ESP AUTHENTICATION GUIDESPF Lookups: 2 / 10DKIM Type: CNAMEBIMI: Supported
How to Set Up SPF & DKIM for Microsoft 365 (Exchange Online): DNS Authentication Guide
Configure authoritative DNS records for Microsoft 365 (Exchange Online). Prevent spoofing, maintain high inbox placement at Google & Yahoo, and verify alignment without exceeding RFC 7208 lookup limits.
Required DNS Records for Microsoft 365 (Exchange Online)
1. Sender Policy Framework (SPF)
Type: TXTHost / Name:@
Value / Content:
v=spf1 include:spf.protection.outlook.com ~allUses 2 of your domain's 10 allowed DNS lookups under RFC 7208. Do not add duplicate SPF TXT records.
2. DomainKeys Identified Mail (DKIM)
Type: CNAMESelector / Host Name:selector1._domainkey
Target / Key Content:
selector1-yourcompany-com._domainkey.yourtenant.onmicrosoft.comDelegates cryptographic signing to Microsoft 365 (Exchange Online). Alignment mode is set to relaxed.
Recommended DMARC Policy for Microsoft 365 (Exchange Online)
Once both SPF and DKIM are verified on your domain, enforce DMARC to prevent attackers from sending unauthorized emails spoofing your brand:
v=DMARC1; p=reject; rua=mailto:dmarc-reports@yourcompany.com; pct=100; aspf=r; adkim=rVendor Resources & RFC Standards
Live DNS & SPF Analyzer
Run SPF & DKIM AuditVerify Your Microsoft 365 (Exchange Online) SPF & DKIM Records in Real-Time
Test your authoritative domain now to check DNS lookup limits, evaluate DMARC alignment, and ensure 100% deliverability to Google and Microsoft inboxes.