Skip to main content
ESP AUTHENTICATION GUIDESPF Lookups: 2 / 10DKIM Type: CNAMEBIMI: Supported

How to Set Up SPF & DKIM for Microsoft 365 (Exchange Online): DNS Authentication Guide

Configure authoritative DNS records for Microsoft 365 (Exchange Online). Prevent spoofing, maintain high inbox placement at Google & Yahoo, and verify alignment without exceeding RFC 7208 lookup limits.

Required DNS Records for Microsoft 365 (Exchange Online)

1. Sender Policy Framework (SPF)
Type: TXT
Host / Name:@
Value / Content:
v=spf1 include:spf.protection.outlook.com ~all
Uses 2 of your domain's 10 allowed DNS lookups under RFC 7208. Do not add duplicate SPF TXT records.
2. DomainKeys Identified Mail (DKIM)
Type: CNAME
Selector / Host Name:selector1._domainkey
Target / Key Content:
selector1-yourcompany-com._domainkey.yourtenant.onmicrosoft.com
Delegates cryptographic signing to Microsoft 365 (Exchange Online). Alignment mode is set to relaxed.

Recommended DMARC Policy for Microsoft 365 (Exchange Online)

Once both SPF and DKIM are verified on your domain, enforce DMARC to prevent attackers from sending unauthorized emails spoofing your brand:

v=DMARC1; p=reject; rua=mailto:dmarc-reports@yourcompany.com; pct=100; aspf=r; adkim=r

Vendor Resources & RFC Standards

RFC 7208 (SPF)RFC 6376 (DKIM)RFC 7489 (DMARC)Microsoft 365 (Exchange Online) Official Setup Guide
Live DNS & SPF Analyzer

Verify Your Microsoft 365 (Exchange Online) SPF & DKIM Records in Real-Time

Test your authoritative domain now to check DNS lookup limits, evaluate DMARC alignment, and ensure 100% deliverability to Google and Microsoft inboxes.

Run SPF & DKIM Audit