy targets for spoofing. Lock them down completely:
parkeddomain.com. TXT "v=spf1 -all"
_dmarc.parkeddomain.com. TXT "v=DMARC1; p=reject"